Courseiva

NSE7 · domain

Advanced Threat Protection

This domain covers Fortinet's Advanced Threat Protection tooling on FortiGate and Fabric: IPS sensors and custom signatures, anomaly detection, automated threat response via automation stitches and quarantine, and event correlation through FortiAnalyzer and FortiSIEM. Questions are scenario-based, asking you to pick the correct components, features, or products that satisfy a stated security outcome.

157 questions38 easy82 medium37 hard

Focused practice

Practice Advanced Threat Protection questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Advanced Threat Protection

Be able to map a threat scenario to the right Fortinet components: IPS sensor plus automation stitch for auto-blocking, FortiSIEM or FortiAnalyzer for correlation, FortiEDR for endpoint containment. The key is pairing the correct trigger with the correct response action.

Configuring IPS sensors, custom signatures, and protocol anomaly detection on FortiGate

Building automation stitches with triggers and actions to block source IPs automatically

Using FortiAnalyzer and FortiSIEM for event collection, correlation, and unified threat views

Deploying FortiEDR and FortiClient EMS for endpoint detection, response, and automated containment

Watch out for

Common Advanced Threat Protection exam traps

  • ▸Choosing automation stitches alone when the scenario also requires an IPS sensor with the right severity trigger and action.
  • ▸Confusing FortiAnalyzer log aggregation with FortiSIEM correlation, or picking FortiSandbox for event correlation it does not perform.
  • ▸Assuming anomaly detection is a separate module rather than an IPS sensor feature configured with protocol anomaly signatures.

Question index

All Advanced Threat Protection questions (157)

Click any question to see the full explanation, or start a practice session above.

1

Which Fortinet product is specifically designed to deploy decoys and lures to detect lateral movement and early-stage attacks inside the network?

Easy
2

Which FortiClient ATP feature provides protection against zero-day malware by monitoring process behavior and blocking suspicious activities at the endpoint?

Easy
3

A security administrator is configuring FortiGate to detect and block command-and-control (C2) traffic using the botnet database and DNS filtering. The administrator wants to ensure that infected internal hosts are identified and their C2 communication is blocked. Which two actions should the administrator take? (Choose two.)

Medium
4

A security team is deploying FortiEDR to protect endpoints. They want to ensure that when a threat is detected, the endpoint is automatically isolated from the network to prevent lateral movement. However, they also need to allow the endpoint to communicate with the FortiEDR management server for updates and remediation. Which FortiEDR feature should they configure to achieve this?

Hard
5

A security administrator is configuring a FortiGate to use a threat feed connector to block traffic from known malicious IP addresses. The administrator wants to ensure that the threat feed is updated automatically and that the FortiGate can use the feed in firewall policies. Which two actions must the administrator perform? (Choose two.)

Hard
6

Which technology uses DMARC reports to help administrators identify unauthorized use of their email domain?

Easy
7

An administrator wants to integrate FortiGate with an external threat intelligence feed to block known malicious IP addresses automatically. Which object should be used to consume the feed?

Medium
8

An admin wants to create a custom IPS signature to detect a specific exploit that sends a string 'EXPLOIT' in the HTTP Host header. Which signature syntax is correct?

Medium
9

A security team is configuring FortiMail for email security. They want to ensure that incoming emails are authenticated using SPF, DKIM, and DMARC, and that emails failing authentication are quarantined. Which THREE settings must be configured in FortiMail? (Choose three.)

Hard
10

An administrator sees the following log entry: 'id=13593 msg="CDR: File attachment sanitized"' Which feature generated this log?

Medium
11

A network administrator is configuring a FortiGate to protect against unknown malware by using machine learning. The administrator wants to enable the feature that uses machine learning to detect and block malicious files based on their behavior and characteristics, without relying solely on signatures. Which antivirus setting should the administrator enable?

Easy
12

A security analyst is reviewing FortiGate logs and notices that several internal hosts are repeatedly connecting to a domain that is known to host malware. The domain is not present in any local or FortiGuard category. The analyst wants to automatically block future connections to this domain and similar malicious domains without manual intervention. Which FortiGate feature should be configured to achieve this?

Hard
13

A network administrator wants to block known malicious IP addresses using threat intelligence feeds on FortiGate. Which feature should they use?

Easy
14

A FortiGate admin configures an automation stitch to send an email alert when a high-severity IPS event occurs. The trigger is 'IPS Event' and the action is 'Email'. After testing, no email is sent despite events being logged. What is the most likely cause?

Medium
15

A security engineer is troubleshooting a scenario where FortiGate is not blocking a known malicious URL categorized as 'Malware'. The web filtering profile is configured with 'monitor all' for the Malware category. What change should be made to block the URL?

Hard
16

A security analyst wants to use automation stitches on FortiGate to automatically block IP addresses that trigger an IPS signature for 'SSH Brute Force'. Which two components are required to create this automation stitch? (Choose two.)

Hard
17

An organization wants to implement multiple layers of defense against advanced persistent threats. Which three Fortinet solutions would be most effective in an ATP strategy? (Choose three.)

Medium
18

A security analyst is reviewing alerts from FortiEDR and wants to automatically isolate an infected endpoint from the network when a malicious process is detected. Which FortiEDR feature should the analyst configure to achieve this?

Easy
19

A FortiGate is configured with a firewall policy that applies an antivirus profile with FortiSandbox inspection enabled. Users report that when they download a suspicious executable from an HTTPS website, the download completes and the file runs, but no verdict is ever returned from FortiSandbox. The administrator confirms that FortiSandbox is reachable and other protocols are being inspected successfully. Which action will most likely resolve the issue?

Hard
20

A FortiGate administrator has enabled FortiGuard Outbreak Prevention and selects the 'Use Outbreak Prevention Database' option. After a new outbreak is detected, the administrator verifies that the IPS signature is applied to all applicable policies. However, the administrator wants to ensure that the FortiGate dynamically updates its protection without requiring a full IPS engine update. Which FortiGuard service must be reachable for the FortiGate to receive outbreak prevention updates?

Medium
21

A security analyst is investigating an alert from FortiSandbox indicating that a file has a high-risk verdict. The analyst wants to automatically prevent the file from executing on other endpoints. Which FortiSandbox integration should be configured to achieve this?

Hard
22

A FortiGate is configured with an antivirus profile that has the machine learning engine enabled. An administrator notices that some files are being detected by the ML engine but the verdict is 'probably clean'. What does this verdict indicate?

Hard
23

A company wants to detect and block phishing emails that contain malicious links. Which FortiGate security profile should be used?

Easy
24

A FortiGate administrator notices that traffic classified as 'unknown' by the antivirus is being allowed. The administrator wants to ensure that such files are submitted to FortiSandbox for analysis and blocked until a verdict is received. Which configuration is required?

Medium
25

What does FortiGuard Outbreak Prevention use to protect against newly discovered malware outbreaks before traditional signatures are available?

Easy
26

What is the primary purpose of Content Disarm and Reconstruction (CDR) in FortiGate's antivirus features?

Easy
27

A FortiGate is configured with a WAF profile to protect a web server. The administrator notices that SQL injection attacks are still reaching the server despite the WAF being enabled. What is the MOST likely reason?

Medium
28

A FortiGate administrator wants to prevent users from accessing a list of known malicious domains. The list is updated daily by a third-party provider and available as a plain text file over HTTPS. Which FortiGate feature should be used to ingest and block these domains?

Easy
29

A company uses FortiEDR and wants to ensure that when an endpoint is compromised, the threat is contained and the security team receives detailed forensics. The team also wants to prevent the malicious process from communicating with its command-and-control server. Which FortiEDR feature should be configured to achieve both containment and forensic data collection?

Hard
30

A security administrator wants to block email spoofing attacks against their organization's domain. They configure SPF, DKIM, and DMARC records. Which protocol authenticates the domain of the email sender by verifying the email's signature against a public key published in DNS?

Medium
31

Which feature on FortiGate uses machine learning to detect never-before-seen malware based on file characteristics?

Easy
32

An administrator configures FortiSandbox inline scanning for HTTP traffic. They notice that files uploaded via HTTP are being scanned but no verdict is being returned, causing delays. What is the MOST likely cause?

Medium
33

A FortiGate administrator is configuring a security profile group and wants to enable inline blocking of malicious files based on FortiGuard cloud threat intelligence, without sending files to FortiSandbox. The administrator has already enabled the antivirus profile and selected the 'Block' action for infected files. Which additional setting should be configured to ensure that files identified as malicious by the FortiGuard service are blocked in real time?

Medium
34

An administrator needs to configure advanced email security on FortiMail to protect against phishing and spoofing. Which THREE features should be enabled to achieve comprehensive email authentication?

Medium
35

An administrator wants to use FortiGate to automatically block traffic if FortiEDR detects a threat on an endpoint. Which feature should the administrator configure?

Medium
36

An administrator wants to block a zero-day malware outbreak detected by FortiGuard. Which feature should be configured to automatically block the threat across all enabled FortiGate devices?

Easy
37

An administrator is configuring FortiGate automation stitches to respond to a detected ransomware outbreak. The trigger is a high severity event from FortiSandbox. Which TWO actions can be used in an automation stitch to contain the threat?

Medium
38

A company uses FortiGate as a web application firewall (WAF) to protect a public web server. The security team wants to block SQL injection attacks. Which WAF signature category should the administrator enable?

Medium
39

A security administrator is reviewing threat logs on a FortiGate running FortiOS 7.4. Multiple internal hosts have triggered IPS signatures for a known botnet C2 domain, but the administrator wants to ensure that DNS queries to this domain are blocked before a connection is attempted. The FortiGate is already using the default FortiGuard ISDB and IPS signatures. Which FortiGate feature should the administrator configure to block DNS resolution of the malicious domain?

Medium
40

A FortiGate administrator wants to ensure that files in email attachments are disarmed before delivery. Which security feature should be configured in the antivirus profile?

Easy
41

A security team is using FortiSandbox to analyze suspicious files. They notice that some files are being analyzed but the verdicts are not being sent back to the FortiGate, so the firewall is not blocking them. Which FortiSandbox setting should the administrator verify to ensure verdicts are returned to the FortiGate?

Medium
42

An organization wants to implement email authentication to prevent spoofing and phishing attacks. They use FortiMail as their email security gateway. Which THREE mechanisms should they configure to achieve comprehensive email authentication?

Medium
43

An administrator is configuring a FortiGate to use the FortiGuard Web Filter to block access to newly registered domains that are often used in phishing campaigns. The administrator wants the block to occur with minimal impact on legitimate business traffic and without relying on manual URL submissions. Which FortiGuard Web Filter category should be used?

Medium
44

A company wants to protect its internal users from malicious files attached to emails. Which FortiGate feature should be configured to inspect SMTP traffic for malware?

Easy
45

An administrator wants to block outbound traffic from internal hosts to known malicious domains without relying on full URL inspection or certificate inspection. The requirement is to use a lightweight DNS-based security service on FortiGate that can block botnet C2 and phishing domains. Which FortiGuard feature should the administrator enable and configure in a DNS filter profile?

Medium
46

An organization wants to deploy a web application firewall (WAF) to protect a public-facing web application. They are evaluating FortiGate versus FortiWeb. Which of the following is a key advantage of using FortiWeb over FortiGate for WAF functionality?

Medium
47

An administrator wants to use FortiGate to block outbound traffic to known malicious IP addresses based on a threat intelligence feed. They configure a threat feed connector and a firewall policy with a destination address group. However, the policy is not blocking traffic to the malicious IPs. What is the most likely cause?

Medium
48

A company wants to receive threat intelligence feeds from external sources to enhance their FortiGate's protection. Which method should be used to integrate external threat feeds into FortiGate?

Medium
49

An organization deploys FortiEDR to protect endpoints. Which component is responsible for collecting and sending telemetry data to the FortiEDR management console?

Medium
50

A FortiGate administrator is configuring SSL inspection on a policy that handles outbound HTTPS traffic. Users report that after enabling deep inspection, some business-critical applications that use certificate pinning fail. The administrator needs to inspect as much traffic as possible while keeping those pinned applications working. What should the administrator do?

Medium
51

An administrator configures email authentication (SPF, DKIM, DMARC) on FortiMail. They find that legitimate emails are being marked as spam by FortiMail. The SPF check passes but DKIM fails. What could be the issue?

Hard
52

An organization is deploying FortiEDR to enhance endpoint protection. Which THREE capabilities does FortiEDR provide? (Choose three.)

Hard
53

A network security administrator notices that FortiGate is not blocking outbound traffic to domains that FortiGuard classifies as malicious. The administrator confirms that the license is valid and FortiGuard category-based blocking is enabled. Which FortiGate feature should be verified to ensure that DNS queries for malicious domains are intercepted and sinkholed?

Medium
54

A security analyst is reviewing FortiGate logs and notices that a web filter profile is blocking access to a known malicious domain, but the block page shows the category as 'Unrated'. The analyst confirms the domain is listed in a custom blocklist. Which FortiGate feature is responsible for overriding the category and enforcing the block?

Hard
55

A company is deploying FortiGate with Advanced Threat Protection (ATP) and wants to block advanced malware that uses encrypted C2 communications. Which security profile should be configured to perform SSL inspection and detect malicious traffic?

Easy
56

An admin configures Content Disarm and Reconstruction (CDR) on FortiGate to protect against malicious macros in Office documents. After applying the CDR profile to a firewall policy, users complain that documents are not being delivered. What is the most likely cause?

Hard
57

A security administrator is configuring a FortiGate to use an external threat intelligence feed via a Threat Feed connector. The administrator wants to ensure that the firewall automatically blocks traffic to malicious IP addresses and domains from the feed. Which two actions are required to achieve this? (Choose two.)

Medium
58

A network admin wants to use FortiClient's advanced threat protection features to detect ransomware behavior on endpoints. Which FortiClient feature should be enabled?

Medium
59

Which Fortinet solution collects and correlates security events from multiple sources to provide a unified view of threats across the network?

Medium
60

A network security administrator wants to use FortiGate to automatically quarantine an endpoint when FortiEDR detects malicious behavior on that endpoint. Which FortiGate feature should be used to integrate with FortiEDR for this purpose?

Easy
61

A network admin is troubleshooting why FortiGate's antivirus is not detecting a known malware sample. The sample is detected by other scanners. Which two checks should the admin perform? (Choose two.)

Medium
62

A security analyst is investigating a recent security incident and wants to use FortiGate's Security Fabric to gather threat intelligence. The analyst needs to view detailed information about a detected threat, including the source, destination, and the specific IPS signature that triggered. Which FortiGate feature provides a centralized view of threat events and allows drill-down into individual incidents?

Hard
63

A security administrator is configuring FortiSandbox integration to automatically block malicious files detected in email attachments. Which TWO actions are required to achieve this integration?

Medium
64

A security team uses FortiSandbox in a FortiGate security fabric. They want files that receive a 'Malicious' verdict to be automatically quarantined and their source endpoints isolated without manual intervention. Which combination of Fortinet components and features must be configured to achieve this automated response?

Hard
65

An administrator wants to create an automation stitch that responds to a high-severity IPS event by blocking the attacker IP. Which THREE components are required to build this automation stitch?

Medium
66

An administrator wants to automatically block a file that FortiSandbox has determined to be malicious. The FortiGate is configured with an antivirus profile that includes FortiSandbox submission. Which verdict action should be set to 'block' in the antivirus profile to achieve this?

Medium
67

What is the primary difference between using a Web Application Firewall (WAF) on FortiGate versus using FortiWeb?

Easy
68

A FortiGate administrator is configuring a security profile to detect command-and-control traffic from internal hosts. The administrator wants to use a signature-based detection method that matches known botnet patterns. Which FortiGate feature should be enabled to accomplish this?

Medium
69

An organization wants to prevent zero-day attacks by using Content Disarm and Reconstruction (CDR) on email attachments. Which Fortinet product provides this capability?

Medium
70

A FortiGate is configured with an IPS sensor that has protocol anomaly detection enabled. The admin notices that legitimate VoIP traffic (SIP) is being blocked. Which action should the admin take to reduce false positives?

Hard
71

A security analyst wants to use automation stitches on FortiGate to automatically block an IP address when a critical severity event is logged. Which TWO components are essential to create this automation stitch? (Choose two.)

Medium
72

An administrator needs to deploy a honeypot solution to detect and deceive attackers inside the network. Which Fortinet product is BEST suited for this purpose?

Medium
73

A network security administrator is deploying a FortiSandbox appliance in a FortiGate environment. The administrator wants to ensure that when a zero-day malware sample is detonated, the FortiGate immediately blocks the file hash and the C2 callback. Which FortiSandbox integration method should the administrator configure on the FortiGate to achieve this?

Medium
74

A security analyst is reviewing FortiGate logs and notices that a known malicious file hash is being downloaded repeatedly, but the antivirus profile is not blocking it. The file is detected by FortiSandbox, and the FortiGate has a valid FortiGuard license. Which action should the analyst take to ensure the hash is blocked on subsequent downloads?

Hard
75

An administrator configured FortiGate to forward suspected malicious files to FortiSandbox. They set the action to 'block' for malicious verdicts. Some files are being blocked, but others with a 'clean' verdict are allowed. However, they notice that some files that should have been sent to FortiSandbox are not being forwarded. Which reason is MOST likely?

Hard
76

A security engineer wants to implement advanced threat protection for email using FortiMail. Which THREE features should be enabled to provide comprehensive protection against sophisticated email threats? (Choose three.)

Hard
77

An administrator is investigating a security incident where a workstation is communicating with a known command and control (C2) server. The FortiGate has IPS enabled but did not block the traffic. Which TWO configuration issues could explain why the IPS did not detect the C2 communication? (Choose two.)

Medium
78

A security administrator is configuring a FortiGate to use an external threat intelligence feed to block malicious IP addresses. The administrator wants the FortiGate to automatically update the list of malicious IPs from a threat feed and use it in firewall policies. Which FortiGate feature should be used?

Medium
79

An administrator is configuring FortiGate to inspect SSL traffic for malware. They enable deep inspection in the SSL inspection profile and apply it to a firewall policy. Users report that some HTTPS websites are showing certificate errors. What is the most likely cause?

Medium
80

An administrator configures an automation stitch on FortiGate to automatically block an IP address when a specific IPS signature triggers. What must be configured as the trigger and action?

Medium
81

A company wants to use FortiMail to implement email authentication to prevent spoofing. Which THREE mechanisms should be configured in FortiMail's Authentication Profile?

Medium
82

An administrator is configuring a FortiGate to detect and block traffic to known malicious domains using DNS filtering. The administrator wants to ensure that DNS queries for malicious domains are blocked and that users are redirected to a block page. Which DNS filter action should be configured?

Medium
83

During a security incident, the SOC team receives an alert from FortiSIEM about a user accessing a known malicious IP. The team wants to automatically block the IP on the FortiGate. Which FortiGate feature can be used to create an automated response based on a threat intelligence feed?

Hard
84

Which FortiMail advanced feature allows the administrator to rewrite URLs in email bodies to redirect users to a safe scanning service when they click on a link?

Medium
85

A FortiGate administrator is configuring a firewall policy to inspect traffic for advanced threats. The administrator wants to ensure that the policy uses both antivirus and IPS inspection, and that the traffic is inspected in a way that minimizes latency while still detecting threats. Which two actions should the administrator take? (Choose two.)

Medium
86

What is the primary function of Content Disarm and Reconstruction (CDR) in FortiGate's antivirus profile?

Easy
87

A network administrator wants to ensure that files downloaded from the internet are analyzed by FortiSandbox before being delivered to the client. The FortiGate is configured with a FortiSandbox connection and an antivirus profile. Which setting must be enabled in the antivirus profile to submit files to FortiSandbox?

Medium
88

An administrator needs to enable automation stitches to automatically block a malicious IP address detected by FortiSandbox. Which two components are required? (Choose two.)

Medium
89

An administrator runs 'diagnose sys session filter dport 443' and sees the following output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate about the session?

Hard
90

A security administrator is configuring a FortiGate to block outbound traffic to known command-and-control (C2) servers. The administrator wants to use a dynamic, cloud-based threat intelligence service that is continuously updated by Fortinet. Which FortiGuard service should be enabled to block traffic based on the latest C2 IP addresses and domains?

Medium
91

Which FortiGate IPS feature allows administrators to create rules that detect network traffic patterns deviating from normal protocol behavior?

Easy
92

A company uses FortiMail for email security. They want to prevent email spoofing by verifying that incoming emails originate from authorized servers. Which email authentication method should be configured on FortiMail to check the sending server's IP against a published SPF record?

Medium
93

A network security team is evaluating options for web application security. They need to protect a critical web application from SQL injection and cross-site scripting (XSS) attacks, and they require granular control over HTTP request parameters. Which THREE factors should influence their decision between using FortiGate's WAF profiles versus deploying a dedicated FortiWeb appliance?

Hard
94

An administrator runs 'diagnose ips anomaly http' and sees many entries with 'type=SQLi' and 'score=0'. What does a score of 0 indicate?

Hard
95

An administrator is configuring FortiMail to improve email security. Which three of the following features are part of FortiMail's advanced threat protection? (Choose three.)

Hard
96

A FortiGate administrator wants to use threat intelligence feeds to block known malicious IP addresses. Which TWO steps are required to accomplish this? (Choose two.)

Medium
97

A FortiGate administrator is using the built-in FortiGuard web filter to block malicious websites. Users report that they can still access a site that is categorized as 'Malware' by FortiGuard. The administrator verifies that the web filter profile is applied to the policy and that the category is set to block. What is the most likely reason for this issue?

Medium
98

An administrator configures a WAF profile on FortiGate to protect a web application. However, the administrator notices that SQL injection attacks are not being blocked. What should the administrator check first?

Medium
99

Which of the following best describes the function of FortiDeceptor in an enterprise network?

Easy
100

An administrator is configuring a FortiGate to block outbound traffic to known malicious IP addresses. They want the block list to be updated automatically from a commercial threat intelligence service that provides a REST API. Which FortiGate feature should be used?

Medium
101

Which Fortinet product is designed specifically to detect and deceive attackers by creating decoy systems and luring them away from real assets?

Easy
102

An organization uses FortiWeb to protect its web applications. The security team wants to block requests that contain a specific custom pattern in the URL. Which feature should be used?

Medium
103

What is the primary purpose of Content Disarm and Reconstruction (CDR) in advanced antivirus protection?

Easy
104

An organization wants to implement a solution that can detect and automatically respond to threats across multiple Fortinet security products. Which product should they use?

Medium
105

An administrator has configured FortiSandbox integration with FortiGate. Files are being submitted, but the firewall is not blocking subsequent downloads of files that FortiSandbox later identifies as malicious. The administrator verifies that the FortiSandbox license is valid and the connection is up. Which configuration is most likely missing?

Hard
106

What is the primary purpose of FortiGuard Outbreak Prevention service?

Easy
107

An organization wants to prevent users from downloading malicious files from the internet. Which FortiGate security profile should be applied to the outbound firewall policy to block files based on their hash if they have been identified as malicious by FortiSandbox?

Easy
108

A FortiGate administrator wants to stop outbound DNS queries to a known malicious domain that is not present in any static blocklist. The administrator has already licensed FortiGuard DNS Filtering and enabled DNS filtering on the firewall policy. Which FortiGuard service must the FortiGate resolve the domain against so that the query is blocked based on the latest threat intelligence?

Medium
109

A FortiGate administrator is troubleshooting why a custom IPS signature is not triggering on traffic matching the pattern. Which TWO checks should be performed?

Hard
110

A FortiGate admin sees the following log: 'Action=blocked, Service=HTTP, Application=Outbreak, File=invoice.doc, ThreatScore=95'. What is the MOST likely explanation for this block?

Hard
111

Which Fortinet product is designed to deploy decoy systems to lure attackers and detect lateral movement within the network?

Easy
112

An administrator wants to create an automation stitch that sends a webhook notification when an IPS attack is detected. Which trigger and action should be used?

Medium
113

Refer to the exhibit. A user reports that accessing a legitimate HTTPS website is blocked. The FortiGate logs show that the connection was denied by the antivirus profile. What is the most likely cause?

Medium
114

Which FortiGate security feature removes potentially malicious active content from files (e.g., macros, scripts) before delivering them to end users?

Easy
115

What is the role of FortiGuard Outbreak Prevention in FortiGate's security suite?

Easy
116

An administrator configures an automation stitch to respond to a high severity event. The trigger is 'event' and the action is 'CLI script'. What must be defined for the action to execute properly?

Medium
117

A company uses an advanced antivirus profile with machine learning engine enabled. After a recent outbreak, several files that were previously undetected are now flagged. How does the outbreak prevention feature help in this situation?

Hard
118

An administrator wants to secure email traffic by ensuring that incoming emails are verified against the sender's domain SPF record. Which email authentication method provides this verification?

Easy
119

A security administrator is deploying FortiDeceptor in a data center network. They want to detect an attacker who is performing internal reconnaissance by scanning the subnet for live hosts. Which FortiDeceptor component should the administrator deploy to generate a decoy IP address that responds to such scans and alerts on any interaction?

Medium
120

A FortiGate administrator is configuring an antivirus profile to protect against unknown malware. The administrator wants to use machine learning to detect malicious files based on their behavior and characteristics without relying solely on signatures. Which antivirus feature should be enabled to meet this requirement?

Easy
121

Which feature in FortiMail provides an additional layer of protection by analyzing the behavior of email attachments in a sandbox environment?

Easy
122

An administrator is configuring a FortiGate to detect and block command and control (C2) traffic using FortiGuard's Indicator of Compromise (IoC) service. The administrator wants to ensure that the firewall checks DNS queries and HTTP requests against the IoC database. Which feature should be enabled on the FortiGate to accomplish this?

Medium
123

A FortiGate is configured with an SSL inspection profile that uses a deep-inspection mode. Users complain that a banking website fails to load, but HTTP sites work. The administrator confirms the site uses TLS 1.3 with Encrypted Client Hello (ECH) and certificate pinning. Which action should the administrator take to restore access while maintaining visibility for other traffic?

Hard
124

An administrator configures a custom IPS signature to detect traffic to a specific malicious domain. Which syntax is correct for a custom IPS signature in FortiGate?

Hard
125

A security analyst is reviewing logs from a FortiGate that uses FortiGuard IPS. The analyst notices that a signature for a recent Apache Struts vulnerability is not triggering even though the vulnerable service is exposed. The FortiGate is running the latest IPS engine and signature database. Which action should the analyst take to verify whether the signature is enabled and properly applied to the traffic?

Hard
126

Which FortiGate security feature can reconstruct files to remove potentially malicious content while preserving the file's usability?

Easy
127

An administrator is configuring FortiMail to be more secure against advanced email threats. Which THREE features should they enable to protect against email-based phishing attacks?

Easy
128

A security analyst is investigating alerts from FortiGate's IPS. They notice that an attack was detected but not blocked, even though the IPS profile is set to block. The log shows the action as 'detected'. What is the most likely reason for this behavior?

Medium
129

A network administrator notices that several endpoints are infected with ransomware despite having FortiGate ATP enabled. The logs show that the files were downloaded over HTTPS, and the antivirus profile did not detect them. What is the most likely reason?

Medium
130

A network administrator notices that FortiGate is not blocking a known malicious file that was submitted to FortiSandbox and received a 'malicious' verdict. The firewall policy includes a FortiSandbox inline scan profile. What is the MOST likely cause?

Medium
131

An administrator is configuring a FortiGate to use the external threat feed feature to block traffic from known malicious IP addresses. They want to ensure that the feed is automatically updated and that the firewall blocks traffic based on the feed. Which two actions must the administrator perform? (Choose two.)

Hard
132

What is the primary function of FortiDeceptor in a network security architecture?

Easy
133

An admin wants to ensure that office documents (e.g., Word, Excel) downloaded from the internet are safe before users open them. Which feature should be used to remove potentially malicious macros and active content?

Medium
134

What is the purpose of FortiDeceptor in an enterprise security architecture?

Easy
135

A FortiGate administrator is configuring a web filter profile to block access to known malicious websites. The administrator wants to ensure that the firewall blocks sites based on FortiGuard category 'Malicious Websites' and also logs the blocked attempts. Which action should the administrator take?

Medium
136

An admin receives an email from FortiMail regarding a message that was rejected due to SPF failure. What does this indicate about the email?

Medium
137

What is the primary benefit of using FortiClient with ATP features in conjunction with FortiGate?

Easy
138

An administrator wants to detect lateral movement and early stages of an attack using decoy systems that mimic production assets. Which Fortinet product should they deploy?

Medium
139

A company uses FortiWeb to protect its web application. They want to block SQL injection attempts. Which FortiWeb feature should be configured to inspect HTTP requests for malicious SQL patterns?

Hard
140

An administrator is configuring FortiDeceptor to detect threats within the network. Which TWO statements about FortiDeceptor are correct?

Medium
141

A company has deployed FortiClient with advanced threat protection (ATP) features. Which TWO capabilities does FortiClient ATP provide beyond basic antivirus?

Medium
142

An admin wants to block malicious files detected by FortiSandbox at the FortiGate level. Which configuration is required on the FortiGate to automatically block files based on FortiSandbox verdict?

Medium
143

Which FortiClient feature is specifically designed to prevent the execution of unknown malware by analyzing behavior in real-time?

Easy
144

An administrator wants to protect against zero-day malware that has not yet been discovered by signature-based detection. Which TWO technologies can help mitigate such threats?

Medium
145

An administrator runs the following CLI output: 'diagnose sys session filter dport 443' and sees 'proto=6 proto_state=01 duration=3600 expire=3599'. Which statement BEST describes the session?

Hard
146

A FortiGate administrator wants to implement Content Disarm and Reconstruction (CDR) for email attachments. Which security profile must be configured to enable CDR?

Medium
147

An IPS administrator wants to detect a new custom attack that sends malformed HTTP headers. The attack pattern is a specific sequence of bytes that is not covered by existing signatures. What is the BEST way to detect this attack on FortiGate?

Medium
148

An email security administrator wants to prevent attackers from spoofing the company's domain. Which email authentication mechanism should be configured to allow receiving servers to verify that emails claiming to be from the domain are sent from authorized mail servers?

Medium
149

A FortiGate administrator configures a custom IPS signature with the pattern 'attack' in the HTTP request URI. After applying the signature, no alerts are generated even though the traffic matches. What is the MOST likely cause?

Hard
150

An administrator wants to configure FortiGate to automatically block a source IP when a high-severity IPS event is detected. Which TWO components must be configured? (Choose two.)

Medium
151

A FortiGate administrator has configured a firewall policy with a web filter profile that uses a FortiGuard category action to block 'Malware' websites. Users report that they can still access some known malicious sites that are categorized as 'Malware'. The administrator verifies that the FortiGuard service is reachable and the license is valid. What is the most likely cause?

Medium
152

An NSE7 administrator is configuring a FortiGate to use the built-in intrusion prevention system (IPS) to detect and block exploits targeting a custom web application. The administrator wants to ensure that the IPS engine inspects all HTTP traffic, including encrypted sessions, without impacting performance. Which FortiGate feature should be enabled to allow IPS inspection of SSL/TLS traffic?

Medium
153

A FortiGate running FortiOS 7.4 is configured with a firewall policy that references an IPS sensor. The sensor uses a custom signature to detect a recently discovered exploit. Users report that the exploit traffic is not being blocked even though the signature is enabled. The administrator confirms the traffic matches the signature and that the policy is in flow-based inspection mode. Which action should the administrator take to ensure the IPS sensor can block the exploit?

Medium
154

Which Fortinet product provides endpoint detection and response (EDR) capabilities, including automated threat containment?

Easy
155

A company is deploying FortiClient ATP to protect endpoints. They want to block ransomware behavior in real time. Which FortiClient feature should be enabled?

Medium
156

A network administrator is deploying FortiGate to protect against unknown malware. They want to use machine learning to detect and block malicious files without relying on signatures. Which antivirus scanning technique should be enabled to achieve this?

Easy
157

A FortiGate administrator has configured an antivirus profile with sandbox inspection and applied it to a firewall policy. Users report that downloads of executable files are delayed significantly, but eventually complete. The administrator wants to reduce the delay while still blocking malicious files before they reach the endpoint. Which change should the administrator make?

Hard

Frequently asked questions

What does the Advanced Threat Protection domain cover on the NSE7 exam?
Be able to map a threat scenario to the right Fortinet components: IPS sensor plus automation stitch for auto-blocking, FortiSIEM or FortiAnalyzer for correlation, FortiEDR for endpoint containment. The key is pairing the correct trigger with the correct response action.
How many questions are in this domain?
This page lists all 157 Advanced Threat Protection questions in the NSE7 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Advanced Threat Protection questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
fortinet-nse7 FORTINET-NSE7 nse7 atp Practice Questions