Courseiva

NSE7 · topic practice

Advanced Threat Protection practice questions

This domain covers Fortinet's Advanced Threat Protection tooling on FortiGate and Fabric: IPS sensors and custom signatures, anomaly detection, automated threat response via automation stitches and quarantine, and event correlation through FortiAnalyzer and FortiSIEM. Questions are scenario-based, asking you to pick the correct components, features, or products that satisfy a stated security outcome.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Advanced Threat Protection

What the exam tests

What to know about Advanced Threat Protection

Be able to map a threat scenario to the right Fortinet components: IPS sensor plus automation stitch for auto-blocking, FortiSIEM or FortiAnalyzer for correlation, FortiEDR for endpoint containment. The key is pairing the correct trigger with the correct response action.

Configuring IPS sensors, custom signatures, and protocol anomaly detection on FortiGate

Building automation stitches with triggers and actions to block source IPs automatically

Using FortiAnalyzer and FortiSIEM for event collection, correlation, and unified threat views

Deploying FortiEDR and FortiClient EMS for endpoint detection, response, and automated containment

Watch out for

Common Advanced Threat Protection exam traps

  • ▸Choosing automation stitches alone when the scenario also requires an IPS sensor with the right severity trigger and action.
  • ▸Confusing FortiAnalyzer log aggregation with FortiSIEM correlation, or picking FortiSandbox for event correlation it does not perform.
  • ▸Assuming anomaly detection is a separate module rather than an IPS sensor feature configured with protocol anomaly signatures.

Practice set

Advanced Threat Protection questions

20 questions · select your answer, then reveal the explanation

A FortiGate administrator receives alerts about a device communicating with a known botnet C2 server. The traffic is encrypted with TLS. Which ATP feature is most effective to block this communication?

Which TWO features are part of FortiGate's Advanced Threat Protection (ATP) suite?

Which THREE actions should be taken to optimize FortiGate ATP performance while maintaining security?

Refer to the exhibit. An administrator notices that some malware files are not being detected by FortiGate. The antivirus profile uses flow-based scanning with FortiSandbox disabled. What is the most likely reason for missed detections?

Exhibit

Refer to the exhibit.

config antivirus profile
    edit "default"
        set comment "Default antivirus"
        config http
            set options scan
            set av-scan mode=flow-based
            set fortisandbox inline-scan disable
            set quarantine enable
        end
        config ftp
            set options scan
            set av-scan mode=flow-based
            set fortisandbox inline-scan disable
            set quarantine enable
        end
        config smb
            set options scan
            set av-scan mode=flow-based
            set fortisandbox inline-scan disable
            set quarantine enable
        end
    next
end
Question 5hardmultiple choice
Read the full VPN explanation →

A large enterprise uses FortiGate as their perimeter firewall with ATP features enabled. They have a mix of internal users and remote VPN users. Recently, several remote users reported that their machines became infected with ransomware after connecting to the VPN. The IT team suspects that the ransomware entered through the VPN tunnel. The FortiGate has an antivirus profile applied to the VPN policy with SSL inspection enabled for all traffic. However, the logs show that no malware was detected. Upon investigation, the team finds that the remote users' machines are not managed by the company and do not have any endpoint protection. The ransomware was delivered via a spear-phishing email that the users opened on their remote machines. The email traffic passed through the VPN tunnel to the corporate mail server first, then back to the user. The FortiGate antivirus profile is configured to scan SMTP traffic but the email was sent from an external source to the corporate mail server, and the mail server uses STARTTLS to receive emails. The FortiGate does not perform SSL inspection on the SMTP traffic because the SMTP service is not included in the SSL inspection profile. What action should the administrator take to prevent this in the future?

Question 6mediumdrag order
Review the full OSPF breakdown →

Drag and drop the steps to configure OSPF on a FortiGate firewall into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Match each FortiGate security profile to its category.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Malware protection

URL and content filtering

DNS-based threat protection

Application visibility and control

Intrusion prevention

A network admin configures FortiGate to submit files to FortiSandbox for analysis. After submission, the FortiGate logs show that files are being sent but no verdict is returned. The FortiSandbox is reachable and licensed. What is the most likely cause?

An organization wants to protect against unknown malware by using machine learning on FortiGate. Which antivirus setting should be enabled to achieve this?

A FortiGate administrator wants to block a custom protocol anomaly where a client sends an HTTP request with a malformed header containing a null byte. Which advanced IPS feature should be used?

An organization uses FortiMail and wants to validate that incoming emails are from legitimate senders by checking the sender's domain against a published policy. Which two email authentication mechanisms can FortiMail use? (Choose two.)

A FortiGate admin runs 'diagnose ips anomaly list' and sees many 'tcp_src_session' events from a single internal IP. The admin suspects a scanning attack. What action should be taken to block this traffic without affecting legitimate traffic?

You run 'diagnose sys session filter dport 443' and see the following output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate about the session?

A company uses FortiWeb as a reverse proxy for their web application. They want to protect against SQL injection attacks. Which FortiWeb feature should be configured?

Which TWO of the following are required for FortiGate to successfully obtain file verdicts from FortiSandbox? (Choose two.)

A security administrator wants to implement automated threat response using FortiGate automation stitches. Which THREE components are mandatory when creating an automation stitch? (Choose three.)

Which TWO email authentication mechanisms does FortiMail support to verify sender identity and reduce spoofing? (Choose two.)

A FortiGate administrator configures an antivirus profile with the machine learning engine enabled and applies it to a policy inspecting HTTP traffic. After deployment, the admin notices that some files are being allowed that should have been detected. What is the MOST likely cause?

An administrator configures a FortiGate to integrate with FortiSandbox for inline scanning. The policy has an antivirus profile with FortiSandbox enabled. What condition must be met for files to be submitted to FortiSandbox?

A FortiGate administrator is troubleshooting why files are not being submitted to FortiSandbox for analysis. Which THREE conditions must be met for file submission to work? (Choose three.)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Advanced Threat Protection sessions

Start a Advanced Threat Protection only practice session

Every question in these sessions is drawn from the Advanced Threat Protection domain — nothing else.

Related practice questions

Related NSE7 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the NSE7 exam test about Advanced Threat Protection?
Be able to map a threat scenario to the right Fortinet components: IPS sensor plus automation stitch for auto-blocking, FortiSIEM or FortiAnalyzer for correlation, FortiEDR for endpoint containment. The key is pairing the correct trigger with the correct response action.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Advanced Threat Protection questions in a focused session?
Yes — the session launcher on this page draws every question from the Advanced Threat Protection domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other NSE7 topics?
Use the topic links above to move to related areas, or go back to the NSE7 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the NSE7 exam covers. They are not copied from any real exam or dump site.