NSE7 Enterprise Firewall and VDOMs Practice Question
Which FortiAnalyzer feature allows administrators to create automated response actions triggered by specific log events, such as blocking an IP address when an intrusion is detected?
⚠ Common exam trap
Candidates often confuse Playbooks with Incidents, assuming Incidents include automation, but Incidents are purely for manual or semi-manual investigation workflows, while Playbooks are the only feature for fully automated, event-triggered responses.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Playbooks
Playbooks in FortiAnalyzer allow administrators to define automated response actions triggered by specific log events, such as blocking an IP address when an intrusion is detected. This feature uses a visual workflow editor to chain conditions and actions (e.g., executing CLI commands via FortiGate API or sending alerts) based on real-time log analysis, enabling automated threat mitigation without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
FortiView
Why it's wrong here
FortiView is a monitoring and visualisation console for logs and traffic, not an automation engine, so it cannot trigger actions such as blocking an IP. It is the right tool when the requirement is investigating and visualising events rather than responding to them automatically.
- ✗
Reports
Why it's wrong here
Reports aggregate and present historical log data for review; they generate no enforcement action against a detected intrusion. Blocking an IP on a log trigger needs the automation stitches/playbook engine. Reports would be correct when the requirement is scheduled visibility or compliance evidence rather than automated response.
- ✗
Incidents
Why it's wrong here
Incidents correlate and group log events for analyst triage; they do not execute enforcement actions such as blocking an IP. Automated responses require the automation stitches/playbook engine, which triggers actions on matching log events. Incidents would be the right focus when the goal is tracking and investigating a security event's lifecycle.
- ✓
Playbooks
Why this is correct
Playbooks in FortiAnalyzer chain automated response actions to log-event triggers, so an intrusion detection event can invoke a block-IP action without manual intervention. This satisfies the requirement for automated, event-driven response rather than static alerting or scheduled reports.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.