Courseiva

NSE7 Advanced Threat Protection Practice Question

Which FortiGate security feature can reconstruct files to remove potentially malicious content while preserving the file's usability?

⚠ Common exam trap

Candidates often confuse FortiSandbox's detection capabilities with CDR's proactive sanitization, mistakenly thinking sandboxing can reconstruct files when it only analyzes and blocks them.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Content Disarm and Reconstruction

Content Disarm and Reconstruction (CDR) is the correct answer because it actively removes potentially malicious content—such as macros, scripts, or embedded objects—from files (e.g., Office documents, PDFs) and then reconstructs a clean, usable version. Unlike detection-based approaches, CDR eliminates threats by sanitizing the file structure itself, ensuring the file remains functional for the end user while blocking exploits.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Antivirus outbreak prevention

    Why it's wrong here

    Outbreak prevention blocks or quarantines traffic matching known outbreak signatures; it never rewrites file contents. Content disarm and reconstruction, which rebuilds files into safe usable form, is the requirement here. Outbreak prevention would be chosen when a zero-day outbreak demands immediate signature-based blocking before FortiGuard updates reach the device.

  • ✓

    Content Disarm and Reconstruction

    Why this is correct

    Content Disarm and Reconstruction strips active elements such as macros, scripts and embedded objects from files, then rebuilds a clean version. The file remains openable and usable, satisfying the requirement to remove malicious content while preserving usability.

  • ✗

    FortiSandbox

    Why it's wrong here

    FortiSandbox detonates suspicious files in an isolated environment and returns a verdict; it does not strip malicious elements and return a sanitised, still-usable file. Content disarm and reconstruction performs that rewriting. FortiSandbox is the right pick when unknown files need behavioural analysis before a block or allow decision.

  • ✗

    IPS application control

    Why it's wrong here

    IPS application control matches signatures and application patterns to block or shape traffic; it cannot parse a file's internal structure and rebuild it minus malicious objects. Content disarm and reconstruction does that. Application control fits when the goal is identifying and controlling which applications traverse the network.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.