NSE7 Advanced Threat Protection Practice Question
Which Fortinet product is designed to deploy decoy systems to lure attackers and detect lateral movement within the network?
⚠ Common exam trap
Many exam-takers confuse FortiDeceptor with FortiSandbox, assuming sandboxing involves decoys, but FortiSandbox focuses on file analysis while FortiDeceptor is purpose-built for deception-based threat detection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
FortiDeceptor
FortiDeceptor is specifically designed to deploy decoy systems (honeypots) that mimic real assets, such as servers or endpoints, to lure attackers. It detects lateral movement by monitoring decoy interactions and generating alerts when an attacker probes or compromises these fake targets, providing early warning of network intrusion.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
FortiSandbox
Why it's wrong here
FortiSandbox analyzes files for malware, not decoys.
- ✓
FortiDeceptor
Why this is correct
FortiDeceptor deploys decoys to detect and deceive attackers.
- ✗
FortiSOAR
Why it's wrong here
FortiSOAR is a SOAR platform, not decoy deployment.
- ✗
FortiEDR
Why it's wrong here
FortiEDR focuses on endpoint detection, response, and real-time threat prevention on individual hosts, not on deploying decoy systems to lure attackers. Its deception capabilities are limited to alerting on suspicious process behaviour, not simulating full network decoys. It is tempting because many associate EDR with threat hunting, but the correct product for decoy-based lateral movement detection is FortiDeceptor, which actively deploys honeypots and lures across the network.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 940-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on NSE7
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which Fortinet product is specifically designed to deploy decoys and lures to detect lateral movement and early-stage attacks inside the network?
easy- A.FortiSandbox
- B.FortiEDR
- ✓ C.FortiDeceptor
- D.FortiClient
Why C: FortiDeceptor is specifically designed to deploy decoys and lures that mimic real assets (e.g., servers, endpoints, IoT devices) to attract and detect lateral movement and early-stage attacks inside the network. It uses deception technology to create a realistic attack surface, triggering alerts when an attacker interacts with a decoy, without relying on signatures or behavioral analysis.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.