Courseiva
Advanced Threat ProtectioneasyMultiple ChoiceObjective-mapped

NSE7 Advanced Threat Protection Practice Question

Which Fortinet product is designed to deploy decoy systems to lure attackers and detect lateral movement within the network?

⚠ Common exam trap

Many exam-takers confuse FortiDeceptor with FortiSandbox, assuming sandboxing involves decoys, but FortiSandbox focuses on file analysis while FortiDeceptor is purpose-built for deception-based threat detection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

FortiDeceptor

FortiDeceptor is specifically designed to deploy decoy systems (honeypots) that mimic real assets, such as servers or endpoints, to lure attackers. It detects lateral movement by monitoring decoy interactions and generating alerts when an attacker probes or compromises these fake targets, providing early warning of network intrusion.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • FortiSandbox

    Why it's wrong here

    FortiSandbox analyzes files for malware, not decoys.

  • FortiDeceptor

    Why this is correct

    FortiDeceptor deploys decoys to detect and deceive attackers.

  • FortiSOAR

    Why it's wrong here

    FortiSOAR is a SOAR platform, not decoy deployment.

  • FortiEDR

    Why it's wrong here

    FortiEDR focuses on endpoint detection, response, and real-time threat prevention on individual hosts, not on deploying decoy systems to lure attackers. Its deception capabilities are limited to alerting on suspicious process behaviour, not simulating full network decoys. It is tempting because many associate EDR with threat hunting, but the correct product for decoy-based lateral movement detection is FortiDeceptor, which actively deploys honeypots and lures across the network.

About these practice questions

This NSE7 question is part of Courseiva's 940-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on NSE7

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which Fortinet product is specifically designed to deploy decoys and lures to detect lateral movement and early-stage attacks inside the network?

easy
  • A.FortiSandbox
  • B.FortiEDR
  • C.FortiDeceptor
  • D.FortiClient

Why C: FortiDeceptor is specifically designed to deploy decoys and lures that mimic real assets (e.g., servers, endpoints, IoT devices) to attract and detect lateral movement and early-stage attacks inside the network. It uses deception technology to create a realistic attack surface, triggering alerts when an attacker interacts with a decoy, without relying on signatures or behavioral analysis.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.