NSE7 Advanced Threat Protection Practice Question
Which Fortinet solution collects and correlates security events from multiple sources to provide a unified view of threats across the network?
⚠ Common exam trap
Watch out — candidates often confuse FortiSandbox or FortiEDR as the central correlation tool because they are prominent in the Fortinet Advanced Threat Protection (ATP) framework, but they lack the multi-source event aggregation and correlation that is the defining function of a SIEM like FortiSIEM.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
FortiSIEM
FortiSIEM is the correct answer because it is specifically designed as a Security Information and Event Management (SIEM) solution that aggregates, normalizes, and correlates logs and events from diverse sources—including firewalls, endpoints, servers, and cloud platforms—into a single pane of glass. It uses a patented event correlation engine and a unified event database to detect multi-stage attack patterns and provide actionable threat intelligence, fulfilling the requirement for a unified view of threats across the network.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
FortiSIEM
Why this is correct
FortiSIEM aggregates logs and events from disparate network devices, then correlates them to surface unified threat views. This collection-and-correlation mechanism directly satisfies the stem's requirement for a single consolidated picture of threats across the network.
- ✗
FortiSandbox
Why it's wrong here
FortiSandbox detonates suspicious files and URLs in an isolated environment to reveal zero-day behaviour; it does not aggregate logs from disparate sources. Its telemetry can feed a correlating platform, but the collection and unified threat view come from FortiSIEM or FortiAnalyzer, making sandboxing the wrong layer for this requirement.
- ✗
FortiDeceptor
Why it's wrong here
FortiDeceptor deploys decoys and lures to detect attackers inside the network; it generates its own deception telemetry rather than aggregating and correlating events from existing sources. It is tempting because its console shows attacker activity, and FortiDeceptor would be correct for early-stage breach detection and threat deception.
- ✗
FortiEDR
Why it's wrong here
FortiEDR monitors and responds to activity on individual endpoints, so it cannot correlate events drawn from network, cloud and other telemetry into one cross-domain threat view. It is tempting because EDR consoles do present detections centrally, and FortiEDR would be correct for endpoint detection and response.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.