Courseiva
Advanced Threat Protection →mediumMultiple Choice

NSE7 Advanced Threat Protection Practice Question

Which Fortinet solution collects and correlates security events from multiple sources to provide a unified view of threats across the network?

⚠ Common exam trap

Watch out — candidates often confuse FortiSandbox or FortiEDR as the central correlation tool because they are prominent in the Fortinet Advanced Threat Protection (ATP) framework, but they lack the multi-source event aggregation and correlation that is the defining function of a SIEM like FortiSIEM.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

FortiSIEM

FortiSIEM is the correct answer because it is specifically designed as a Security Information and Event Management (SIEM) solution that aggregates, normalizes, and correlates logs and events from diverse sources—including firewalls, endpoints, servers, and cloud platforms—into a single pane of glass. It uses a patented event correlation engine and a unified event database to detect multi-stage attack patterns and provide actionable threat intelligence, fulfilling the requirement for a unified view of threats across the network.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    FortiSIEM

    Why this is correct

    FortiSIEM aggregates logs and events from disparate network devices, then correlates them to surface unified threat views. This collection-and-correlation mechanism directly satisfies the stem's requirement for a single consolidated picture of threats across the network.

  • ✗

    FortiSandbox

    Why it's wrong here

    FortiSandbox detonates suspicious files and URLs in an isolated environment to reveal zero-day behaviour; it does not aggregate logs from disparate sources. Its telemetry can feed a correlating platform, but the collection and unified threat view come from FortiSIEM or FortiAnalyzer, making sandboxing the wrong layer for this requirement.

  • ✗

    FortiDeceptor

    Why it's wrong here

    FortiDeceptor deploys decoys and lures to detect attackers inside the network; it generates its own deception telemetry rather than aggregating and correlating events from existing sources. It is tempting because its console shows attacker activity, and FortiDeceptor would be correct for early-stage breach detection and threat deception.

  • ✗

    FortiEDR

    Why it's wrong here

    FortiEDR monitors and responds to activity on individual endpoints, so it cannot correlate events drawn from network, cloud and other telemetry into one cross-domain threat view. It is tempting because EDR consoles do present detections centrally, and FortiEDR would be correct for endpoint detection and response.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.