NSE7 Advanced Threat Protection Practice Question
Which THREE actions should be taken to optimize FortiGate ATP performance while maintaining security?
⚠ Common exam trap
Many exam-takers assume disabling security profiles (Option B) is acceptable for performance optimization, but the question explicitly requires maintaining security, making this a violation of the core constraint.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement allow lists for trusted IP addresses to bypass scanning
Implementing allow lists for trusted IP addresses to bypass scanning (Option A) reduces unnecessary processing of traffic that is known to be safe, thereby optimizing FortiGate ATP performance without compromising security. This approach leverages the FortiGate's ability to exempt trusted sources from deep inspection, which lowers CPU and memory load while maintaining protection for untrusted traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement allow lists for trusted IP addresses to bypass scanning
Why this is correct
Bypassing scanning for trusted sources improves performance.
- ✗
Disable unnecessary security profiles to reduce CPU load
Why it's wrong here
Disabling profiles reduces security.
- ✗
Enable proxy-based inspection for all traffic
Why it's wrong here
Proxy-based inspection increases latency.
- ✓
Enable flow-based inspection for antivirus and IPS
Why this is correct
Flow-based inspection improves performance.
- ✓
Use SSL certificate inspection only for trusted categories
Why this is correct
Selective inspection reduces overhead.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 940 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.