Courseiva
Advanced Threat ProtectionhardMultiple SelectObjective-mapped

NSE7 Advanced Threat Protection Practice Question

Which THREE actions should be taken to optimize FortiGate ATP performance while maintaining security?

⚠ Common exam trap

Many exam-takers assume disabling security profiles (Option B) is acceptable for performance optimization, but the question explicitly requires maintaining security, making this a violation of the core constraint.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Implement allow lists for trusted IP addresses to bypass scanning

Implementing allow lists for trusted IP addresses to bypass scanning (Option A) reduces unnecessary processing of traffic that is known to be safe, thereby optimizing FortiGate ATP performance without compromising security. This approach leverages the FortiGate's ability to exempt trusted sources from deep inspection, which lowers CPU and memory load while maintaining protection for untrusted traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Implement allow lists for trusted IP addresses to bypass scanning

    Why this is correct

    Bypassing scanning for trusted sources improves performance.

  • Disable unnecessary security profiles to reduce CPU load

    Why it's wrong here

    Disabling profiles reduces security.

  • Enable proxy-based inspection for all traffic

    Why it's wrong here

    Proxy-based inspection increases latency.

  • Enable flow-based inspection for antivirus and IPS

    Why this is correct

    Flow-based inspection improves performance.

  • Use SSL certificate inspection only for trusted categories

    Why this is correct

    Selective inspection reduces overhead.

About these practice questions

Courseiva writes every NSE7 question from scratch — 940 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.