Fortinet NSE 7 Advanced Threat Protection 2.5 Exam
Question 1 Which Fortinet component uses dynamic analysis to detect unknown malware?
- FortiAnalyzer
- FortiAP
- FortiSandbox
- FortiSwitch
Answer: C
Explanation: FortiSandbox analyzes suspicious files in an isolated environment to detect zero- day or unknown threats.
Question 2 Which security profile on a FortiGate is primarily responsible for detecting and blocking malicious or compromised websites?
- Intrusion Prevention
- Web Filtering
- Application Control
- Antivirus
Answer: B
Explanation: Web Filtering analyzes URL requests and compares them against threat intelligence to block malicious websites.
- / 4
Fortinet NSE 7 Advanced Threat Protection 2.5 Exam
Question 3 Which type of threat aims to remain undetected for an extended period while it gathers information about the target?
- Advanced Persistent Threat (APT)
- Polymorphic Virus
- Ransomware
- Trojan Horse
Answer: A
Explanation: APTs stealthily infiltrate networks and remain hidden to extract data over a long duration.
Question 4 Which Fortinet product provides global threat research and intelligence updates for FortiGate devices?
- FortiConverter
- FortiCare
- FortiGuard
- FortiSwitch
Answer: C
Explanation: FortiGuard Labs delivers threat intelligence and real-time updates that FortiGate devices use for advanced protection. 2 / 4
Fortinet NSE 7 Advanced Threat Protection 2.5 Exam
Question 5 Which method best describes how FortiSandbox analyzes suspicious files?
- Signature-only scanning
- Static IP analysis
- Dynamic execution in a controlled environment
- Cloud-based script emulation
Answer: C
Explanation: FortiSandbox executes files in a virtual environment to observe real-time malicious behaviors.
Question 6 Which Fortinet solution aggregates logs from multiple FortiGates for centralized analysis?
- FortiManager
- FortiAnalyzer
- FortiSIEM
- FortiToken
Answer: B
Explanation: FortiAnalyzer collects logs, events, and security data for in-depth analysis and threat hunting. 3 / 4
Fortinet NSE 7 Advanced Threat Protection 2.5 Exam
Question 7 Which feature in FortiGate focuses on identifying malicious software through heuristic, behavioral, and reputation-based scanning?
- IPS Sensor
- SSL Inspection
- Antivirus Profile
- Routing Policy
Answer: C
Explanation: The Antivirus profile inspects files using signatures, heuristics, and behavioral analysis to detect malware.
Question 8 In the ATP lifecycle, which step involves taking immediate actions to contain an ongoing attack?
- Detection
- Incident Response
- Post-attack Recovery
- Investigation
Answer: B
Explanation: Incident Response is the phase where security teams actively mitigate and contain the threat.
- / 4