Exam2pass
0 items Sign In or Register
  • Home
  • IT Exams
  • Guarantee
  • FAQs
  • Reviews
  • Contact Us
  • Demo
Exam2pass > Fortinet > Fortinet Certifications > NSE7_ATP-2.5 > NSE7_ATP-2.5 Online Practice Questions and Answers

NSE7_ATP-2.5 Online Practice Questions and Answers

Questions 4

Examine the FortiGate antivirus logs shown in the exhibit, than answer the following question:

Based on the logs shown, which of the following statements is correct? (Choose two.)

A. The fsa_dropper.exe file was blocked using a local black list entry.

B. The fsa_sample_1.exe file was not sent to FortiSandbox.

C. The eicar.exe file was blocked using a FortiGiard generated signature.

D. The fsa_downloader.exe file was not blocked by FortiGate.

Buy Now

Correct Answer: BD

File Filter allows the Web Filter profile to block files passing through a FortiGate based on file type. Reference: https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/610893/file-filter

Questions 5

At which stage of the kill chain will an attacker use tools, such as nmap, ARIN, and banner grabbing, on the targeted organization's network?

A. Exploitation

B. Reconnaissance

C. Lateral movement

D. Weaponization

Buy Now

Correct Answer: B

Questions 6

FortiGate root VDOM is authorized and configured to send suspicious files to FortiSandbox for inspection. The administrator creates a new VDOM, and then generates some traffic so that the new VDOM sends a file to FortiSandbox for the first time.

Which of the following is true regarding this scenario?

A. FortiSandbox will accept the file, but not inspect it until the administrator manually configures the new VDOM on FortiSandbox.

B. FortiSandbox will inspect all files based on the root VDOM authorization state and configuration.

C. FortiSandbox will accept the file, but not inspect it until the administrator manually authorizes the new VDOM on FortiSandbox.

D. By default, FortiSandbox will autoauthorize the new VDOM, and inspect files as they are received.

Buy Now

Correct Answer: B

Questions 7

Examine the System Information widget shown in the exhibit, then answer the following question:

Which of the following inspections will FortiSandbox perform on samples submitted for sandboxing? (Choose two.)

A. URL rating on FQDN seen in DNS requests

B. IP reputation check on callback connections

C. Antivirus inspection on downloaded files

D. URL rating on HTTP GET requests

Buy Now

Correct Answer: CD

Questions 8

Which of the kill chain stages does Fortinet's advanced threat protection solution block? (Choose three.)

A. Command and control

B. Delivery

C. Reconnaissance

D. Lateral movement

E. Weaponization

Buy Now

Correct Answer: ACD

Questions 9

Which of the advanced threat protection solutions should you use to protect against an attacker may take during the lateral movement stage of the kill chain? (Choose two.)

A. FortiClient and FortiSandbox

B. FortiMail and FortiSandbox

C. FortiGate and FortiSandbox

D. FortiWeb and FortiSandbox

Buy Now

Correct Answer: BD

Questions 10

Which of the following scan job report sections are generated by static analysis? (Choose two.)

A. Office Behaviors

B. Launched Processes

C. Registry Changes

D. Virtual Simulator

Buy Now

Correct Answer: CD

Questions 11

Examine the CLI configuration, than answer the following question:

Which of the following statements is true regarding this FortiMail's inspection behavior?

A. Malicious URLs will be removed by antispam and replaced with a message.

B. Suspicious files not detected by antivirus will be inspected by FortiSandbox.

C. Known malicious URLs will be inspected by FortiSandbox.

D. Files are skipped by content profile will be inspected by FortiSandbox.

Buy Now

Correct Answer: C

Questions 12

Which FortiWeb feature supports file submission to FortiSandbox?

A. Attack signature

B. Credential stuffing defense

C. IP reputation

D. File security

Buy Now

Correct Answer: C

Questions 13

Examine the scan job report shown in the exhibit, then answer the following question: Which of the following statements are true regarding this verdict? (Choose two.)

A. The file contained malicious JavaScipt.

B. The file contained a malicious macro.

C. The file was sandboxed in two-guest VMs.

D. The file was extracted using sniffer-mode inspection.

Buy Now

Correct Answer: AC

Exam Code: NSE7_ATP-2.5
Exam Name: Fortinet NSE 7 - Advanced Threat Protection 2.5
Last Update: Jun 12, 2025
Questions: 30

PDF (Q&A)

$45.99
ADD TO CART

VCE

$49.99
ADD TO CART

PDF + VCE

$59.99
ADD TO CART

Exam2Pass----The Most Reliable Exam Preparation Assistance

There are tens of thousands of certification exam dumps provided on the internet. And how to choose the most reliable one among them is the first problem one certification candidate should face. Exam2Pass provide a shot cut to pass the exam and get the certification. If you need help on any questions or any Exam2Pass exam PDF and VCE simulators, customer support team is ready to help at any time when required.

Home | Guarantee & Policy |  Privacy & Policy |  Terms & Conditions |  How to buy |  FAQs |  About Us |  Contact Us |  Demo |  Reviews

2025 Copyright @ exam2pass.com All trademarks are the property of their respective vendors. We are not associated with any of them.