ExamGecko
Question list
Search
Search

Question 52 - FCP_FAZ_AN-7.4 discussion

Report
Export

What happens when the indicator of compromise (IOC) engine on FortiAnalyzer finds web logs that match blacklisted IP addresses?

A.

FortiAnalyzer flags the associated host for further analysis.

Answers
A.

FortiAnalyzer flags the associated host for further analysis.

B.

A new infected entry is added for the corresponding endpoint under Compromised Hosts.

Answers
B.

A new infected entry is added for the corresponding endpoint under Compromised Hosts.

C.

The detection engine classifies those logs as Suspicious.

Answers
C.

The detection engine classifies those logs as Suspicious.

D.

The endpoint is marked as Compromised and, optionally, can be put in quarantine.

Answers
D.

The endpoint is marked as Compromised and, optionally, can be put in quarantine.

Suggested answer: B
asked 27/11/2024
Miguel Tuimil Galdo
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first