ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 39 - NSE8_812 discussion

Report
Export

Refer to the exhibit.

The exhibit shows the forensics analysis of an event detected by the FortiEDR core In this scenario, which statement is correct regarding the threat?

A.
This is an exfiltration attack and has been stopped by FortiEDR.
Answers
A.
This is an exfiltration attack and has been stopped by FortiEDR.
B.
This is an exfiltration attack and has not been stopped by FortiEDR
Answers
B.
This is an exfiltration attack and has not been stopped by FortiEDR
C.
This is a ransomware attack and has not been stopped by FortiEDR.
Answers
C.
This is a ransomware attack and has not been stopped by FortiEDR.
D.
This is a ransomware attack and has been stopped by FortiEDR
Answers
D.
This is a ransomware attack and has been stopped by FortiEDR
Suggested answer: D

Explanation:

The exhibit shows the forensics analysis of an event detected by the FortiEDR core. The event graph indicates that a process named svchost.exe was launched by a malicious file named 1.exe, which was downloaded from a suspicious URL. The process then attempted to encrypt files in various folders, such as Documents, Pictures, and Desktop, which are typical targets of ransomware attacks.

However, FortiEDR was able to stop the process and prevent any file encryption by applying its realtime post-execution prevention feature. Therefore, this is a ransomware attack and has been stopped by FortiEDR. Reference: https://docs.fortinet.com/document/fortiedr/6.0.0/administrationguide/ 733983/forensics https://www.fortinet.com/content/dam/fortinet/assets/datasheets/ fortiedr.pdf

asked 18/09/2024
Karlis Priede
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first