New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet FCP_FAZ_AN-7.4 Exam - Topic 2 Question 23 Discussion

Actual exam question for Fortinet's FCP_FAZ_AN-7.4 exam
Question #: 23
Topic #: 2
[All FCP_FAZ_AN-7.4 Questions]

Which log will generate an event with the status Unhandled?

Show Suggested Answer Hide Answer
Suggested Answer: B

In FortiOS 7.4.1 and FortiAnalyzer 7.4.1, the 'Unhandled' status in logs typically signifies that the FortiGate encountered a security event but did not take any specific action to block or alter it. This usually occurs in the context of Intrusion Prevention System (IPS) logs.

IPS logs with action=pass: When the IPS engine inspects traffic and determines that it does not match any known attack signatures or violate any configured policies, it assigns the action 'pass'. Since no action is taken to block or modify this traffic, the status is logged as 'Unhandled.'

Let's look at why the other options are incorrect:

An AV log with action=quarantine: Antivirus (AV) logs with the action 'quarantine' indicate that a file was detected as malicious and moved to quarantine. This is a definitive action, so the status wouldn't be 'Unhandled.'

A WebFilter log will action=dropped: WebFilter logs with the action 'dropped' indicate that web traffic was blocked according to the configured web filtering policies. Again, this is a specific action taken, not an 'Unhandled' event.

An AppControl log with action=blocked: Application Control logs with the action 'blocked' mean that an application was denied access based on the defined application control rules. This is also a clear action, not 'Unhandled.'


Contribute your Thoughts:

0/2000 characters
Staci
8 hours ago
I thought it was D, AppControl logs can be tricky!
upvoted 0 times
...
Marshall
6 days ago
D) An AppControl log with action=blocked? More like an AppControl log with action=comedy!
upvoted 0 times
...
Kelvin
11 days ago
Hmm, I'm going to go with B) An IPS log with action=pass. Seems like the most logical choice.
upvoted 0 times
...
Magdalene
16 days ago
The correct answer is D, because an AppControl log with action=blocked will generate an event with the status Unhandled.
upvoted 0 times
...
Dalene
21 days ago
C) A WebFilter log will action=dropped.
upvoted 0 times
...
Junita
26 days ago
D) An AppControl log with action=blocked.
upvoted 0 times
...
Pearlene
1 month ago
I thought AppControl logs with action=blocked were more likely to be handled, so I'm leaning towards the AV log instead.
upvoted 0 times
...
Lenita
1 month ago
I practiced a similar question, and I feel like the WebFilter log with action=dropped could be a candidate, but I need to double-check.
upvoted 0 times
...
Beula
1 month ago
I remember something about AV logs, but I can't recall if quarantine would actually lead to an Unhandled event.
upvoted 0 times
...
Rosalia
2 months ago
I think it might be the IPS log with action=pass, but I'm not entirely sure how that relates to Unhandled status.
upvoted 0 times
...
Arlyne
2 months ago
I'm leaning towards option C. A WebFilter log with a dropped action seems like it could potentially generate an Unhandled event if the system couldn't properly handle that action.
upvoted 0 times
...
Jerilyn
2 months ago
I think the key here is to focus on the actions that could lead to an Unhandled event. An AV quarantine or WebFilter drop seem like they might fit that criteria.
upvoted 0 times
...
Reena
2 months ago
I think it's B. IPS logs often pass events.
upvoted 0 times
...
Geraldine
2 months ago
B is correct, IPS logs with action=pass are unhandled.
upvoted 0 times
...
Golda
3 months ago
I'm a bit confused on the difference between the log types. Can someone clarify what each one is for?
upvoted 0 times
...
Gladys
3 months ago
I lean towards B as well. Pass means no action taken.
upvoted 0 times
...
Corinne
3 months ago
Okay, let's see. I'm pretty sure an Unhandled event is generated when an action can't be properly processed. So I'll need to look for an action that might cause that.
upvoted 0 times
...
Corrinne
3 months ago
Hmm, this seems like a tricky one. I'll need to think through the different log types and actions carefully.
upvoted 0 times
Rebecka
2 months ago
I think it's B. The IPS log with action=pass sounds right.
upvoted 0 times
...
...

Save Cancel