Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet FCP_FAZ_AN-7.6 Exam - Topic 2 Question 13 Discussion

What happens when the indicator of compromise (IOC) engine on FortiAnalyzer finds web logs that match blacklisted IP addresses?
B) A new infected entry is added for the corresponding endpoint under Compromised Hosts.
A) FortiAnalyzer flags the associated host for further analysis.
C) The detection engine classifies those logs as Suspicious.
D) The endpoint is marked as Compromised and, optionally, can be put in quarantine.

Fortinet FCP_FAZ_AN-7.6 Exam - Topic 2 Question 13 Discussion

Actual exam question for Fortinet's FCP_FAZ_AN-7.6 exam
Question #: 13
Topic #: 2
[All FCP_FAZ_AN-7.6 Questions]

What happens when the indicator of compromise (IOC) engine on FortiAnalyzer finds web logs that match blacklisted IP addresses?

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

0/2000 characters
Lili
2 days ago
I think D) is a bit extreme, quarantine might not be necessary.
upvoted 0 times
...
Kelvin
7 days ago
Totally agree, that's how it should work!
upvoted 0 times
...
Gracia
12 days ago
A) is correct, it flags the host for analysis.
upvoted 0 times
...
Cecilia
17 days ago
I'm leaning towards option D because quarantining seems like a common response for compromised endpoints.
upvoted 0 times
...
Ma
23 days ago
I feel like the logs would be classified as Suspicious, but I can't recall if that's the main action taken.
upvoted 0 times
...
Emilio
28 days ago
I remember something about compromised hosts, so maybe option B is correct? It sounds familiar.
upvoted 0 times
...
Lachelle
1 month ago
I think when the IOC engine finds a match, it might flag the host for further analysis, but I'm not entirely sure.
upvoted 0 times
...

Save Cancel