Fortinet FCP_FAZ_AN-7.6 Exam - Topic 2 Question 13 Discussion
What happens when the indicator of compromise (IOC) engine on FortiAnalyzer finds web logs that match blacklisted IP addresses?
B) A new infected entry is added for the corresponding endpoint under Compromised Hosts.
A) FortiAnalyzer flags the associated host for further analysis.
C) The detection engine classifies those logs as Suspicious.
D) The endpoint is marked as Compromised and, optionally, can be put in quarantine.
Currently there are no comments in this discussion, be the first to comment!