Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet FCP_FAZ_AN-7.6 Exam - Topic 2 Question 13 Discussion

What happens when the indicator of compromise (IOC) engine on FortiAnalyzer finds web logs that match blacklisted IP addresses?
B) A new infected entry is added for the corresponding endpoint under Compromised Hosts.
A) FortiAnalyzer flags the associated host for further analysis.
C) The detection engine classifies those logs as Suspicious.
D) The endpoint is marked as Compromised and, optionally, can be put in quarantine.

Fortinet FCP_FAZ_AN-7.6 Exam - Topic 2 Question 13 Discussion

Actual exam question for Fortinet's FCP_FAZ_AN-7.6 exam
Question #: 13
Topic #: 2
[All FCP_FAZ_AN-7.6 Questions]

What happens when the indicator of compromise (IOC) engine on FortiAnalyzer finds web logs that match blacklisted IP addresses?

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

0/2000 characters
Lucina
21 days ago
B makes sense. We need to track infected endpoints.
upvoted 0 times
...
Virgilio
27 days ago
I prefer A. Flagging for analysis is important too.
upvoted 0 times
...
Elroy
1 month ago
I think D is the best answer. Quarantine is crucial.
upvoted 0 times
...
Kate
1 month ago
B) is also true, it adds to Compromised Hosts.
upvoted 0 times
...
Alethea
1 month ago
Wait, so it actually marks the endpoint as Compromised? That's surprising!
upvoted 0 times
...
Lili
2 months ago
I think D) is a bit extreme, quarantine might not be necessary.
upvoted 0 times
...
Kelvin
2 months ago
Totally agree, that's how it should work!
upvoted 0 times
...
Gracia
2 months ago
A) is correct, it flags the host for analysis.
upvoted 0 times
...
Cecilia
2 months ago
I'm leaning towards option D because quarantining seems like a common response for compromised endpoints.
upvoted 0 times
...
Ma
2 months ago
I feel like the logs would be classified as Suspicious, but I can't recall if that's the main action taken.
upvoted 0 times
...
Emilio
2 months ago
I remember something about compromised hosts, so maybe option B is correct? It sounds familiar.
upvoted 0 times
...
Lachelle
3 months ago
I think when the IOC engine finds a match, it might flag the host for further analysis, but I'm not entirely sure.
upvoted 0 times
...

Save Cancel