(How does FortiAnalyzer block indicators? (Choose one answer))
Comprehensive and Detailed Explanation From Exact Extract of knowledge of FortiAnalyzer 7.6 Study guide documents:
The FortiAnalyzer study guide states that blocking suspicious indicators is performed by integrating FortiAnalyzer with FortiManager (not by directly pushing a block list to FortiGate). Specifically: ''To use this feature, you must set up an authorized FortiManager connector for the FortiAnalyzer on the Fabric Connector page of FortiAnalyzer.''
It then explains the backend mechanism: ''In the back end, a playbook called Block_indicator runs every 5 minutes to send the information to FortiManager.'' After a successful run, ''the blocked indicator is pushed to the FortiManager External Resource list.'' From there, FortiManager can create threat feeds/security profiles/policy blocks and push policies to FortiGate as needed---however, the study guide clarifies: ''The Blocked status on FortiAnalyzer confirms that the list is updated on FortiManager, but it is not synced to FortiGate.''
Therefore, FortiAnalyzer blocks indicators by using a FortiManager connector and sending the block information to FortiManager (Option B).
Maile
7 hours agoCrista
5 days agoMalcolm
11 days agoCandida
16 days agoChauncey
21 days agoDanilo
26 days agoEun
1 month agoRosio
1 month agoBettyann
1 month agoEdda
2 months agoMalinda
2 months agoLenora
2 months agoRima
2 months agoVirgie
2 months agoCarylon
2 months agoMalcolm
3 months agoCristal
3 months agoSanjuana
3 months ago