Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet FCP_FAZ_AN-7.6 Exam - Topic 2 Question 14 Discussion

(How does FortiAnalyzer block indicators? (Choose one answer))
B) It uses a FortiManager connector to send the block list.
A) It uses an automation script to update FortiGate with the block list.
C) It uses a FortiClient EMS connector to send the block list.
D) It uses a webhook to allow FortiGate to send the block list.

Fortinet FCP_FAZ_AN-7.6 Exam - Topic 2 Question 14 Discussion

Actual exam question for Fortinet's FCP_FAZ_AN-7.6 exam
Question #: 14
Topic #: 2
[All FCP_FAZ_AN-7.6 Questions]

(How does FortiAnalyzer block indicators? (Choose one answer))

Show Suggested Answer Hide Answer
Suggested Answer: B

Comprehensive and Detailed Explanation From Exact Extract of knowledge of FortiAnalyzer 7.6 Study guide documents:

The FortiAnalyzer study guide states that blocking suspicious indicators is performed by integrating FortiAnalyzer with FortiManager (not by directly pushing a block list to FortiGate). Specifically: ''To use this feature, you must set up an authorized FortiManager connector for the FortiAnalyzer on the Fabric Connector page of FortiAnalyzer.''

It then explains the backend mechanism: ''In the back end, a playbook called Block_indicator runs every 5 minutes to send the information to FortiManager.'' After a successful run, ''the blocked indicator is pushed to the FortiManager External Resource list.'' From there, FortiManager can create threat feeds/security profiles/policy blocks and push policies to FortiGate as needed---however, the study guide clarifies: ''The Blocked status on FortiAnalyzer confirms that the list is updated on FortiManager, but it is not synced to FortiGate.''

Therefore, FortiAnalyzer blocks indicators by using a FortiManager connector and sending the block information to FortiManager (Option B).


Contribute your Thoughts:

0/2000 characters
Maile
7 hours ago
I think it's A. Automation scripts are efficient.
upvoted 0 times
...
Crista
5 days ago
I’m not sure, but B has a strong case.
upvoted 0 times
...
Malcolm
11 days ago
I feel A is the best choice. Automation is the future.
upvoted 0 times
...
Candida
16 days ago
D is interesting, but less likely. Webhooks are complex.
upvoted 0 times
...
Chauncey
21 days ago
C seems plausible too. FortiClient EMS is important.
upvoted 0 times
...
Danilo
26 days ago
B sounds right, centralized management is crucial.
upvoted 0 times
...
Eun
1 month ago
I’m leaning towards B. FortiManager is key.
upvoted 0 times
...
Rosio
1 month ago
I agree, A makes sense. Quick updates!
upvoted 0 times
...
Bettyann
1 month ago
I think it's A. Automation scripts are efficient.
upvoted 0 times
...
Edda
2 months ago
C) is not the right answer, just FYI!
upvoted 0 times
...
Malinda
2 months ago
Wait, a webhook? That sounds off...
upvoted 0 times
...
Lenora
2 months ago
Definitely A), I've seen it in action.
upvoted 0 times
...
Rima
2 months ago
I thought it was B) with FortiManager?
upvoted 0 times
...
Virgie
2 months ago
A) is correct, it automates updates to FortiGate.
upvoted 0 times
...
Carylon
2 months ago
I'm leaning towards option D because I remember something about webhooks in a different context, but I need to double-check that.
upvoted 0 times
...
Malcolm
3 months ago
I feel like option C could be a possibility too, but I can't recall the specifics of the FortiClient EMS connector.
upvoted 0 times
...
Cristal
3 months ago
I remember practicing a question about FortiManager and its role, so maybe option B is correct?
upvoted 0 times
...
Sanjuana
3 months ago
I think it might be option A, but I'm not entirely sure how the automation script works with FortiGate.
upvoted 0 times
...

Save Cancel