Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet FCP_FAZ_AN-7.6 Exam - Topic 3 Question 12 Discussion

Which two actions should an administrator take to vide Compromised Hosts on FortiAnalyzer? (Choose two.)
A) Enable device detection on the FotiGate device that are sending logs to FortiAnalyzer. and B) Enable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent to fortiAnalyzer.
C) Make sure all endpoints are reachable by FortiAnalyzer.
D) Subscribe FortiAnalyzer to FortiGuard to keep its local threat database up to date.

Fortinet FCP_FAZ_AN-7.6 Exam - Topic 3 Question 12 Discussion

Actual exam question for Fortinet's FCP_FAZ_AN-7.6 exam
Question #: 12
Topic #: 3
[All FCP_FAZ_AN-7.6 Questions]

Which two actions should an administrator take to vide Compromised Hosts on FortiAnalyzer? (Choose two.)

Show Suggested Answer Hide Answer
Suggested Answer: A, B

To view Compromised Hosts on FortiAnalyzer, certain configurations need to be in place on both FortiGate and FortiAnalyzer. Compromised Host data on FortiAnalyzer relies on log information from FortiGate to analyze threats and compromised activities effectively. Here's why the selected answers are correct:

Option A: Enable device detection on the FortiGate devices that are sending logs to FortiAnalyzer

Enabling device detection on FortiGate allows it to recognize and log devices within the network, sending critical information about hosts that could be compromised. This is essential because FortiAnalyzer relies on these logs to determine which hosts may be at risk based on suspicious activities observed by FortiGate. This setting enables FortiGate to provide device-level insights, which FortiAnalyzer uses to populate the Compromised Hosts view.

Option B: Enable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent to FortiAnalyzer

Web filtering is crucial in identifying potentially compromised hosts since it logs any access to malicious sites or blocked categories. FortiAnalyzer uses these web filter logs to detect suspicious or malicious web activity, which can indicate compromised hosts. By ensuring that FortiGate sends these web filtering logs to FortiAnalyzer, the administrator enables FortiAnalyzer to analyze and identify hosts engaging in risky behavior.

Let's review the other options for clarity:

Option C: Make sure all endpoints are reachable by FortiAnalyzer

This is incorrect. FortiAnalyzer does not need direct access to all endpoints. Instead, it collects data indirectly from FortiGate logs. FortiGate devices are the ones that interact with endpoints and then forward relevant logs to FortiAnalyzer for analysis.

Option D: Subscribe FortiAnalyzer to FortiGuard to keep its local threat database up to date

Although subscribing to FortiGuard helps keep threat intelligence updated, it is not a requirement specifically to view compromised hosts. FortiAnalyzer primarily uses logs from FortiGate (such as web filtering and device detection) to detect compromised hosts.


Contribute your Thoughts:

0/2000 characters
Afton
17 hours ago
I like A and B. Web filtering can catch issues early.
upvoted 0 times
...
Tamie
6 days ago
C seems less relevant. If logs are sent, they should be reachable already.
upvoted 0 times
...
Kristofer
11 days ago
True, but I still prefer A and D for immediate action.
upvoted 0 times
...
Sophia
16 days ago
I feel like B could help too. Web filtering logs are useful.
upvoted 0 times
...
Svetlana
21 days ago
D is also important. Keeping the threat database updated is key.
upvoted 0 times
...
Merissa
27 days ago
I agree, A is essential for identifying compromised hosts.
upvoted 0 times
...
Cristy
1 month ago
I think A and D are the best choices. Device detection is crucial.
upvoted 0 times
...
Darnell
1 month ago
Not sure about D), isn't that just extra cost?
upvoted 0 times
...
Pete
1 month ago
Enabling device detection is a must!
upvoted 0 times
...
Lizbeth
2 months ago
Wait, can FortiAnalyzer really detect all compromised hosts?
upvoted 0 times
...
Mireya
2 months ago
I think B) is also important for monitoring.
upvoted 0 times
...
Lavonda
2 months ago
A) and D) are definitely the right moves.
upvoted 0 times
...
Antonio
2 months ago
I definitely recall something about subscribing to FortiGuard for updates, but I can't remember if that's one of the main actions needed.
upvoted 0 times
...
Virgie
2 months ago
I’m a bit confused about whether making sure endpoints are reachable is really necessary for compromised hosts.
upvoted 0 times
...
Marta
2 months ago
I remember a practice question about logging, and I feel like web filtering might be relevant here too.
upvoted 0 times
...
Rosenda
3 months ago
I think enabling device detection on FortiGate is important, but I'm not sure if that's the only action needed.
upvoted 0 times
...

Save Cancel