(How does FortiAnalyzer block indicators? (Choose one answer)
Study Guide p.98: blocking suspicious indicators requires an authorized FortiManager connector and updates a FortiManager External Resource list.
Technical Deep Dive: The correct answer is B. FortiAnalyzer does not directly push the block to FortiGate from the indicator page. It uses a FortiManager connector; the Block_indicator playbook periodically sends blocked indicators to FortiManager, where they are added to an External Resource list. FortiManager policies or threat feeds can then be used to push enforcement to FortiGate. Option A skips FortiManager, which is the documented control point. Options C and D use the wrong integration mechanism for indicator blocking.
Currently there are no comments in this discussion, be the first to comment!