Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet FCP_FAZ_AN-7.6 Exam - Topic 3 Question 17 Discussion

(How does FortiAnalyzer block indicators? (Choose one answer)
B) It uses a FortiManager connector to send the block list.
A) It uses an automation script to update FortiGate with the block list.
C) It uses a FortiClient EMS connector to send the block list.
D) It uses a webhook to allow FortiGate to send the block list.

Fortinet FCP_FAZ_AN-7.6 Exam - Topic 3 Question 17 Discussion

Actual exam question for Fortinet's FCP_FAZ_AN-7.6 exam
Question #: 17
Topic #: 3
[All FCP_FAZ_AN-7.6 Questions]

(How does FortiAnalyzer block indicators? (Choose one answer)

Show Suggested Answer Hide Answer
Suggested Answer: B

Study Guide p.98: blocking suspicious indicators requires an authorized FortiManager connector and updates a FortiManager External Resource list.

Technical Deep Dive: The correct answer is B. FortiAnalyzer does not directly push the block to FortiGate from the indicator page. It uses a FortiManager connector; the Block_indicator playbook periodically sends blocked indicators to FortiManager, where they are added to an External Resource list. FortiManager policies or threat feeds can then be used to push enforcement to FortiGate. Option A skips FortiManager, which is the documented control point. Options C and D use the wrong integration mechanism for indicator blocking.


Contribute your Thoughts:

0/2000 characters

Currently there are no comments in this discussion, be the first to comment!


Save Cancel