(How does FortiAnalyzer block indicators? (Choose one answer))
Comprehensive and Detailed Explanation From Exact Extract of knowledge of FortiAnalyzer 7.6 Study guide documents:
The FortiAnalyzer study guide states that blocking suspicious indicators is performed by integrating FortiAnalyzer with FortiManager (not by directly pushing a block list to FortiGate). Specifically: ''To use this feature, you must set up an authorized FortiManager connector for the FortiAnalyzer on the Fabric Connector page of FortiAnalyzer.''
It then explains the backend mechanism: ''In the back end, a playbook called Block_indicator runs every 5 minutes to send the information to FortiManager.'' After a successful run, ''the blocked indicator is pushed to the FortiManager External Resource list.'' From there, FortiManager can create threat feeds/security profiles/policy blocks and push policies to FortiGate as needed---however, the study guide clarifies: ''The Blocked status on FortiAnalyzer confirms that the list is updated on FortiManager, but it is not synced to FortiGate.''
Therefore, FortiAnalyzer blocks indicators by using a FortiManager connector and sending the block information to FortiManager (Option B).
Catarina
15 days agoRonnie
20 days agoHermila
26 days agoCarlota
1 month agoCarman
1 month agoArtie
1 month agoHermila
2 months agoChantell
2 months agoEnola
2 months agoMerissa
2 months agoLeontine
2 months agoJenise
2 months agoLeatha
3 months agoSalina
3 months agoKimbery
4 months agoShantell
4 months agoLorrie
4 months agoElmira
4 months agoGeorgiann
4 months ago