Refer to the exhibit.

Based on the exhibit, which two observations are true? (Choose two answers)
The correct answers are C and D.
The exhibit shows the incident classification as Malicious. In the Activity Audit, the entry from FortinetCloudServices states: ''Classification change: Malicious'' and also says the file is classified as malicious. This directly proves that FCS classified the event as malicious. The FortiEDR guide explains that the audit history shows the chronology for classifying the security event and displays details when FortiEDR Cloud Service (FCS) reclassifies a security event after its initial classification by the Core.
The exhibit also states that the file was ''Detected as Unknown malware.'' This supports option D in the exam wording: FortiEDR/FCS has classified the file as malicious, but it is being identified as unknown malware, meaning it was not recognized as a known malware family/signature at the time of classification. The guide explains that FCS enhances classification using data enrichment, automated and manual analysis, file analysis, sandboxing, machine learning flow analysis, commonality analysis, crowdsourced data deduction, and other methods, so ''unknown malware'' can still be classified malicious by FCS.
Option A is wrong because the exhibit shows Malicious, not Suspicious. Option B is wrong because the incident status is Unhandled, not resolved or handled.
=========
Currently there are no comments in this discussion, be the first to comment!