Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet NSE6_OTS_AR-7.6 Exam - Topic 3 Question 3 Discussion

Actual exam question for Fortinet's NSE6_OTS_AR-7.6 exam
Question #: 3
Topic #: 3
[All NSE6_OTS_AR-7.6 Questions]

Refer to the exhibit.

Based on the information provided on the partial Event Monitor page shown in the exhibit, how was the attack detected? (Choose one answer)

Show Suggested Answer Hide Answer
Suggested Answer: D

The correct answer is D. Automatically by an event handler. The study guide explicitly states that ''Event handlers generate events on FortiAnalyzer'' and ''FortiAnalyzer uses event handlers to filter all incoming logs. If the logs received match the conditions set in the event handlers, FortiAnalyzer generates an event.'' It also says ''You can view all generated events on the Event Monitor page.'' This directly matches the exhibit, which is showing entries on the Event Monitor page. Therefore, the attack shown there was detected automatically through an event handler.

The guide also explains the detection flow: ''FortiAnalyzer receives logs,'' ''FortiAnalyzer parses logs,'' and ''FortiAnalyzer generates an event if a rule is matched in an event handler.'' In addition, the Event Monitor view includes the Handler column, which identifies the event handler that generated the event. That is why the attack is not considered manually detected, and it is not primarily detected by a playbook or stitch. Playbooks and stitches are used for subsequent automation actions, but the event appearing in Event Monitor is created by the event handler mechanism.


Contribute your Thoughts:

0/2000 characters
Malinda
5 days ago
I think the attack detection might be related to an event handler, but I'm not entirely sure.
upvoted 0 times
...

Save Cancel