nerdexam
Fortinet

FCP_FAZ_AD-7.4 · Question #115

Refer to the exhibit. Laptopt is used by several administrators to manage FortiAnalyzer. You want to configure a generic text filter that matches all login attempts to the web interface generated by…

The correct answer is A. operation-login & performed_on=="GUI(10.1.1.100)" & user!=admin. On there the task was to create a filter for failed logins from any other location but the local "Add the text performed_on!~10.0.1.10. This includes any attempts coming from devices with an IP address that is not the one configured on the Local-Client computer."

Event Management

Question

Refer to the exhibit. Laptopt is used by several administrators to manage FortiAnalyzer. You want to configure a generic text filter that matches all login attempts to the web interface generated by any user other than "admin" and coming from Laptop1:

Which filter will achieve the desired result?

Exhibit

FCP_FAZ_AD-7.4 question #115 exhibit

Options

  • Aoperation-login & performed_on=="GUI(10.1.1.100)" & user!=admin
  • Boperation-login & srcip==10.1.1.100 & dstip==10.1.1.210 & user==admin
  • Coperation-login & dstip==10.1.1.210 & userl-admin
  • Doperation-login & performed_on=="GUI(10.1.1.210)' & user!=admin

How the community answered

(38 responses)
  • A
    76% (29)
  • B
    3% (1)
  • C
    8% (3)
  • D
    13% (5)

Explanation

On there the task was to create a filter for failed logins from any other location but the local "Add the text performed_on!~10.0.1.10. This includes any attempts coming from devices with an IP address that is not the one configured on the Local-Client computer."

Topics

#text filter#log filter syntax#web interface login#event filtering

Community Discussion

No community discussion yet for this question.

Full FCP_FAZ_AD-7.4 Practice