nerdexam
Fortinet

FCP_FAZ_AD-7.4 · Question #143

What happens when the IOC breach detection engine on FortiAnalyzer finds web logs that match a blocklisted IP address?

The correct answer is C. A new Infected entry is added for the corresponding endpoint. The breach detection engine on FortiAnalyzer uses Fortiguard Threat DEtection Service (TDS) intelligence to analyze web filter logs for breach detection...When the threat match is found, a threat score is given to the end user based on the overall ranking score from TDS.

SOC Features (Playbooks, Incident Response)

Question

What happens when the IOC breach detection engine on FortiAnalyzer finds web logs that match a blocklisted IP address?

Options

  • AThe endpoint is marked as Compromised and. optionally, can be put in quarantine.
  • BFortiAnalyzer flags the associated host for further analysis.
  • CA new Infected entry is added for the corresponding endpoint.
  • DThe detection engine classifies those logs as Suspicious

How the community answered

(42 responses)
  • A
    7% (3)
  • B
    12% (5)
  • C
    76% (32)
  • D
    5% (2)

Explanation

The breach detection engine on FortiAnalyzer uses Fortiguard Threat DEtection Service (TDS) intelligence to analyze web filter logs for breach detection...When the threat match is found, a threat score is given to the end user based on the overall ranking score from TDS.

Topics

#IOC detection#blocklisted IP#compromised endpoints#breach detection

Community Discussion

No community discussion yet for this question.

Full FCP_FAZ_AD-7.4 Practice