nerdexam
Fortinet

FCP_FAZ_AD-7.4 · Question #54

Which two actions should an administrator take to view Compromised Hosts on FortiAnalyzer? (Choose two.)

The correct answer is A. Enable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent C. Subscribe FortiAnalyzer to FortiGuard to keep its local threat database up-to-date. Compromised Hosts or Indicators of Compromise service (IOC) is a licensed feature. To view Compromised Hosts, you must turn on the UTM web filter of FortiGate devices and subscribe your FortiAnalyzer unit to FortiGuard to keep its local threat database synchronized with the…

SOC Features (Playbooks, Incident Response)

Question

Which two actions should an administrator take to view Compromised Hosts on FortiAnalyzer? (Choose two.)

Options

  • AEnable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent
  • BEnable device detection on an interface on the FortiGate devices that are connected to the
  • CSubscribe FortiAnalyzer to FortiGuard to keep its local threat database up-to-date.
  • DMake sure all endpoints are reachable by FortiAnalyzer.

How the community answered

(21 responses)
  • A
    76% (16)
  • B
    14% (3)
  • D
    10% (2)

Explanation

Compromised Hosts or Indicators of Compromise service (IOC) is a licensed feature. To view Compromised Hosts, you must turn on the UTM web filter of FortiGate devices and subscribe your FortiAnalyzer unit to FortiGuard to keep its local threat database synchronized with the FortiGuard threat database. See Subscribing FortiAnalyzer to FortiGuard. Ref : https://docs.fortinet.com/document/fortianalyzer/6.4.0/administration-guide/137635/viewing- compromised-hosts

Topics

#compromised hosts#FortiGuard subscription#web filtering logs#threat database

Community Discussion

No community discussion yet for this question.

Full FCP_FAZ_AD-7.4 Practice