FCP_FAZ_AN-7.4 · Question #36
What happens when the indicator of compromise (IOC) engine on FortiAnalyzer finds web logs that match blacklisted IP addresses?
The correct answer is B. A new infected entry is added for the corresponding endpoint under Compromised Hosts. The breach detection engine on FortiAnalyzer uses Fortiguard Threat DEtection Service (TDS) intelligence to analyze web filter logs for breach detection...When the threat match is found, a threat score is given to the end user based on the overall ranking score from TDS.
Question
What happens when the indicator of compromise (IOC) engine on FortiAnalyzer finds web logs that match blacklisted IP addresses?
Options
- AFortiAnalyzer flags the associated host for further analysis.
- BA new infected entry is added for the corresponding endpoint under Compromised Hosts.
- CThe detection engine classifies those logs as Suspicious.
- DThe endpoint is marked as Compromised and, optionally, can be put in quarantine.
How the community answered
(26 responses)- A8% (2)
- B77% (20)
- C4% (1)
- D12% (3)
Explanation
The breach detection engine on FortiAnalyzer uses Fortiguard Threat DEtection Service (TDS) intelligence to analyze web filter logs for breach detection...When the threat match is found, a threat score is given to the end user based on the overall ranking score from TDS.
Topics
Community Discussion
No community discussion yet for this question.