FCP_FAZ_AN-7.4 · Question #40
Which log will generate an event with the status Unhandled?
The correct answer is B. An IPS log with action=pass. In FortiOS 7.4.1 and FortiAnalyzer 7.4.1, the "Unhandled" status in logs typically signifies that the FortiGate encountered a security event but did not take any specific action to block or alter it. This usually occurs in the context of Intrusion Prevention System (IPS) logs…
Question
Which log will generate an event with the status Unhandled?
Options
- AAn AV log with action=quarantine.
- BAn IPS log with action=pass.
- CA WebFilter log will action=dropped.
- DAn AppControl log with action=blocked.
How the community answered
(48 responses)- A2% (1)
- B85% (41)
- C4% (2)
- D8% (4)
Explanation
In FortiOS 7.4.1 and FortiAnalyzer 7.4.1, the "Unhandled" status in logs typically signifies that the FortiGate encountered a security event but did not take any specific action to block or alter it. This usually occurs in the context of Intrusion Prevention System (IPS) logs. IPS logs with action=pass: When the IPS engine inspects traffic and determines that it does not match any known attack signatures or violate any configured policies, it assigns the action "pass". Since no action is taken to block or modify this traffic, the status is logged as "Unhandled."
Topics
Community Discussion
No community discussion yet for this question.