nerdexam
Fortinet

FCP_FAZ_AN-7.4 · Question #40

Which log will generate an event with the status Unhandled?

The correct answer is B. An IPS log with action=pass. In FortiOS 7.4.1 and FortiAnalyzer 7.4.1, the "Unhandled" status in logs typically signifies that the FortiGate encountered a security event but did not take any specific action to block or alter it. This usually occurs in the context of Intrusion Prevention System (IPS) logs…

Alerting and Incident Response

Question

Which log will generate an event with the status Unhandled?

Options

  • AAn AV log with action=quarantine.
  • BAn IPS log with action=pass.
  • CA WebFilter log will action=dropped.
  • DAn AppControl log with action=blocked.

How the community answered

(48 responses)
  • A
    2% (1)
  • B
    85% (41)
  • C
    4% (2)
  • D
    8% (4)

Explanation

In FortiOS 7.4.1 and FortiAnalyzer 7.4.1, the "Unhandled" status in logs typically signifies that the FortiGate encountered a security event but did not take any specific action to block or alter it. This usually occurs in the context of Intrusion Prevention System (IPS) logs. IPS logs with action=pass: When the IPS engine inspects traffic and determines that it does not match any known attack signatures or violate any configured policies, it assigns the action "pass". Since no action is taken to block or modify this traffic, the status is logged as "Unhandled."

Topics

#event handler#Unhandled status#IPS log#action=pass

Community Discussion

No community discussion yet for this question.

Full FCP_FAZ_AN-7.4 Practice