nerdexam
Fortinet

FCP_FAZ_AN-7.4 · Question #46

Which two actions should an administrator take to view Compromised Hosts on FortiAnalyzer? (Choose two.)

The correct answer is B. Enable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent to D. Subscribe FortiAnalyzer to FortiGuard to keep its local threat database up to date. In order to configure IOC, you require the following: - A one-year subscription to IOC. Note that FortiAnalyzer does include an evaluation license, but it is restrictive and only meant to give you an idea of how the feature works. - A web filter services subscription on…

SOC Operations

Question

Which two actions should an administrator take to view Compromised Hosts on FortiAnalyzer? (Choose two.)

Options

  • AEnable device detection on the FotiGate device that are sending logs to FortiAnalyzer.
  • BEnable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent to
  • CMake sure all endpoints are reachable by FortiAnalyzer.
  • DSubscribe FortiAnalyzer to FortiGuard to keep its local threat database up to date.

How the community answered

(35 responses)
  • A
    9% (3)
  • B
    71% (25)
  • C
    20% (7)

Explanation

In order to configure IOC, you require the following: - A one-year subscription to IOC. Note that FortiAnalyzer does include an evaluation license, but it is restrictive and only meant to give you an idea of how the feature works. - A web filter services subscription on FortiGate device(s) - Web filter policies on FortiGate device(s) that send traffic to FortiAnalyzer

Topics

#compromised hosts#FortiGuard subscription#web filtering#threat detection

Community Discussion

No community discussion yet for this question.

Full FCP_FAZ_AN-7.4 Practice