nerdexam
Fortinet

FCP_FAZ_AN-7.4 · Question #9

Refer to the exhibit. Laptop1 is used by several administrators to manage FortiAnalyzer. You want to configure a generic text filter that matches all login attempts to the web interface generated by…

The correct answer is A. Operation-login & performed_on==''GUI(10.1.1.100)' and user!=admin. On there the task was to create a filter for failed logins from any other location but the local "Add the text performed_on!~10.0.1.10. This includes any attempts coming from devices with an IP address that is not the one configured on the Local-Client computer."

Troubleshooting and Maintenance

Question

Refer to the exhibit. Laptop1 is used by several administrators to manage FortiAnalyzer. You want to configure a generic text filter that matches all login attempts to the web interface generated by any user other than "admin", and coming from Laptop1. Which filter will achieve the desired result?

Exhibit

FCP_FAZ_AN-7.4 question #9 exhibit

Options

  • AOperation-login & performed_on==''GUI(10.1.1.100)' and user!=admin
  • BOperation-login & performed_on==''GU (10.1.1.120)' and user!=admin
  • COperation-login & srcip== 10.1.1.100 and dstip==10.1.1.1.210 and user==admin
  • DOperation-login & dstip==10.1.1.210 and user!-admin

How the community answered

(28 responses)
  • A
    75% (21)
  • B
    7% (2)
  • C
    14% (4)
  • D
    4% (1)

Explanation

On there the task was to create a filter for failed logins from any other location but the local "Add the text performed_on!~10.0.1.10. This includes any attempts coming from devices with an IP address that is not the one configured on the Local-Client computer."

Topics

#log filter syntax#text filter#login audit#log search query

Community Discussion

No community discussion yet for this question.

Full FCP_FAZ_AN-7.4 Practice