nerdexam
Fortinet

FCSS_ADA_AR-6.7 · Question #57

Refer to the exhibit. An administrator wants to remediate the incident from FortiSIEM shown in the exhibit. What option is available to the administrator?

The correct answer is D. Run the block IP FortiOS 5.4. The incident shown in the exhibit indicates that a firewall detected malware but could not remediate it. The firewall identified the EICAR_TEST_FILE virus and logged the source IP (10.0.3.10) as the origin of the threat. To remediate this, the administrator should take action…

SOAR Integration and Automation

Question

Refer to the exhibit. An administrator wants to remediate the incident from FortiSIEM shown in the exhibit. What option is available to the administrator?

Exhibit

FCSS_ADA_AR-6.7 question #57 exhibit

Options

  • AQuarantine IP FortiClient
  • BRun the block domain Windows DNS
  • CRun the block MAC FortiOS
  • DRun the block IP FortiOS 5.4

How the community answered

(19 responses)
  • A
    5% (1)
  • B
    16% (3)
  • C
    5% (1)
  • D
    74% (14)

Explanation

The incident shown in the exhibit indicates that a firewall detected malware but could not remediate it. The firewall identified the EICAR_TEST_FILE virus and logged the source IP (10.0.3.10) as the origin of the threat. To remediate this, the administrator should take action at the network level, specifically using FortiOS to block the source IP address. The option "Run the block IP FortiOS 5.4" provides the ability to block traffic from the infected IP at the firewall level, effectively preventing further threats from that source.

Topics

#incident remediation#FortiOS#IP blocking#remediation actions

Community Discussion

No community discussion yet for this question.

Full FCSS_ADA_AR-6.7 Practice