nerdexam
Fortinet

FCSS_LED_AR-7.6 · Question #54

Refer to the exhibits. Examine the FortiGate configuration, FortiAnalyzer logs, and FortiGate widget shown in the exhibits. Security Fabhc quarantine automation has been configured to isolate…

The correct answer is C. The malicious website is not recognized as an indicator of compromise (IOC) by FortiAnalyzer. D. The threat detection services license is missing or invalid under FortiAnalyzer. In this scenario: FortiGate + FortiAnalyzer are part of theSecurity Fabric AnAutomation Stitchis configured: Trigger:Compromised Host - High(IOC from FortiAnalyzer) Action:Quarantine on FortiSwitch + FortiAP A test device10.0.2.1visits a malicious website. FortiAnalyzer logs…

Troubleshooting and Best Practices

Question

Refer to the exhibits. Examine the FortiGate configuration, FortiAnalyzer logs, and FortiGate widget shown in the exhibits. Security Fabhc quarantine automation has been configured to isolate compromised devices automatically. FortiAnalyzer has been added to the Security Fabric, and an automation stitch has been configured to quarantine compromised devices. To test the setup, a device with the IP address 10.0.2.1 that is connected through a managed FortiSwitch attempts to access a malicious website. The logs on FortiAnalyzer confirm that the event was recorded, but the device does not appear in the FortiGate quarantine widget. Which two reasons could explain why FortiGate is not quarantining the device? (Choose two.)

Exhibit

FCSS_LED_AR-7.6 question #54 exhibit

Options

  • AThe IOC action should include only the FortiSwitch in the quarantine.
  • BThe SSL inspection should be set to deep-Inspection
  • CThe malicious website is not recognized as an indicator of compromise (IOC) by FortiAnalyzer.
  • DThe threat detection services license is missing or invalid under FortiAnalyzer.

How the community answered

(46 responses)
  • A
    11% (5)
  • B
    22% (10)
  • C
    67% (31)

Explanation

In this scenario: FortiGate + FortiAnalyzer are part of theSecurity Fabric AnAutomation Stitchis configured: Trigger:Compromised Host - High(IOC from FortiAnalyzer) Action:Quarantine on FortiSwitch + FortiAP A test device10.0.2.1visits a malicious website. FortiAnalyzer logs show the event, butFortiGate does NOT quarantine the device. This means theautomation did not receive an IOC trigger, OR theFabric did not classify it as a

Topics

#Security Fabric quarantine#IOC#FortiAnalyzer#automation stitch

Community Discussion

No community discussion yet for this question.

Full FCSS_LED_AR-7.6 Practice