NSE5_FAZ-7.2 · Question #54
Which two actions should an administrator take to view Compromised Hosts on FortiAnalyzer? (Choose two.)
The correct answer is A. Enable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent C. Subscribe FortiAnalyzer to FortiGuard to keep its local threat database up-to-date. Compromised Hosts or Indicators of Compromise service (IOC) is a licensed feature. To view Compromised Hosts, you must turn on the UTM web filter of FortiGate devices and subscribe your FortiAnalyzer unit to FortiGuard to keep its local threat database synchronized with the…
Question
Which two actions should an administrator take to view Compromised Hosts on FortiAnalyzer? (Choose two.)
Options
- AEnable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent
- BEnable device detection on an interface on the FortiGate devices that are connected to the
- CSubscribe FortiAnalyzer to FortiGuard to keep its local threat database up-to-date.
- DMake sure all endpoints are reachable by FortiAnalyzer.
How the community answered
(67 responses)- A82% (55)
- B12% (8)
- D6% (4)
Explanation
Compromised Hosts or Indicators of Compromise service (IOC) is a licensed feature. To view Compromised Hosts, you must turn on the UTM web filter of FortiGate devices and subscribe your FortiAnalyzer unit to FortiGuard to keep its local threat database synchronized with the FortiGuard threat database. See Subscribing FortiAnalyzer to FortiGuard. Ref : https://docs.fortinet.com/document/fortianalyzer/6.4.0/administration-guide/137635/viewing- compromised-hosts
Topics
Community Discussion
No community discussion yet for this question.