nerdexam
Fortinet

NSE5_FAZ-7.2 · Question #54

Which two actions should an administrator take to view Compromised Hosts on FortiAnalyzer? (Choose two.)

The correct answer is A. Enable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent C. Subscribe FortiAnalyzer to FortiGuard to keep its local threat database up-to-date. Compromised Hosts or Indicators of Compromise service (IOC) is a licensed feature. To view Compromised Hosts, you must turn on the UTM web filter of FortiGate devices and subscribe your FortiAnalyzer unit to FortiGuard to keep its local threat database synchronized with the…

FortiSoC

Question

Which two actions should an administrator take to view Compromised Hosts on FortiAnalyzer? (Choose two.)

Options

  • AEnable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent
  • BEnable device detection on an interface on the FortiGate devices that are connected to the
  • CSubscribe FortiAnalyzer to FortiGuard to keep its local threat database up-to-date.
  • DMake sure all endpoints are reachable by FortiAnalyzer.

How the community answered

(67 responses)
  • A
    82% (55)
  • B
    12% (8)
  • D
    6% (4)

Explanation

Compromised Hosts or Indicators of Compromise service (IOC) is a licensed feature. To view Compromised Hosts, you must turn on the UTM web filter of FortiGate devices and subscribe your FortiAnalyzer unit to FortiGuard to keep its local threat database synchronized with the FortiGuard threat database. See Subscribing FortiAnalyzer to FortiGuard. Ref : https://docs.fortinet.com/document/fortianalyzer/6.4.0/administration-guide/137635/viewing- compromised-hosts

Topics

#compromised hosts#web filtering#FortiGuard#threat database

Community Discussion

No community discussion yet for this question.

Full NSE5_FAZ-7.2 Practice