NSE7_OTS-7.2 · Question #45
An OT administrator deployed many devices to secure the OT network. However, the SOC team is reporting that there are too many alerts, and that many of the alerts are false positive. The OT…
The correct answer is C. FortiSOAR and FortiSIEM. The OT administrator should deploy FortiSOAR and FortiSIEM (Option C) to automate manual tasks, reduce false positives, and improve SOC efficiency, because FortiSIEM consolidates and analyzes logs for comprehensive security visibility, while FortiSOAR provides the automation…
Question
An OT administrator deployed many devices to secure the OT network. However, the SOC team is reporting that there are too many alerts, and that many of the alerts are false positive. The OT administrator would like to find a solution that eliminates repetitive tasks, improves efficiency, saves time, and saves resources. Which products should the administrator deploy to address these issues and automate most of the manual tasks done by the SOC team?
Options
- AFortiSIEM and FortiManager
- BFortiSandbox and FortiSIEM
- CFortiSOAR and FortiSIEM
- DA syslog server and FortiSIEM
How the community answered
(30 responses)- A7% (2)
- B13% (4)
- C77% (23)
- D3% (1)
Explanation
The OT administrator should deploy FortiSOAR and FortiSIEM (Option C) to automate manual tasks, reduce false positives, and improve SOC efficiency, because FortiSIEM consolidates and analyzes logs for comprehensive security visibility, while FortiSOAR provides the automation and orchestration to respond to alerts with playbooks, effectively streamlining workflows and freeing up SOC resources.
Topics
Community Discussion
No community discussion yet for this question.