nerdexam
Fortinet

NSE7_OTS-7.2 · Question #45

An OT administrator deployed many devices to secure the OT network. However, the SOC team is reporting that there are too many alerts, and that many of the alerts are false positive. The OT…

The correct answer is C. FortiSOAR and FortiSIEM. The OT administrator should deploy FortiSOAR and FortiSIEM (Option C) to automate manual tasks, reduce false positives, and improve SOC efficiency, because FortiSIEM consolidates and analyzes logs for comprehensive security visibility, while FortiSOAR provides the automation…

FortiAnalyzer for OT

Question

An OT administrator deployed many devices to secure the OT network. However, the SOC team is reporting that there are too many alerts, and that many of the alerts are false positive. The OT administrator would like to find a solution that eliminates repetitive tasks, improves efficiency, saves time, and saves resources. Which products should the administrator deploy to address these issues and automate most of the manual tasks done by the SOC team?

Options

  • AFortiSIEM and FortiManager
  • BFortiSandbox and FortiSIEM
  • CFortiSOAR and FortiSIEM
  • DA syslog server and FortiSIEM

How the community answered

(30 responses)
  • A
    7% (2)
  • B
    13% (4)
  • C
    77% (23)
  • D
    3% (1)

Explanation

The OT administrator should deploy FortiSOAR and FortiSIEM (Option C) to automate manual tasks, reduce false positives, and improve SOC efficiency, because FortiSIEM consolidates and analyzes logs for comprehensive security visibility, while FortiSOAR provides the automation and orchestration to respond to alerts with playbooks, effectively streamlining workflows and freeing up SOC resources.

Topics

#FortiSOAR#FortiSIEM#SOC automation#false positive reduction

Community Discussion

No community discussion yet for this question.

Full NSE7_OTS-7.2 Practice