NSE7_SOC_AR-7.6 · Question #2
Which three end user logs does FortiAnalyzer use to identify possible IOC compromised hosts? (Choose three.)
The correct answer is B. DNS filter logs D. IPS logs E. Web filter logs. Overview of Indicators of Compromise (IoCs): Indicators of Compromise (IoCs) are pieces of evidence that suggest a system may have been compromised. These can include unusual network traffic patterns, the presence of known malicious files, or other suspicious activities…
Question
Which three end user logs does FortiAnalyzer use to identify possible IOC compromised hosts? (Choose three.)
Options
- AEmail filter logs
- BDNS filter logs
- CApplication filter logs
- DIPS logs
- EWeb filter logs
How the community answered
(27 responses)- A4% (1)
- B93% (25)
- C4% (1)
Explanation
Overview of Indicators of Compromise (IoCs): Indicators of Compromise (IoCs) are pieces of evidence that suggest a system may have been compromised. These can include unusual network traffic patterns, the presence of known malicious files, or other suspicious activities. FortiAnalyzer's Role: FortiAnalyzer aggregates logs from various Fortinet devices to provide comprehensive visibility and analysis of network events. It uses these logs to identify potential IoCs and compromised hosts. Relevant Log Types: DNS Filter Logs: DNS requests are a common vector for malware communication. Analyzing DNS filter logs helps in identifying suspicious domain queries, which can indicate malware attempting to communicate with command and control (C2) servers. Intrusion Prevention System (IPS) logs detect and block exploit attempts and malicious activities. These logs are critical for identifying compromised hosts based on detected intrusion attempts or behaviors matching known attack patterns. Web Filter Logs: Web filtering logs monitor and control access to web content. These logs can reveal access to malicious websites, download of malware, or other web-based threats, indicating a compromised
Topics
Community Discussion
No community discussion yet for this question.