nerdexam
Fortinet

NSE7_SOC_AR-7.6 · Question #32

A customer wants FortiAnalyzer to run an automation stitch that executes a CLI command on FortiGate to block a predefined list of URLs, if a botnet command-and-control (C&C) server IP is detected…

The correct answer is C. Event handler. You configure an event handler on FortiAnalyzer to detect the botnet C&C IP log and enable the "Automation Stitch" option. When that event fires, FortiAnalyzer notifies the FortiGate, which then runs the predefined CLI stitch to block the URL list.

FortiAnalyzer for SOC

Question

A customer wants FortiAnalyzer to run an automation stitch that executes a CLI command on FortiGate to block a predefined list of URLs, if a botnet command-and-control (C&C) server IP is detected. Which FortiAnalyzer feature must you use to start this automation process?

Options

  • APlaybook
  • BData selector
  • CEvent handler
  • DConnector

How the community answered

(47 responses)
  • A
    2% (1)
  • B
    11% (5)
  • C
    83% (39)
  • D
    4% (2)

Explanation

You configure an event handler on FortiAnalyzer to detect the botnet C&C IP log and enable the "Automation Stitch" option. When that event fires, FortiAnalyzer notifies the FortiGate, which then runs the predefined CLI stitch to block the URL list.

Topics

#automation stitch#event handler#botnet C&C detection#FortiGate CLI

Community Discussion

No community discussion yet for this question.

Full NSE7_SOC_AR-7.6 Practice