NSE7_SOC_AR-7.6 · Question #32
A customer wants FortiAnalyzer to run an automation stitch that executes a CLI command on FortiGate to block a predefined list of URLs, if a botnet command-and-control (C&C) server IP is detected…
The correct answer is C. Event handler. You configure an event handler on FortiAnalyzer to detect the botnet C&C IP log and enable the "Automation Stitch" option. When that event fires, FortiAnalyzer notifies the FortiGate, which then runs the predefined CLI stitch to block the URL list.
Question
A customer wants FortiAnalyzer to run an automation stitch that executes a CLI command on FortiGate to block a predefined list of URLs, if a botnet command-and-control (C&C) server IP is detected. Which FortiAnalyzer feature must you use to start this automation process?
Options
- APlaybook
- BData selector
- CEvent handler
- DConnector
How the community answered
(47 responses)- A2% (1)
- B11% (5)
- C83% (39)
- D4% (2)
Explanation
You configure an event handler on FortiAnalyzer to detect the botnet C&C IP log and enable the "Automation Stitch" option. When that event fires, FortiAnalyzer notifies the FortiGate, which then runs the predefined CLI stitch to block the URL list.
Topics
Community Discussion
No community discussion yet for this question.