nerdexam
Fortinet

NSE7_SOC_AR-7.6 · Question #7

Refer to the exhibits. You configured a spearphishing event handler and the associated rule. However. FortiAnalyzer did not generate an event. When you check the FortiAnalyzer log viewer, you…

The correct answer is B. Configure a FortiSandbox data selector and add it tothe event handler. FortiAnalyzer event handlers require a Data Selector to define what type of logs (source, log type, etc.) the handler should process. In your configuration, the Data Selector field is empty, meaning the handler doesn't know which Since you're working with FortiSandbox logs, you…

FortiAnalyzer for SOC

Question

Refer to the exhibits. You configured a spearphishing event handler and the associated rule. However. FortiAnalyzer did not generate an event. When you check the FortiAnalyzer log viewer, you confirm that FortiSandbox forwarded the appropriate logs, as shown in the raw log exhibit. What configuration must you change on FortiAnalyzer in order for FortiAnalyzer to generate an event?

Exhibit

NSE7_SOC_AR-7.6 question #7 exhibit

Options

  • AIn the Log Type field, change the selection to AntiVirus Log(malware).
  • BConfigure a FortiSandbox data selector and add it tothe event handler.
  • CIn the Log Filter by Text field, type the value: .5 ub t ype ma Iwa re..
  • DChange trigger condition by selecting. Within a group, the log field Malware Kame (mname>

How the community answered

(33 responses)
  • A
    12% (4)
  • B
    64% (21)
  • C
    3% (1)
  • D
    21% (7)

Explanation

FortiAnalyzer event handlers require a Data Selector to define what type of logs (source, log type, etc.) the handler should process. In your configuration, the Data Selector field is empty, meaning the handler doesn't know which Since you're working with FortiSandbox logs, you need to: - Create a custom Data Selector that filters logs from FortiSandbox. - Attach that Data Selector to the event handler. Without this, FortiAnalyzer will not apply the rule to any logs, and no events will be generated, even if the logs match the conditions.

Topics

#event handler#FortiSandbox integration#data selector#spearphishing detection

Community Discussion

No community discussion yet for this question.

Full NSE7_SOC_AR-7.6 Practice