nerdexam
Fortinet

NSE8_812 · Question #197

A customer is trying to setup a Playbook automation using a FortiAnalyzer, FortiWeb and FortiGate. The intention is to have the FortiGate quarantine any source of SQL Injection detected by the…

The correct answer is A. The Group By option in the handler should be different to src, so src can be used on the Playbook configuration. E. To fix the issue the parameter for script on the Playbook configuration should be epip. See the full explanation below for the reasoning.

Question

A customer is trying to setup a Playbook automation using a FortiAnalyzer, FortiWeb and FortiGate. The intention is to have the FortiGate quarantine any source of SQL Injection detected by the FortiWeb. They got the automation setup to trigger on the FortiGate when simulating an attack to their website, but the quarantine object was created at the IP: 0.0.0.0. Referring to the configuration and logs in the exhibits, which two statements are true? (Choose two.)

Options

  • AThe Group By option in the handler should be different to src, so src can be used on the Playbook configuration.
  • BFortiSOC Playbooks combining FortiWeb and FortiGate are not supported.
  • CTo diagnose this issue, you need to use the command diagnose test application oftpd 22.
  • DThe FortiAnalyzer ADOM Type must be Fabric.
  • ETo fix the issue the parameter for script on the Playbook configuration should be epip.

How the community answered

(30 responses)
  • A
    83% (25)
  • B
    10% (3)
  • C
    3% (1)
  • D
    3% (1)

Community Discussion

No community discussion yet for this question.

Full NSE8_812 Practice