View all questions & answers for the NSE 5 - FortiAnalyzer 7.6 Analyst Exam Materials exam
NSE 5 - FortiAnalyzer 7.6 Analyst Exam Materials-Question 70 Discussion
Comments
Selected Answers: C
Selected Answers: A
Infected: Indicates a real breach. FortiAnalyzer found matches of the blacklisted IPs or domain generation
algorithms (DGAs) in the web logs.
Selected Answers: D
Selected Answers: A
A new Infected entry is added for the corresponding endpoint under Compromised Hosts.
When the IOC engine on FortiAnalyzer detects web logs that match blocklisted IP addresses, it adds a new Infected entry for the corresponding endpoint under the Compromised Hosts section. This is the specific behavior triggered by a blocklisted IP match in web logs.
Ruling out the others:
B ❌ — FortiAnalyzer does not automatically run a default playbook in the background for IOC matches; playbooks need to be explicitly configured and triggered
C ❌ — Logs matching blocklisted IPs are classified as Infected, not "Suspicious" — Suspicious is a different classification level
D ❌ — The endpoint being marked as "Compromised" and quarantined is a possible action but requires additional configuration (e.g., a playbook or automation stitch); it is not the automatic default behavior of the IOC engine itself
What happens when the indicator of compromise (IOC) engine on FortiAnalyzer finds web logs that match blocklisted IP addresses? (Choose one answer)
Brave-Dump Clients Votes