Exit NSE5_FAZ-7.2 Fortinet NSE 5 - FortiAnalyzer 7.2
Question 5 of 5
0% complete
Q5 Single choice

What happens when the IOC breach detection engine on FortiAnalyzer finds web logs that match a blocklisted IP address?

  • A

    The endpoint is marked as Compromised and. optionally, can be put in quarantine.

  • B

    FortiAnalyzer flags the associated host for further analysis.

  • C

    A new Infected entry is added for the corresponding endpoint.

  • D

    The detection engine classifies those logs as Suspicious