nse5_faz-72 Exam QuestionsBrowse all questions from this exam

nse5_faz-72 Exam - Question 20


Which two actions should an administrator take to view Compromised Hosts on FortiAnalyzer? (Choose two.)

Show Answer
Correct Answer: ABD

To view Compromised Hosts on FortiAnalyzer, an administrator should enable web filtering in firewall policies on FortiGate devices and ensure these logs are sent to FortiAnalyzer. This allows FortiAnalyzer to capture and analyze web traffic for potential threats. Additionally, enabling device detection on the FortiGate devices that are sending logs to FortiAnalyzer is crucial. Device detection helps in identifying and keeping track of endpoints, which is essential for monitoring compromised hosts effectively.

Discussion

4 comments
Sign in to comment
DaniSerbOptions: AB
Nov 15, 2023

A: FortiAnalyzer downloads threat intelligence FortiGuard package (TDS) every day B: FortiAnalyzer runs real-time threat detection when it receives logs from the FortiGate web filter Reference: FortiAnalyzer Analyst Study Guide for FortiAnalyzer 7.2

r_jordanOptions: AB
Dec 15, 2023

A and B

rian00z_Options: AB
Apr 10, 2024

A and B are correct. FortiAnalyzer Analyst Study Guide for FortiAnalyzer 7.2, p. 73

rian00z_Options: AB
Apr 10, 2024

A and B are correct. FortiAnalyzer Analyst Study Guide for FortiAnalyzer 7.2, p. 73