nse5_faz-72 Exam QuestionsBrowse all questions from this exam

nse5_faz-72 Exam - Question 25


What happens when the IOC breach detection engine on FortiAnalyzer finds web logs that match a blocklisted IP address?

Show Answer
Correct Answer: AC

When the IOC breach detection engine on FortiAnalyzer finds web logs that match a blocklisted IP address, a new Infected entry is added for the corresponding endpoint.

Discussion

6 comments
Sign in to comment
r_jordanOption: C
Dec 15, 2023

C is correct

Alexh07Option: C
Apr 20, 2024

Answer Correct is C In FortiAnalyzer Analyst 7.2 Study Guide, p. 73 "The breach detection engine on FortiAnalyzer uses Fortiguard Threat DEtection Service (TDS) intelligence to analyze web filter logs for breach detection...When the threat match is found, a threat score is given to the end user based on the overall ranking score from TDS"

paytenj10Option: C
Dec 12, 2023

If a match is found in the blacklist, then FortiAnalyzer displays the endpoint in Compromised Hosts with a Verdict of Infected. The answer is C

Thomas_2020Option: C
Dec 17, 2023

C correct

LAFNELLOption: C
Jan 4, 2024

C is correct

rian00z_Option: C
Apr 14, 2024

C is correct