QuestionQ9

Zero-trust LAN access

Refer to the exhibits.

Question Image

Question Image

Question Image

Question Image

Question Image

Review the FortiGate configuration, FortiAnalyzer logs, and FortiGate widget displayed in the exhibits.

Security Fabric quarantine automation is configured to automatically isolate compromised devices. FortiAnalyzer has been added to the Security Fabric, and an automation stitch has been set up to quarantine compromised devices.

To test this configuration, a device with IP address 10.0.2.1, connected through a managed FortiSwitch, attempts to reach a malicious website. FortiAnalyzer logs verify that the event was recorded, but the device is absent from the FortiGate quarantine widget.

Which two reasons could account for FortiGate not quarantining the device?

Choose two
  • A The threat detection services license is missing or invalid under FortiAnalyzer.
  • B The SSL inspection should be set to deep-Inspection.
  • C The malicious website is not recognized as an indicator of compromise (IOC) by FortiAnalyzer.
  • D The IOC action should include only the FortiSwitch in the quarantine.
Explanation

FortiAnalyzer must be licensed for its Indicators of Compromise (IOC)/Compromised Hosts service and have a valid threat database to identify a source as compromised. It evaluates web-filter, DNS, and traffic logs against that database; a logged malicious-site event that does not match or accumulate to a qualifying IOC verdict will not generate the high-severity compromised-host event required by the automation stitch. The standard quarantine action intentionally supports both FortiSwitch and FortiAP access-layer devices.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!