QuestionQ12

Events, forensics, and threat hunting

Refer to the exhibit.

Question Image

Based on the exhibit, which statement regarding this threat-hunting query is true?

  • A RDP connections will be automatically blocked and classified as suspicious.
  • B A security incident will be generated whenever the device attempts an RDP connection.
  • C The query is limited to detecting network activity and does not inspect process behavior.
  • D The query is configured as a global hunting rule and is automatically visible across all organizations.
Explanation

A scheduled FortiEDR query automatically creates a security event when it finds matching activity. This query runs every 15 minutes, looks for activity with remote port 3389 (RDP), and assigns matching events the Suspicious classification. It does not itself block connections.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!