QuestionQ13

Events, forensics, and threat hunting

Refer to the exhibit.

Question Image

Based on the incident details displayed in the exhibit, which two statements about this incident are correct?

Choose two
  • A The incident has already been fully handled.
  • B The incident occurred on only one device.
  • C The destination IP address is blocked by FortiGate.
  • D The incident is classified by the FortiEDR Core.
Explanation

The incident affects one device, while the incident records show multiple variants. Its audit trail records that IP address 74.125.235.20 was added to the malicious-IP addresses on the FortiGate firewall; FortiEDR–FortiGate integration automatically denies access to such malicious destination addresses. The incident remains unhandled, and its shown classification change is attributed to Fortinet rather than the FortiEDR Core.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!