QuestionQ16

Events, forensics, and threat hunting

Refer to the exhibit.

Question Image

A FortiEDR analyst is prioritizing response actions.

One application has a Critical vulnerability score but an Unknown ACI rating, while another has a Medium vulnerability score with active ACI evidence of adversary targeting. Which application must be addressed first?

Explanation

ACI severity supplies adversary-centric intelligence, including threat-actor insights, while NIST severity represents baseline vulnerability severity. Active evidence that adversaries are targeting a vulnerability indicates immediate exploitation relevance, so it should be prioritized ahead of a Critical vulnerability that has no ACI evidence.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!