QuestionQ26

Incident response

Which configuration is necessary for FortiNAC to perform an automated incident response based on FortiGate traffic?

  • A FortiNAC should be added as a participant in the Security Fabric.
  • B FortiNAC requires read-write SNMP access to FortiGate.
  • C FortiNAC should be configured as a syslog server on FortiGate.
  • D FortiNAC requires HTTPS access to FortiGate for API calls.
Explanation

FortiGate must forward its relevant traffic and event logs to FortiNAC through syslog. FortiNAC receives and parses those messages to generate security events and alarms, which can trigger the configured automated response.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!