Podcast
Questions and Answers
Which action can be performed by right-clicking an event?
Which action can be performed by right-clicking an event?
- Leave a comment
- Create an incident
- Filter events
- All of the above (correct)
When should an event be acknowledged?
When should an event be acknowledged?
- When it is a compromised device
- When it is related to IPS
- When it is mitigated (correct)
- When it needs further investigation
What is the purpose of creating an incident?
What is the purpose of creating an incident?
- To leave a comment for your records
- To prevent or mitigate security breaches (correct)
- To acknowledge the event
- To assign it to an administrator
How can incidents be created in FortiAnalyzer?
How can incidents be created in FortiAnalyzer?
What information is shown on the incident analysis page?
What information is shown on the incident analysis page?
Where can you find the list of events associated with an incident?
Where can you find the list of events associated with an incident?
What should be done with a solved incident?
What should be done with a solved incident?
What can be configured for each incident status change?
What can be configured for each incident status change?
What is the importance of keeping incident settings up to date?
What is the importance of keeping incident settings up to date?
When should an incident be considered closed?
When should an incident be considered closed?
By default, event handlers are restricted to the A-dom where they were created. What happens to event handlers by default?
By default, event handlers are restricted to the A-dom where they were created. What happens to event handlers by default?
When exporting an event handler, what options are available for the file format?
When exporting an event handler, what options are available for the file format?
What can be used as filters in Event Handlers and Reports?
What can be used as filters in Event Handlers and Reports?
What format is used to save the exported event handler file?
What format is used to save the exported event handler file?
How can you import an event handler?
How can you import an event handler?
What can you do with an event in the Event Monitor?
What can you do with an event in the Event Monitor?
What types of events can be examined in All Events?
What types of events can be examined in All Events?
What should be given priority when managing events?
What should be given priority when managing events?
What actions can be performed for events in the Event Monitor?
What actions can be performed for events in the Event Monitor?
What is the default behavior if an imported event handler's name already exists?
What is the default behavior if an imported event handler's name already exists?