20 Questions
Which action can be performed by right-clicking an event?
All of the above
When should an event be acknowledged?
When it is mitigated
What is the purpose of creating an incident?
To prevent or mitigate security breaches
How can incidents be created in FortiAnalyzer?
Manually or automatically with a playbook
What information is shown on the incident analysis page?
All of the above
Where can you find the list of events associated with an incident?
Events
What should be done with a solved incident?
Delete it from the list
What can be configured for each incident status change?
Notifications
What is the importance of keeping incident settings up to date?
To track the progress of the investigation
When should an incident be considered closed?
When it is marked as solved
By default, event handlers are restricted to the A-dom where they were created. What happens to event handlers by default?
They are restricted to the A-dom where they were created.
When exporting an event handler, what options are available for the file format?
Text or zipped
What can be used as filters in Event Handlers and Reports?
Subnets and subnet groups
What format is used to save the exported event handler file?
JSON
How can you import an event handler?
Right-click on Event Handler List and select Import
What can you do with an event in the Event Monitor?
View events generated by event handlers
What types of events can be examined in All Events?
All events, endpoint events, threat events, and system events
What should be given priority when managing events?
Events with an unhandled status and/or critical severity
What actions can be performed for events in the Event Monitor?
Acknowledge, add a comment, assign to an administrator, or create an incident
What is the default behavior if an imported event handler's name already exists?
A timestamp will be automatically appended to the name
Learn how to export event handlers in different A-doms and save time from creating them again. Discover the step-by-step process to export event handlers from the Event Handler List and choose the appropriate options.
Make Your Own Quizzes and Flashcards
Convert your notes into interactive study material.
Get started for free