FortiView
20 Questions
0 Views

Choose a study mode

Play Quiz
Study Flashcards
Spaced Repetition
Chat to lesson

Podcast

Play an AI-generated podcast conversation about this lesson

Questions and Answers

Which pane is designed for a network and security operations center where multiple dashboards are displayed in large monitors in a SOC or NOC environment?

  • Widgets
  • Monitors (correct)
  • FortiClient software inventory
  • Threats
  • What can you view on the Monitors dashboards?

  • Threats and compromised hosts
  • Wi-Fi and ZTNA
  • Applications and system performance
  • Network events and security alerts (correct)
  • What can you investigate on the Traffic dashboard?

  • Compromised hosts
  • DNS servers
  • Applications generating traffic
  • Top sources of traffic (correct)
  • What is listed as the major source of traffic from the host with the IP address 10.0.0.21?

    <p>DNS</p> Signup and view all the answers

    What does log fetching allow FortiAnalyzer to do?

    <p>Run queries or reports on archived logs</p> Signup and view all the answers

    What is the role of the FortiAnalyzer device that sends logs during log fetching?

    <p>Fetch server</p> Signup and view all the answers

    How many log-fetching sessions can be established between two FortiAnalyzer devices?

    <p>One</p> Signup and view all the answers

    What must be ensured for log fetching to work properly?

    <p>All of the above</p> Signup and view all the answers

    What happens to logs outside the data policy constraints on the client?

    <p>They are deleted</p> Signup and view all the answers

    When can you see the logs of devices in the client?

    <p>After adding the devices to Device Manager</p> Signup and view all the answers

    Which column indicates the number of different threats associated with an IOC hit in FortiView?

    <p>Threats</p> Signup and view all the answers

    What action can you take to acknowledge an IOC hit in FortiView?

    <p>Click &quot;Ack&quot; in the Acknowledge column</p> Signup and view all the answers

    What can you do to view more details and filter the view based on two categories for an IOC hit in FortiView?

    <p>Double-click the entry</p> Signup and view all the answers

    What does the Blocklist category indicate for an IOC hit in FortiView?

    <p>Items marked as infected after checking the blocklist</p> Signup and view all the answers

    What action can you take if you believe that an IP address or domain listed under the Detect Pattern column is valid for an IOC hit in FortiView?

    <p>Report it as misrated</p> Signup and view all the answers

    What does the Suspicious category indicate for an IOC hit in FortiView?

    <p>A match found in the suspicious list</p> Signup and view all the answers

    What does Fortianalyzer do when an endpoint is flagged in the Suspicious category for an IOC hit in FortiView?

    <p>Lists or updates the endpoint in Compromised Hosts</p> Signup and view all the answers

    What can you do to filter the entries in the IOC FortiView by specifying devices or a time period?

    <p>Filter the entries by specifying devices</p> Signup and view all the answers

    By default, can you view acknowledged IOCs in FortiView?

    <p>Yes, acknowledged IOCs are always visible</p> Signup and view all the answers

    What can you do when you double-click an entry in FortiView?

    <p>View more details and filter the view based on two categories</p> Signup and view all the answers

    More Like This

    Mastering FortiView Charting
    16 questions
    FortiSIEM Incident Knowledge Quiz
    7 questions
    Use Quizgecko on...
    Browser
    Browser