What happens when the IOC breach detection engine on FortiAnalyzer finds web logs that match a blocklisted IP address?

What happens when the IOC breach detection engine on FortiAnalyzer finds web logs that match a blocklisted IP address?
A . The endpoint is marked as Compromised and. optionally, can be put in quarantine.
B . FortiAnalyzer flags the associated host for further analysis.
C . A new Infected entry is added for the corresponding endpoint.
D . The detection engine classifies those logs as Suspicious

Answer: A

Subscribe
Notify of
guest
0 Comments
Inline Feedbacks
View all comments