When managing incidents on FortiAnalyzer, what must an analyst be aware of?
A.
You can manually attach generated reports to incidents.
B.
The status of the incident is always linked to the status of the attached event.
C.
Severity incidents rated with the level High have an initial service-level agreement (SLA) response time of 1 hour.
D.
Incidents must be acknowledged before they can be analyzed.
The Answer Is:
A
This question includes an explanation.
Explanation:
Exact Extract: Study Guide p.185: reports can be attached to incidents manually from an existing report, manually from an incident, or automatically through playbooks.
Technical Deep Dive: The correct answer is A. Incidents are containers for related security events, and attaching a report gives the analyst historical or contextual evidence in addition to real-time event data. Option B is wrong because incident status is managed independently from attached event status. Option C is not a FortiAnalyzer default rule from the guide; SLA response times are organization-specific. Option D is wrong because incidents can be opened and analyzed directly; acknowledgment is not a prerequisite to analysis.
FCP_FAZ_AN-7.6 PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 65% Discount on All Products,
Use Coupon: "ac4s65"