FCP Threat Detection & Incident Response 3 — Questions and Answers
Question 1: Which MITRE ATT&CK tactic does FortiDeceptor primarily address by luring attackers into interacting with honeypot assets?
- Discovery (Correct answer)
- Initial Access
- Exfiltration
- Impact
Correct answer: Discovery
FortiDeceptor honeypots attract attackers performing internal discovery scans, triggering alerts when decoy assets are probed.
Question 2: An analyst needs to search across 90 days of compressed archive logs in FortiAnalyzer. Which feature enables queries against these historical records?
- Log Fetch (Archive Log Search) (Correct answer)
- Real-time Log Monitor
- FortiView Dashboard
- Event Handler correlation
Correct answer: Log Fetch (Archive Log Search)
FortiAnalyzer's Log Fetch feature retrieves and indexes archived logs from storage, enabling historical queries beyond the hot-log window.
Question 3: During incident eradication, an analyst removes malware from an infected host. What is the NEXT step in the NIST incident response lifecycle after eradication?
- Recovery (Correct answer)
- Identification
- Containment
- Preparation
Correct answer: Recovery
After eradication, the NIST lifecycle moves to Recovery—restoring systems to normal operations and monitoring for signs of reinfection.
Question 4: FortiGate's Intrusion Prevention System (IPS) generates an alert for CVE-2021-44228 (Log4Shell). Which action should a SOC analyst take FIRST?
- Verify whether the target host is running a vulnerable Log4j version (Correct answer)
- Immediately power off all web servers
- Disable the IPS sensor to reduce false positives
- Escalate to the vendor without further investigation
Correct answer: Verify whether the target host is running a vulnerable Log4j version
Confirming whether the targeted asset actually runs a vulnerable Log4j version determines if the alert is a true positive before taking disruptive action.
Question 5: What is the purpose of a FortiSIEM 'Watch List' in the context of threat detection?
- A dynamic list of high-risk entities (users, IPs, hosts) that triggers enhanced monitoring rules (Correct answer)
- A read-only list of vendor-supplied threat signatures
- A scheduled report of the top 10 firewall violations
- A list of assets excluded from all correlation rules
Correct answer: A dynamic list of high-risk entities (users, IPs, hosts) that triggers enhanced monitoring rules
Watch Lists in FortiSIEM allow analysts to flag specific entities for elevated scrutiny, enabling correlation rules to fire with lower thresholds for those entities.
Question 6: Which FortiEDR response capability allows an analyst to isolate a compromised endpoint from the network while maintaining the FortiEDR management channel?
- Network Isolation (Forensic Mode) (Correct answer)
- Full Shutdown via EDR console
- VLAN reassignment through FortiSwitch
- Firewall address group blacklisting
Correct answer: Network Isolation (Forensic Mode)
FortiEDR's Network Isolation (Forensic Mode) blocks all network traffic except the management tunnel, allowing continued investigation without network spread.
Question 7: In a FortiSOAR incident response workflow, what does the 'Escalate' action typically trigger?
- A notification to a higher-tier analyst and an increase in incident severity (Correct answer)
- Automatic closure of the incident after review
- A rollback of all firewall rule changes
- Submission of the incident to a public threat database
Correct answer: A notification to a higher-tier analyst and an increase in incident severity
The Escalate action in FortiSOAR notifies senior analysts and typically raises the incident's severity or SLA priority for faster response.
Which MITRE ATT&CK tactic does FortiDeceptor primarily address by luring attackers into interacting with honeypot assets?