FCP Threat Detection & Incident Response 5 β Questions and Answers
Question 1: Which FortiGate feature can automatically quarantine an endpoint detected by FortiEDR as compromised, without manual SOC intervention?
- Fabric Agent integration with Endpoint Quarantine via Security Fabric (Correct answer)
- Static address group assignment
- Manual VLAN change on FortiSwitch CLI
- FortiGuard IP Reputation blocking only
Correct answer: Fabric Agent integration with Endpoint Quarantine via Security Fabric
The Fortinet Security Fabric enables FortiEDR to trigger automated endpoint quarantine on FortiGate via the Fabric Agent, removing the host from the network instantly.
Question 2: An analyst reviews FortiSIEM and sees an incident tagged 'False Positive' but the same attack pattern recurs the next day. What is the BEST corrective action?
- Tune the correlation rule to reduce false positives while preserving true positive detection (Correct answer)
- Delete the correlation rule permanently
- Mark all future similar incidents as false positives automatically
- Ignore the pattern since it was previously classified as benign
Correct answer: Tune the correlation rule to reduce false positives while preserving true positive detection
Rule tuning adjusts thresholds or adds exception conditions to reduce noise without losing the ability to detect genuine attacks with the same pattern.
Question 3: In FortiSOAR, what is the role of a 'Playbook Trigger' based on an incoming alert from FortiSIEM?
- It automatically initiates a predefined response workflow when FortiSIEM pushes a matching alert (Correct answer)
- It manually queues an alert for analyst review with no automation
- It disables the FortiSIEM connector to prevent alert floods
- It archives the alert to cold storage without processing
Correct answer: It automatically initiates a predefined response workflow when FortiSIEM pushes a matching alert
A FortiSOAR playbook trigger listens for inbound alerts from integrated sources like FortiSIEM and automatically launches the mapped response playbook.
Question 4: During a post-incident review, the team finds that an attacker used DNS-over-HTTPS (DoH) to evade detection. Which Fortinet control should be implemented to address this gap?
- Enable DNS Filter to block DoH providers and force DNS traffic through FortiGate's resolver (Correct answer)
- Block all UDP port 53 traffic at the perimeter
- Increase IPS sensor sensitivity for HTTP signatures
- Deploy FortiDeceptor honeypots on the DNS server
Correct answer: Enable DNS Filter to block DoH providers and force DNS traffic through FortiGate's resolver
FortiGate's DNS Filter can block known DoH provider domains and IPs, forcing clients to use inspectable DNS and preventing covert channel abuse.
Question 5: Which phase of the Cyber Kill Chain does FortiSandbox MOST directly address by detonating suspicious files in an isolated environment?
- Delivery and Exploitation (Correct answer)
- Reconnaissance
- Command and Control (established)
- Actions on Objectives
Correct answer: Delivery and Exploitation
FortiSandbox detects malicious payloads during the Delivery and Exploitation phases by safely executing files and observing their behavior before they reach endpoints.
Question 6: A threat hunter finds evidence of T1003 (OS Credential Dumping) on a Windows host via FortiEDR telemetry. Which attacker tool is MOST commonly associated with this technique?
- Mimikatz (Correct answer)
- Metasploit Meterpreter (network pivot)
- Nmap (port scanner)
- Wireshark (packet capture)
Correct answer: Mimikatz
Mimikatz is the most widely associated tool with LSASS memory dumping and other Windows credential extraction techniques mapped to MITRE T1003.
Question 7: FortiAnalyzer shows a spike in 'Application Control' block events for the 'Tor' application category from multiple internal hosts. What is the MOST appropriate initial incident response action?
- Identify the internal hosts involved and investigate whether Tor usage is policy-sanctioned or indicative of data exfiltration (Correct answer)
- Immediately disable all internet access for the organization
- Remove the Application Control profile to stop generating false alerts
- Forward logs to law enforcement without further investigation
Correct answer: Identify the internal hosts involved and investigate whether Tor usage is policy-sanctioned or indicative of data exfiltration
The first step is identifying the affected hosts and determining whether Tor use violates policy or indicates exfiltration before taking broader disruptive actions.
Which FortiGate feature can automatically quarantine an endpoint detected by FortiEDR as compromised, without manual SOC intervention?