Question 1 of 30
A network administrator is tasked with enhancing the detection of insider threats and sophisticated malware on a segmented corporate network protected by FortiGate firewalls. The administrator has configured FortiAnalyzer for centralized logging and reporting. During a routine review, an alert is generated indicating a workstation exhibiting an atypical pattern of high-volume outbound connections to a newly registered, geographically distant IP address range, using an unusual port. Which FortiAnalyzer feature, in conjunction with FortiGate logs, is most instrumental in identifying and flagging this specific type of anomalous user and device activity?
User and Device Behavior Analysis (UDBA) module for baseline deviation detection
FortiGate's Intrusion Prevention System (IPS) signature matching against known malware
FortiAnalyzer's Log View to manually sift through raw traffic logs for suspicious patterns
FortiGate's Application Control to block unsanctioned protocols and services

Preparing for NSE7_LED7.0 Fortinet NSE 7 LAN Edge 7.0? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free