Question 1 of 30
A cybersecurity operations team, utilizing FortiSOAR to aggregate threat intelligence from a specialized third-party feed, discovers a critical zero-day indicator of compromise—a newly active command-and-control server IP address. This IP address is not yet present in any FortiGate\'s native blacklist. To ensure immediate and consistent protection across the enterprise\'s distributed network of FortiGate firewalls, managed centrally, which operational workflow within the Fortinet Security Fabric would provide the most effective and timely mitigation?
FortiManager ingests the new IP address from FortiSOAR, dynamically updates a corresponding address object, and pushes a revised firewall policy to all managed FortiGates to block traffic to this specific IP.
Security analysts manually configure a deny-all firewall policy on each individual FortiGate device to block the newly identified IP address, ensuring immediate local protection.
FortiAnalyzer is configured to generate an alert based on the incoming IP address, prompting manual investigation and policy adjustments by the security team for each affected FortiGate.
The FortiGate's Intrusion Prevention System (IPS) profile is updated with a custom signature designed to detect and block traffic patterns associated with the C2 server, relying on behavioral analysis rather than the specific IP.

Preparing for NSE8811 Fortinet NSE 8 Written Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free