exam questions

Exam NSE8_812 All Questions

View all questions & answers for the NSE8_812 exam

Exam NSE8_812 topic 1 question 39 discussion

Actual exam question from Fortinet's NSE8_812
Question #: 39
Topic #: 1
[All NSE8_812 Questions]


Refer to the exhibit.
The exhibit shows the forensics analysis of an event detected by the FortiEDR core.
In this scenario, which statement is correct regarding the threat?

  • A. This is an exfiltration attack and has been stopped by FortiEDR
  • B. This is an exfiltration attack and has not been stopped by FortiEDR
  • C. This is a ransomware attack and has not been stopped by FortiEDR
  • D. This is a ransomware attack and has been stopped by FortiEDR
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Pat1361
10 months ago
"Block fortinet" is not red, meaning it has not been stopped. C is correct
upvoted 2 times
...
ac89l
1 year, 3 months ago
Selected Answer: C
A,D not correct, because this is Simulated Block, and the 'block fortinet" is gray. I would go with C https://docs.fortinet.com/document/fortiedr/6.0.0/administration-guide/28226/flow-analyzer-view
upvoted 2 times
...
Golux
1 year, 4 months ago
C is the correct answer ! the last rightmost node logo is a file, meaning it is a ransomware attack, and the Block fortinet Logo is grey ( not red) meaning it is a simulated block...the attack was not stopped
upvoted 2 times
...
ama6
1 year, 7 months ago
it has been blocked but not stop
upvoted 2 times
...
ama6
1 year, 7 months ago
B is correct exhibit also shows that the attack is using the Cobalt Strike beacon. Cobalt Strike is a penetration testing tool that can be used for both legitimate and malicious purposes. In this case, the Cobalt Strike beacon is being used to exfiltrate files from the device.
upvoted 1 times
...
pplee_sh
1 year, 8 months ago
Selected Answer: D
Should be D
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago