View all questions & answers for the NSE 6 - FortiEDR 7.0 Administrator Exam Materials exam
NSE 6 - FortiEDR 7.0 Administrator Exam Materials-Question 10 Discussion
Comments
Selected Answers: A, C
C) A valid API user with access to connectors – Integration requires a user account with valid API credentials that has proper permission for Fabric connectors (e.g., FortiAnalyzer or FortiAnalyzer Cloud).
Selected Answers: A, C
• A valid API user with access to connectors: An API user account with the "Rest API User" role is necessary for the Security Fabric to interact with the FortiEDR Central Manager.
https://docs.fortinet.com/document/fortiedr/7.2.3/administration-guide/778942/firewall-integration
Selected Answers: A, C
Integrate with security devices:
Firewall: Automatically add malicious IP addresses to blocked lists
Network access control (NAC): Isolate a device using a FortiNAC device
Sandbox: Automatically send malicious files to FortiSandbox for analysis
Custom Connector: Third-party integration for automated incident response
FortiEDR requirements:
Central manager connected to FCS
On-premises core with jumpbox functionality
A valid API user with access to connectors
FortiEDR version 5.0.3 can be integrated with multiple connectors for automated incident response. You can configure your integration using RESTful API or on the ADMINISTRATION tab of the management console under INTEGRATIONS. Be aware that you also need to configure connectors as well to integrate with FortiEDR. To configure your integrations on FortiEDR, you will need an on-premises core with jumpbox functionality and a valid API user able to access FortiGate, FortiManager, FortiSandbox, and/or FortiNAC. You'll also need a central manager that is connected to Fortinet Cloud Service. These connectors can be used as part of the automated extended response.
Which two criteria are required for integrating FortiEDR with the Fortinet Security Fabric? (Choose two answers)
Brave-Dump Clients Votes