Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet Exam NSE8_812 Topic 1 Question 32 Discussion

Actual exam question for Fortinet's NSE8_812 exam
Question #: 32
Topic #: 1
[All NSE8_812 Questions]

Refer to the exhibit showing a FortiSOAR playbook.

You are investigating a suspicious e-mail alert on FortiSOAR, and after reviewing the executed playbook, you can see that it requires intervention.

What should be your next step?

Show Suggested Answer Hide Answer
Suggested Answer: A

The exhibited playbook requires intervention, which means that the playbook has reached a point where it needs a human operator to take action. The next step should be to go to the Incident Response tasks dashboard and run the pending actions. This will allow you to see the pending actions that need to be taken and to take those actions.

The other options are not correct. Option B will only show you the notification icon, but it will not allow you to run the pending input action. Option C will run the Mark Drive by Download playbook action, but this is not the correct action to take in this case. Option D is not a valid option.

Here are some additional details about pending actions in FortiSOAR:

Pending actions are actions that need to be taken by a human operator.

Pending actions are displayed in the Incident Response tasks dashboard.

Pending actions can be run by clicking on the action in the dashboard.


Contribute your Thoughts:

Truman
7 hours ago
Mark Drive by Download? Nah, that's not quite what we're after. Let's stick to the Incident Response tasks.
upvoted 0 times
...
Lezlie
8 days ago
Ah, the notification icon, of course! That's the quickest way to get those pending actions running.
upvoted 0 times
...
Yuette
11 days ago
Hmm, looks like we need to intervene. I'm thinking the Incident Response tasks dashboard is the way to go here.
upvoted 0 times
...
Valentin
24 days ago
I would go with B) Click on the notification icon on FortiSOAR GUI and run the pending input action. It might provide more specific instructions.
upvoted 0 times
...
Olive
25 days ago
I agree with Afton. It makes sense to follow the playbook and take action on the pending tasks.
upvoted 0 times
...
Afton
26 days ago
I think the next step should be A) Go to the Incident Response tasks dashboard and run the pending actions.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77