Cyber Monday 2024! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet Exam NSE8_812 Topic 5 Question 30 Discussion

Actual exam question for Fortinet's NSE8_812 exam
Question #: 30
Topic #: 5
[All NSE8_812 Questions]

Refer to the exhibit showing a FortiSOAR playbook.

You are investigating a suspicious e-mail alert on FortiSOAR, and after reviewing the executed playbook, you can see that it requires intervention.

What should be your next step?

Show Suggested Answer Hide Answer
Suggested Answer: A

The exhibited playbook requires intervention, which means that the playbook has reached a point where it needs a human operator to take action. The next step should be to go to the Incident Response tasks dashboard and run the pending actions. This will allow you to see the pending actions that need to be taken and to take those actions.

The other options are not correct. Option B will only show you the notification icon, but it will not allow you to run the pending input action. Option C will run the Mark Drive by Download playbook action, but this is not the correct action to take in this case. Option D is not a valid option.

Here are some additional details about pending actions in FortiSOAR:

Pending actions are actions that need to be taken by a human operator.

Pending actions are displayed in the Incident Response tasks dashboard.

Pending actions can be run by clicking on the action in the dashboard.


Contribute your Thoughts:

Alethea
3 months ago
B) Click on the notification icon on FortiSOAR GUI and run the pending input action. Duh, it's right there in the question. Although, I do enjoy a good game of 'find the hidden action'.
upvoted 0 times
...
Amina
3 months ago
C) Run the Mark Drive by Download playbook action. Wait, is this some kind of secret spy mission? I'm in!
upvoted 0 times
Luis
2 months ago
D) Reply to the e-mail with the requested Playbook action
upvoted 0 times
...
Dewitt
2 months ago
C) Run the Mark Drive by Download playbook action. Sounds exciting!
upvoted 0 times
...
German
2 months ago
B) Click on the notification icon on FortiSOAR GUI and run the pending input action
upvoted 0 times
...
Solange
2 months ago
A) Go to the Incident Response tasks dashboard and run the pending actions
upvoted 0 times
...
...
Lavina
3 months ago
D) Reply to the e-mail with the requested Playbook action. I mean, who doesn't love a good old-fashioned email reply, right? It's like a digital love letter to the suspicious activity.
upvoted 0 times
Elmira
2 months ago
D) Reply to the e-mail with the requested Playbook action
upvoted 0 times
...
Paris
2 months ago
A) Go to the Incident Response tasks dashboard and run the pending actions
upvoted 0 times
...
Zona
2 months ago
B) Click on the notification icon on FortiSOAR GUI and run the pending input action
upvoted 0 times
...
Ruth
2 months ago
A) Go to the Incident Response tasks dashboard and run the pending actions
upvoted 0 times
...
...
Mammie
3 months ago
I think option C) Run the Mark Drive by Download playbook action could also be a valid next step, depending on the situation.
upvoted 0 times
...
Marci
3 months ago
A) Go to the Incident Response tasks dashboard and run the pending actions. Surely, this is the right way to handle the situation.
upvoted 0 times
Coral
3 months ago
Yes, that sounds like the best next step to take.
upvoted 0 times
...
Aja
3 months ago
I think we should go to the Incident Response tasks dashboard and run the pending actions.
upvoted 0 times
...
...
Louvenia
3 months ago
I would go with option B) Click on the notification icon on FortiSOAR GUI and run the pending input action.
upvoted 0 times
...
Ernest
3 months ago
I agree with Maddie, running the pending actions seems like the logical next step.
upvoted 0 times
...
Sheron
4 months ago
B) Click on the notification icon on FortiSOAR GUI and run the pending input action. This is the most logical next step to investigate the suspicious email alert.
upvoted 0 times
Scot
3 months ago
I agree. Let's go ahead and take that next step.
upvoted 0 times
...
Gianna
3 months ago
That sounds like a good idea. It's important to investigate the suspicious email alert.
upvoted 0 times
...
Ciara
3 months ago
I think we should click on the notification icon on FortiSOAR GUI and run the pending input action.
upvoted 0 times
...
...
Maddie
4 months ago
I think the next step should be A) Go to the Incident Response tasks dashboard and run the pending actions.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77