Question 1
Q1A SOC analyst at a large financial institution is designing a FortiAnalyzer playbook to automate the initial response to a critical 'Potential Ransomware Activity' event. The playbook must first isolate the affected endpoint using a FortiGate connector, then retrieve the process hash from the event logs, and finally submit this hash to a third-party sandboxing service for deep analysis. Which playbook task sequence represents the most logical and effective workflow for this scenario?
Show answer & explanation
Correct answer: B
The most effective workflow prioritizes containment. First, quarantine the endpoint to prevent the potential ransomware from spreading (Containment). Second, retrieve the necessary artifact (the process hash) for investigation. Finally, submit the hash to the sandbox for detailed analysis to confirm the threat and inform further response actions. Performing these steps out of order could allow the threat to propagate or lead to analysis of an incorrect artifact.