Question 1
A SOC analyst at a financial services company is investigating a high-severity event related to multiple failed login attempts from a suspicious IP address. The analyst needs to quickly gather all associated traffic logs, endpoint logs, and application control logs related to this IP for the last 24 hours. Which FortiAnalyzer feature provides the most efficient, integrated view for this type of cross-log-type investigation?
Answer and explanation
Correct answer: C
The global search bar in the 'Log View' tab is the most efficient tool for this task. It allows an analyst to search for a specific value (like an IP address) across all indexed log types simultaneously within the selected time frame. This provides a quick, correlated view of all activities associated with the IP without the need to build reports or manually browse individual log files.