Exam FCP_FAZ_AN-7.6 Topic 2 Question 29 Discussion
Actual exam question for Fortinet's FCP_FAZ_AN-7.6 exam
Question #: 29
Topic #: 2
Question #: 29
Topic #: 2
Which log will generate an event with the status Unhandled?
Suggested Answer: B Vote an answer
Study Guide p.82: "Unhandled" means the security event risk is not mitigated or contained, and an IPS/AV pass action is an example.
Technical Deep Dive: The correct answer is B because an IPS log with action=pass means the traffic matched or was observed in a way that generated a security event, but the traffic was not blocked, dropped, or quarantined. FortiAnalyzer therefore treats the event as still open from a SOC workflow perspective. Option A is wrong because quarantine isolates the malicious object and maps to Contained. Options C and D are wrong because dropped or blocked actions mean enforcement already occurred, which maps to Mitigated rather than Unhandled.
Technical Deep Dive: The correct answer is B because an IPS log with action=pass means the traffic matched or was observed in a way that generated a security event, but the traffic was not blocked, dropped, or quarantined. FortiAnalyzer therefore treats the event as still open from a SOC workflow perspective. Option A is wrong because quarantine isolates the malicious object and maps to Contained. Options C and D are wrong because dropped or blocked actions mean enforcement already occurred, which maps to Mitigated rather than Unhandled.
by Nathan at Sep 30, 2026, 12:45 AM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).