Exact Extract: “FortiSOAR assumes the Preparation phase is outside its incident handling scope because it is considered a pre-SOAR responsibility.”
Exact Extract: “In FortiSOAR, the Detection and Analysis phases are expanded into Detection, Identification, and Confirmation… In the Identification phase, analysts can evaluate the alerts tied to the incident, understand the context, and enrich indicators. In the Confirmation phase, an analyst can confirm whether the incident is a true positive or a false positive.”
The correct answers are B and D . NIST 800-61 Revision 2 uses broader incident handling phases, including Preparation , Detection and Analysis , Containment , Eradication , Recovery , and Post-Incident Activity . FortiSOAR modifies that model by treating Preparation as outside SOAR scope and splitting NIST’s Detection and Analysis into more operationally useful FortiSOAR phases: Detection , Identification , and Confirmation . Therefore, Identification and Confirmation are FortiSOAR-specific phase names that are not standalone NIST phases.
A is wrong because Preparation is a NIST phase, but FortiSOAR excludes it from its incident handling workflow. C is not the best answer because Detection is part of NIST’s combined Detection and Analysis phase and is also present in FortiSOAR.
Technical Deep Dive: FortiSOAR’s split is practical. Detection is when the alert or incident enters FortiSOAR. Identification is where analysts enrich, contextualize, and scope the issue. Confirmation is the decision point where the incident is validated as true positive or false positive. This granularity improves playbook design because different automation belongs in each phase. FortiGate NP/CP offloading has no relevance here because this is incident lifecycle modeling, not traffic processing.
Submit