FAQ
Answers to common questions about FPT Security Hub (CSPM) for L1 Support.
1. Product overview
| # | Question | Answer |
|---|---|---|
| 1.1 | What is FPT Security Hub (CSPM)? | FPT Security Hub is a Cloud Security Posture Management (CSPM) service that automatically detects misconfigurations and security risks in cloud infrastructure. It provides an overview dashboard, a prioritized list of issues by severity, and centralized management of all cloud resources in one place. |
| 1.2 | What resource types does FPT Security Hub scan? | Supported asset types: Instance, Subnet, Security Group, Storage Disk, User, User Group, IAM Role, Load Balancer, Database, Object Storage. |
| 1.3 | How often is scan data updated? | The system automatically performs incremental scans every 10 minutes — scanning only new assets or assets with configuration changes, not a full scan every time. |
| 1.4 | How are issue severity levels classified? | Issues are classified into four levels: Critical, High, Medium, Low. Prioritize resolution from Critical downward. |
| 1.5 | Who has access to FPT Security Hub? | Tenant Admin only. Other users see: "You do not have sufficient permissions to view this page!" |
2. Service activation
| # | Question | Answer |
|---|---|---|
| 2.1 | Is the CSPM service enabled by default? | No. The service is not enabled automatically — the Tenant Admin must activate it manually the first time by clicking "Activate Service" on the interface. |
| 2.2 | A customer sees "SERVICE IS NOT ACTIVATED" — what should I do? | The service has not been activated for this Tenant. Guide the Tenant Admin to click "Activate Service" on that screen. After activation, the system moves to the Dashboard immediately — however, wait a moment for the first scan results to appear. |
| 2.3 | Can the Service Activation screen reappear after activation? | Yes. If the Tenant Admin deactivates the service, the Service Activation screen will reappear when accessing the system. |
| 2.4 | Activation done but no data yet — how to handle? | This is normal behavior. After activation, the system shows the Dashboard immediately but needs to wait for the automatic scan cycle (10 minutes) before the first results are available. Once scanning is complete, click Sync to load the latest data. |
| 2.5 | Why does clicking "Activate Service" get no response? | The system may be busy — retry after a few minutes. If it still fails, escalate to L2 to investigate the activation API. |
3. Dashboard
| # | Question | Answer |
|---|---|---|
| 3.1 | What information does the Dashboard show? | The Dashboard provides an overview including: Security Risk Score, Total Assets, Publicly Exposed Assets, Open Findings (by severity), Top Risky Assets, and Security Findings Trend (trend chart over time). |
| 3.2 | What is the Security Risk Score? What score is considered dangerous? | An overall security risk rating on a scale of 1–10. Lower score = lower risk (for example, 1.5/10 = low); high score (for example, 9/10) = high risk, requires immediate attention. |
| 3.3 | What are Publicly Exposed Assets? | Cloud resources that are exposed to the public internet. This group requires priority review because it is vulnerable to external attacks. |
| 3.4 | What are Top Risky Assets? | A list of resources with the most security issues. Click the 👁 icon on the Dashboard to view the list of issues on each asset. |
| 3.5 | The Dashboard shows no data — what is the cause? | A scan cycle may not have completed yet. Wait for the automatic scan (10 minutes); after scanning is done, click Sync to load the latest results. |
4. Issue management
| # | Question | Answer |
|---|---|---|
| 4.1 | What is Issue Management used for? | A centralized screen showing all security issues detected by CSPM scans. Tenant Admins can search, filter by asset type or compliance control, view issue details, and find remediation guidance. |
| 4.2 | What columns does the Issue List show? | Severity (+ Score), Issue (name + description), Asset (name + type), VPC, Status, First Detected, Reference (related Control ID). |
| 4.3 | What is the default sort order for issues? | Default sort is Score descending — most critical issues appear at the top. |
| 4.4 | What can I search issues by? | Search by issue name, description, asset name, VPC (case-insensitive). |
| 4.5 | What does the filter support? | Filter by Asset Type (Instance, Subnet, Security Group, etc.) and by Reference (Control ID from a compliance framework). |
| 4.6 | What does Issue Detail show? | Severity, Issue Name, Status, Asset Name, Asset Type, Issue Description, Issue Remediation (specific fix guidance), References (documentation links), and detailed Asset Information. |
| 4.7 | What statuses can an issue have? | Currently (Phase 1), only Open status. Ignored, Accepted Risk, and False Positive statuses will be added in Phase 2. |
| 4.8 | How do I view the latest data in the Issue List? | Click the Sync button — the system reloads the most recent scan data, preserving current filters/search and resetting to page 1. Note: Sync only displays results from the most recent scan; it does not trigger a new scan. |
| 4.9 | Issue List or search returns no results — what does this mean? | The system shows "No records found" for both cases: no issues have been scanned yet, or no issues match the current search/filter criteria. If there is no scan data, wait for the automatic scan cycle (10 minutes); if a filter is active, review and try clearing it. |
| 4.10 | Which asset types are supported? | Instance, Subnet, Security Group, Storage Disk, User, User Group, IAM Role, Load Balancer, Database, Object Storage. |
| 4.11 | Is it normal for VPC to show "N/A" for some assets? | Yes — asset types User, User Group, IAM Role are not associated with a VPC so displaying "N/A" is correct system behavior. |
5. Asset Inventory
| # | Question | Answer |
|---|---|---|
| 5.1 | What is Asset Inventory? | A screen that shows a list of all cloud resources automatically discovered and updated by periodic scans. |
| 5.2 | What does the Asset List show? | Asset Name, Type, VPC, Public Exposure (Yes/No), and Last Scan At (most recent scan time). |
| 5.3 | How do I view issues for a specific asset? | On the Asset Inventory screen, click the asset name — the system displays the list of issues on that asset. |
| 5.4 | What filter options are available in the Asset List? | Filter by VPC, Asset Type, Public Exposure. Search by asset name. |
| 5.5 | Why doesn't an asset appear in the list? | New assets need at least one automatic scan cycle (10 minutes) before they appear. After scanning is complete, click Sync to load the updated list. |
| 5.6 | Does "Public Exposure: Yes" mean the asset is under attack? | Not necessarily. "Yes" means the resource is exposed to the internet — review to confirm whether this is intentional and check related issues. |
6. Common errors
| # | Symptom | Common cause | Resolution |
|---|---|---|---|
| 6.1 | "SERVICE IS NOT ACTIVATED" screen | Service not activated for this Tenant | Tenant Admin clicks "Activate Service" |
| 6.2 | "No records found" on Issue List / Asset List | No scan completed yet, or search/filter criteria do not match | Wait for the automatic scan cycle (10 minutes); after scanning is done, click Sync. If a filter is active, review and try clearing it |
| 6.3 | VPC shows "N/A" | Asset type has no associated VPC (User, IAM Role, etc.) | Correct system behavior, not an error |
| 6.4 | Cannot access the system (permission error) | Account is not Tenant Admin | Sign in with a Tenant Admin account |
| 6.5 | System shows "System is busy" error | System temporarily overloaded | Retry after a few minutes; if it persists, escalate to L2 |
| 6.6 | Dashboard does not update after changes | Scan has not re-run, or Sync has not been clicked | Wait for the next scan cycle (10 minutes); then click Sync or reload the page to load the latest data |