Skip to main content

FAQ

Answers to common questions about FPT Security Hub (CSPM) for L1 Support.

1. Product overview

#QuestionAnswer
1.1What is FPT Security Hub (CSPM)?FPT Security Hub is a Cloud Security Posture Management (CSPM) service that automatically detects misconfigurations and security risks in cloud infrastructure. It provides an overview dashboard, a prioritized list of issues by severity, and centralized management of all cloud resources in one place.
1.2What resource types does FPT Security Hub scan?Supported asset types: Instance, Subnet, Security Group, Storage Disk, User, User Group, IAM Role, Load Balancer, Database, Object Storage.
1.3How often is scan data updated?The system automatically performs incremental scans every 10 minutes — scanning only new assets or assets with configuration changes, not a full scan every time.
1.4How are issue severity levels classified?Issues are classified into four levels: Critical, High, Medium, Low. Prioritize resolution from Critical downward.
1.5Who has access to FPT Security Hub?Tenant Admin only. Other users see: "You do not have sufficient permissions to view this page!"

2. Service activation

#QuestionAnswer
2.1Is the CSPM service enabled by default?No. The service is not enabled automatically — the Tenant Admin must activate it manually the first time by clicking "Activate Service" on the interface.
2.2A customer sees "SERVICE IS NOT ACTIVATED" — what should I do?The service has not been activated for this Tenant. Guide the Tenant Admin to click "Activate Service" on that screen. After activation, the system moves to the Dashboard immediately — however, wait a moment for the first scan results to appear.
2.3Can the Service Activation screen reappear after activation?Yes. If the Tenant Admin deactivates the service, the Service Activation screen will reappear when accessing the system.
2.4Activation done but no data yet — how to handle?This is normal behavior. After activation, the system shows the Dashboard immediately but needs to wait for the automatic scan cycle (10 minutes) before the first results are available. Once scanning is complete, click Sync to load the latest data.
2.5Why does clicking "Activate Service" get no response?The system may be busy — retry after a few minutes. If it still fails, escalate to L2 to investigate the activation API.

3. Dashboard

#QuestionAnswer
3.1What information does the Dashboard show?The Dashboard provides an overview including: Security Risk Score, Total Assets, Publicly Exposed Assets, Open Findings (by severity), Top Risky Assets, and Security Findings Trend (trend chart over time).
3.2What is the Security Risk Score? What score is considered dangerous?An overall security risk rating on a scale of 1–10. Lower score = lower risk (for example, 1.5/10 = low); high score (for example, 9/10) = high risk, requires immediate attention.
3.3What are Publicly Exposed Assets?Cloud resources that are exposed to the public internet. This group requires priority review because it is vulnerable to external attacks.
3.4What are Top Risky Assets?A list of resources with the most security issues. Click the 👁 icon on the Dashboard to view the list of issues on each asset.
3.5The Dashboard shows no data — what is the cause?A scan cycle may not have completed yet. Wait for the automatic scan (10 minutes); after scanning is done, click Sync to load the latest results.

4. Issue management

#QuestionAnswer
4.1What is Issue Management used for?A centralized screen showing all security issues detected by CSPM scans. Tenant Admins can search, filter by asset type or compliance control, view issue details, and find remediation guidance.
4.2What columns does the Issue List show?Severity (+ Score), Issue (name + description), Asset (name + type), VPC, Status, First Detected, Reference (related Control ID).
4.3What is the default sort order for issues?Default sort is Score descending — most critical issues appear at the top.
4.4What can I search issues by?Search by issue name, description, asset name, VPC (case-insensitive).
4.5What does the filter support?Filter by Asset Type (Instance, Subnet, Security Group, etc.) and by Reference (Control ID from a compliance framework).
4.6What does Issue Detail show?Severity, Issue Name, Status, Asset Name, Asset Type, Issue Description, Issue Remediation (specific fix guidance), References (documentation links), and detailed Asset Information.
4.7What statuses can an issue have?Currently (Phase 1), only Open status. Ignored, Accepted Risk, and False Positive statuses will be added in Phase 2.
4.8How do I view the latest data in the Issue List?Click the Sync button — the system reloads the most recent scan data, preserving current filters/search and resetting to page 1. Note: Sync only displays results from the most recent scan; it does not trigger a new scan.
4.9Issue List or search returns no results — what does this mean?The system shows "No records found" for both cases: no issues have been scanned yet, or no issues match the current search/filter criteria. If there is no scan data, wait for the automatic scan cycle (10 minutes); if a filter is active, review and try clearing it.
4.10Which asset types are supported?Instance, Subnet, Security Group, Storage Disk, User, User Group, IAM Role, Load Balancer, Database, Object Storage.
4.11Is it normal for VPC to show "N/A" for some assets?Yes — asset types User, User Group, IAM Role are not associated with a VPC so displaying "N/A" is correct system behavior.

5. Asset Inventory

#QuestionAnswer
5.1What is Asset Inventory?A screen that shows a list of all cloud resources automatically discovered and updated by periodic scans.
5.2What does the Asset List show?Asset Name, Type, VPC, Public Exposure (Yes/No), and Last Scan At (most recent scan time).
5.3How do I view issues for a specific asset?On the Asset Inventory screen, click the asset name — the system displays the list of issues on that asset.
5.4What filter options are available in the Asset List?Filter by VPC, Asset Type, Public Exposure. Search by asset name.
5.5Why doesn't an asset appear in the list?New assets need at least one automatic scan cycle (10 minutes) before they appear. After scanning is complete, click Sync to load the updated list.
5.6Does "Public Exposure: Yes" mean the asset is under attack?Not necessarily. "Yes" means the resource is exposed to the internet — review to confirm whether this is intentional and check related issues.

6. Common errors

#SymptomCommon causeResolution
6.1"SERVICE IS NOT ACTIVATED" screenService not activated for this TenantTenant Admin clicks "Activate Service"
6.2"No records found" on Issue List / Asset ListNo scan completed yet, or search/filter criteria do not matchWait for the automatic scan cycle (10 minutes); after scanning is done, click Sync. If a filter is active, review and try clearing it
6.3VPC shows "N/A"Asset type has no associated VPC (User, IAM Role, etc.)Correct system behavior, not an error
6.4Cannot access the system (permission error)Account is not Tenant AdminSign in with a Tenant Admin account
6.5System shows "System is busy" errorSystem temporarily overloadedRetry after a few minutes; if it persists, escalate to L2
6.6Dashboard does not update after changesScan has not re-run, or Sync has not been clickedWait for the next scan cycle (10 minutes); then click Sync or reload the page to load the latest data