Refer to the exhibit.
Based on the Security Fabric automation settings, what action will be taken on compromised endpoints?
Based on the Security Fabric automation settings shown in the exhibit:
The automation stitch is configured with a trigger for a 'Compromised Host.'
The action specified for this trigger is 'Quarantine FortiClient via EMS.'
This indicates that when an endpoint is detected as compromised, FortiClient EMS will quarantine the endpoint as part of the automation process.
Therefore, the action taken on compromised endpoints will be to quarantine them through EMS.
Reference
FortiGate Security 7.2 Study Guide, Automation Stitches and Actions Section
Fortinet Documentation on Configuring Automation Stitches and Quarantine Actions
Whitney
5 months agoEssie
5 months agoVelda
4 months agoGraciela
4 months agoMarkus
5 months agoHollis
4 months agoDyan
4 months agoMaybelle
4 months agoMozell
4 months agoLynette
5 months agoCassandra
5 months agoXochitl
5 months agoRosamond
5 months agoDalene
5 months agoSylvia
5 months agoTeresita
5 months agoAleisha
5 months agoWillard
5 months agoAleisha
5 months agoTegan
5 months agoLynda
5 months agoMabel
5 months agoFrederick
5 months agoMireya
5 months ago