Refer to the exhibit.
Based on the Security Fabric automation settings, what action will be taken on compromised endpoints?
Based on the Security Fabric automation settings shown in the exhibit:
The automation stitch is configured with a trigger for a 'Compromised Host.'
The action specified for this trigger is 'Quarantine FortiClient via EMS.'
This indicates that when an endpoint is detected as compromised, FortiClient EMS will quarantine the endpoint as part of the automation process.
Therefore, the action taken on compromised endpoints will be to quarantine them through EMS.
Reference
FortiGate Security 7.2 Study Guide, Automation Stitches and Actions Section
Fortinet Documentation on Configuring Automation Stitches and Quarantine Actions
Whitney
10 months agoEssie
10 months agoVelda
9 months agoGraciela
9 months agoMarkus
10 months agoHollis
9 months agoDyan
9 months agoMaybelle
9 months agoMozell
10 months agoLynette
10 months agoCassandra
10 months agoXochitl
10 months agoRosamond
10 months agoDalene
10 months agoSylvia
11 months agoTeresita
10 months agoAleisha
10 months agoWillard
10 months agoAleisha
10 months agoTegan
10 months agoLynda
10 months agoMabel
10 months agoFrederick
10 months agoMireya
10 months ago