Refer to the exhibit.
Based on the Security Fabric automation settings, what action will be taken on compromised endpoints?
Based on the Security Fabric automation settings shown in the exhibit:
The automation stitch is configured with a trigger for a 'Compromised Host.'
The action specified for this trigger is 'Quarantine FortiClient via EMS.'
This indicates that when an endpoint is detected as compromised, FortiClient EMS will quarantine the endpoint as part of the automation process.
Therefore, the action taken on compromised endpoints will be to quarantine them through EMS.
Reference
FortiGate Security 7.2 Study Guide, Automation Stitches and Actions Section
Fortinet Documentation on Configuring Automation Stitches and Quarantine Actions
Whitney
10 months agoEssie
10 months agoVelda
10 months agoGraciela
10 months agoMarkus
11 months agoHollis
10 months agoDyan
10 months agoMaybelle
10 months agoMozell
10 months agoLynette
10 months agoCassandra
10 months agoXochitl
11 months agoRosamond
11 months agoDalene
11 months agoSylvia
11 months agoTeresita
10 months agoAleisha
10 months agoWillard
10 months agoAleisha
11 months agoTegan
11 months agoLynda
11 months agoMabel
11 months agoFrederick
11 months agoMireya
11 months ago