ExamGecko
Question list
Search
Search

Question 3 - NSE7_ZTA-7.2 discussion

Report
Export

Which statement is true regarding a FortiClient quarantine using FortiAnalyzer playbooks?

A.
FortiGate sends a notification to FortiClient EMS to quarantine the endpoint
Answers
A.
FortiGate sends a notification to FortiClient EMS to quarantine the endpoint
B.
FortiAnalyzer discovers malicious activity in the logs and notifies FortiGate
Answers
B.
FortiAnalyzer discovers malicious activity in the logs and notifies FortiGate
C.
FortiAnalyzer sends an API to FortiClient EMS to quarantine the endpoint
Answers
C.
FortiAnalyzer sends an API to FortiClient EMS to quarantine the endpoint
D.
FortiClient sends logs to FortiAnalyzer
Answers
D.
FortiClient sends logs to FortiAnalyzer
Suggested answer: C

Explanation:

FortiAnalyzer playbooks are automated workflows that can perform actions based on triggers, conditions, and outputs. One of the actions that a playbook can perform is to quarantine a device by sending an API call to FortiClient EMS, which then instructs the FortiClient agent on the device to disconnect from the network. This can help isolate and contain a compromised or non-compliant device from spreading malware or violating policies.Reference:=

Quarantine a device from FortiAnalyzer playbooks

Playbooks

asked 18/09/2024
ADAMA DAO
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first