Which security fabric component sends a notification io quarantine an endpoint after IOC detection "n the automation process?

Which security fabric component sends a notification io quarantine an endpoint after IOC detection "n the automation process?
A . FortiAnalyzer
B . FortiGate
C . FortiClient EMS
D . FortiClient

Answer: C

Explanation:

Understanding the Automation Process:

In the Security Fabric, automation processes can include actions such as quarantining an endpoint after an IOC (Indicator of Compromise) detection.

Evaluating Responsibilities:

FortiClient EMS plays a crucial role in endpoint management and can send notifications to quarantine endpoints.

Conclusion:

The correct security fabric component that sends a notification to quarantine an endpoint after IOC

detection is FortiClient EMS.

Reference: FortiClient EMS and automation process documentation from the study guides.

Subscribe
Notify of
guest
0 Comments
Inline Feedbacks
View all comments