nerdexam
Fortinet

FCP_FCT_AD-7.2 · Question #27

Refer to the exhibit. Based on the Security Fabric automation settings, what action will be taken on compromised endpoints?

The correct answer is A. The administrator must enable remote HTTPS access to EMS. Based on the FortiGate Security Fabric settings shown in the exhibits, to successfully quarantine an endpoint when it is detected as a compromised host (IoC), the following step is required: Enable Remote HTTPS Access to EMS: This setting allows FortiGate to communicate…

Alerting and Incident Response

Question

Refer to the exhibit. Based on the Security Fabric automation settings, what action will be taken on compromised endpoints?

Options

  • AThe administrator must enable remote HTTPS access to EMS.
  • BThe administrator must enable FQDN on EMS.
  • CThe administrator must authorize FortiGate on FortiAnalyzer.
  • DThe administrator must enable SSH access to EMS.

How the community answered

(24 responses)
  • A
    79% (19)
  • B
    13% (3)
  • C
    4% (1)
  • D
    4% (1)

Explanation

Based on the FortiGate Security Fabric settings shown in the exhibits, to successfully quarantine an endpoint when it is detected as a compromised host (IoC), the following step is required: Enable Remote HTTPS Access to EMS: This setting allows FortiGate to communicate securely with FortiClient EMS over HTTPS. Remote HTTPS access is essential for the quarantine functionality to operate correctly, enabling the EMS server to receive and act upon the quarantine commands from FortiGate. Therefore, the administrator must enable remote HTTPS access to EMS to allow the quarantine process to function properly. (Note: This question's choices, answer, and explanation appear to be a duplicate of Question 27 in the source document.)

Topics

#Security Fabric automation#endpoint quarantine#compromised host#IoC response

Community Discussion

No community discussion yet for this question.

Full FCP_FCT_AD-7.2 Practice