View all questions & answers for the NSE 6 - FortiClient EMS 7.4 Administrator Exam Materials exam


Question 27 Discussion

The security team plans to leverage their existing Fortinet Security Fabric infrastructure to create an automated response capability to isolate compromised endpoints. Their environment consists of FortiClient EMS, FortiGate firewalls, and FortiAnalyzer. Which two configurations are required to quarantine endpoints based on indicator of compromise (IOC) verdicts from the security fabric deployment? (Choose two answers)

  • A. A FortiAnalyzer playbook configured to notify FortiGate about IOC incidents
  • B. An automation stitch configured on FortiGate for host quarantine
  • C. FortiClient configured to send traffic and security logs to FortiAnalyzer
  • D. The IOC feature enabled in the malware endpoint protection profile
Correct Answer: B,C

Brave-Dump Clients Votes

BC 100%

Comments



Anonymous99 2025-08-23 09:09:59

Selected Answers: B, C


Refer FCP - FortiClient EMS 7.4 Administrator Study_Guide pg 290