View all questions & answers for the NSE 6 - FortiEDR 7.0 Administrator Exam Materials exam
NSE 6 - FortiEDR 7.0 Administrator Exam Materials-Question 17 Discussion
Comments
Selected Answers: B
In FortiEDR, device isolation is classified as a Remediation action.
Remediation actions are designed to contain and neutralize threats, for example by isolating compromised devices from the network.
Other categories serve different purposes:
Investigation → collecting evidence
Notifications → generating alerts
Custom → executing user-defined actions
Selected Answers: B
You are asked to create a playbook to isolate a device with a collector. Which action category does isolating a device with a collector fall under? (Choose one answer)
Brave-Dump Clients Votes