View all questions & answers for the NSE 6 - FortiEDR 7.0 Administrator Exam Materials exam
NSE 6 - FortiEDR 7.0 Administrator Exam Materials-Question 6 Discussion
Comments
Selected Answers: A, C
The exhibit shows that the device R2D2-kvm63 was moved from the “Training” group to the “High Security Collector Group” in FortiEDR.
This movement represents an isolation action triggered by a playbook.
The triggered rule “Training-eXtended Detection” confirms that a playbook was executed.
Moving the device to a High Security group is a form of isolation, not an event blocking action.
Selected Answers: A, C
• It is not a simulation policy because simulation policy does not do any type of action they notify only
• No blocking happened in history the device has been moved toa different group and the extended Detction policies do not perform any blocking actions since it does not engage directly with collector
• By elimination the only response left is that the device has been oved to isolation but there is not clear indication of it. (VERIFY THIS ANSWER)
Refer to the Exhibit: Based on the event shown in the exhibit, which two statements about the event are true? (Choose two answers)
Brave-Dump Clients Votes