The FortiEDR core classified an event as inconclusive, but a few seconds later FCS revised the classification to malicious. What playbook actions are applied to the event?
A.
Playbook actions applied to suspicious events
B.
Playbook actions applied to inconclusive events
Study guide p.96
"FCS controls playbook actions, if FCS is not available, no action will be taken"
D is the correct answer.
Core can only block, allow, or log
B. Playbook actions applied to inconclusive events
Pag7 on study guide
upvoted 1 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Latrel
1 month, 4 weeks agothinasci01
3 months, 3 weeks agosoporte127
6 months agoipfpjmpyoofpjuryee
8 months, 1 week agoebenav11
8 months, 2 weeks ago