Page 129 of study guide
1.FortiClient sends logs to FortiAnalyzer.
2.FortiAnalyzer discovers IOCs in the logs and notifies FortiGate.
3.FortiGate identifies if FortiClient is a connected endpoint, and if it has FortiClient EMS as a Fabric Connector that FortiClient is connected to. With this information, FortiGate sends a notification to FortiClient EMS to quarantine the endpoint.
4.FortiClient EMS searches for the endpoint and sends a quarantine message to it.
5.The endpoint receives the quarantine message and quarantines itself, blocking all network traffic. The endpoint notifies FortiGate and EMS of the status change.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
powermaster_777
2 days, 17 hours agoTIGERZ44
3 months agovinceandroyd
4 months, 3 weeks ago