Refer to the exhibit.

If a rule containing the automation policy shown in the exhibit triggers, what will happen?
The automation policy is configured to run a remediation script named 'Fortinet FortiOS - Block Source IP FortiOS via API'. It specifies enforcement on two FortiGate devices: FortiGate508 and FortiGate90D. Therefore, associated source IP addresses will be blocked on those two FortiGate firewalls only.
The correct answer is D because the remediation configuration defines specific enforcement targets. The FortiSIEM Study Guide explains that automation policies can run remediation scripts automatically when an incident occurs. It also explains the remediation options: Enforce On determines which devices the script runs against, while Run On identifies whether the script is launched from the supervisor or a collector. The Study Guide further states that mitigation scripts can block an IP address in a firewall or disable a user in Active Directory, and recommends specifying the Enforce On value because it controls the target device used by the remediation script. In the exhibit, the selected script is a Fortinet FortiOS block-source-IP remediation script, and the Enforce On field lists two FortiGate devices. That means the block action is targeted only at those two named FortiGate firewalls. The Aviation organization limits the automation policy context, but it does not mean every device in the organization receives the block. It is also not all FortiGate firewalls or the whole Network CMDB group.
Currently there are no comments in this discussion, be the first to comment!