The FortiEDR core classified an event as inconclusive, but a few seconds later FCS revised the classification to malicious. What playbook actions are applied to the event?
A.
Playbook actions applied to suspicious events
B.
Playbook actions applied to inconclusive events
Study guide p.96
"FCS controls playbook actions, if FCS is not available, no action will be taken"
D is the correct answer.
Core can only block, allow, or log
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Latrel
6 months, 3 weeks agothinasci01
8 months, 3 weeks agosoporte127
10 months, 4 weeks agoipfpjmpyoofpjuryee
1 year, 1 month agoebenav11
1 year, 1 month ago