QuestionQ9
Zero-trust LAN accessRefer to the exhibits.





Review the FortiGate configuration, FortiAnalyzer logs, and FortiGate widget displayed in the exhibits.
Security Fabric quarantine automation is configured to automatically isolate compromised devices. FortiAnalyzer has been added to the Security Fabric, and an automation stitch has been set up to quarantine compromised devices.
To test this configuration, a device with IP address 10.0.2.1, connected through a managed FortiSwitch, attempts to reach a malicious website. FortiAnalyzer logs verify that the event was recorded, but the device is absent from the FortiGate quarantine widget.
Which two reasons could account for FortiGate not quarantining the device?
Choose two
- A The threat detection services license is missing or invalid under FortiAnalyzer.
- B The SSL inspection should be set to deep-Inspection.
- C The malicious website is not recognized as an indicator of compromise (IOC) by FortiAnalyzer.
- D The IOC action should include only the FortiSwitch in the quarantine.
Community Discussion