An administrator wants to configure FortiGate to automatically block a source IP when a high-severity IPS event is detected. Which TWO components must be configured? (Choose two.)
The IPS Event trigger is what detects the high-severity signature hit and fires the stitch; without it, no automation runs. It supplies the event context, including the offending source IP, that the paired action needs to block traffic automatically.
Why this answer
Option C is correct because an automation stitch must have a trigger that fires on the relevant log event, and setting the trigger to 'IPS Event' (specifically matching high-severity IPS logs) is what initiates the automated response when the IPS sensor detects the threat. Option E is correct because the stitch also needs an action that performs the blocking; the 'Quarantine' action adds the offending source IP to the quarantine list so FortiGate drops subsequent traffic from it. Together, the IPS Event trigger and the Quarantine action form the automation stitch that automatically blocks the source IP.
Option A is not required by the question because, while IPS must be enabled somewhere for events to occur, the question asks specifically about the automation components needed to block the source, not the base policy configuration. Option B is incorrect because FortiGuard category subscription relates to web filtering/security rating services, not to triggering IPS-based quarantine. Option D is incorrect because a static route to the source IP is unrelated to dynamically blocking a detected attacker.