This alert indicates that the endpoint attempted to browse to a URL that is known to be exploitative. If no other alerts from the endpoint are present, it is unlikely that the endpoint is infected. If the Network Security Security appliance is in blocking mode, infection matches are blocked
It is possible that other channels are being used in such a way that they are undetectable or that the endpoint is compromised but using a different point on the network for its traffic. Check if anything suspicious happened around this time. If you have the Trellix IPS license and known exploit details are available, check if the vulnerable software versions are being used. Check local security logs and security information and event management (SIEM) logs. You can also use the Endpoint Security (HX) server for triage investigation.