ExamGecko
Question list
Search
Search

Question 9 - NSE6_FSR-7.3 discussion

Report
Export

Refer to the exhibit.

Which two statements about the recommendation engine are true? (Choose two.)

A.

There are no playbooks that can be run on the recommended alerts using the recommendation panel

Answers
A.

There are no playbooks that can be run on the recommended alerts using the recommendation panel

B.

The dataset is trained to predict the Severity and Type fields.

Answers
B.

The dataset is trained to predict the Severity and Type fields.

C.

The recommendation engine is set to automatically accept suggestions.

Answers
C.

The recommendation engine is set to automatically accept suggestions.

D.

The alert severity is High, but the recommendation is for it to be set to Medium

Answers
D.

The alert severity is High, but the recommendation is for it to be set to Medium

Suggested answer: B, D

Explanation:

The Recommendation Engine in FortiSOAR is designed to assist in alert triage by suggesting values for certain fields based on historical data and machine learning models. In this case, the engine is trained to predict both the Severity and Type fields, suggesting values that align with past incidents and threat intelligence. Although the current alert severity is High, the recommendation engine has suggested adjusting it to Medium based on the pattern of similar past alerts, indicating a less critical threat level than initially perceived. This functionality helps analysts by providing data-driven insights, which can optimize alert handling and resource allocation.

asked 12/10/2024
antonio de simone
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first