ExamGecko
Question list
Search
Search

Question 15 - NSE5_FSM-6.3 discussion

Report
Export

Refer to the exhibit.

Which section contains the sortings that determine how many incidents are created?

A.
Actions
Answers
A.
Actions
B.
Group By
Answers
B.
Group By
C.
Aggregate
Answers
C.
Aggregate
D.
Filters
Answers
D.
Filters
Suggested answer: C

Explanation:

Incident Creation in FortiSIEM: Incidents in FortiSIEM are created based on specific patterns and conditions defined within the system.

Group By Function: The 'Group By' section in the 'Edit SubPattern' window specifies how the data should be grouped for analysis and incident creation.

Impact of Grouping: The way data is grouped affects the number of incidents generated. Each unique combination of the grouped attributes results in a separate incident.

Exhibit Analysis: In the provided exhibit, the 'Group By' section lists 'Reporting Device,' 'Reporting IP,' and 'User.' This means incidents will be created for each unique combination of these attributes.

Reference: FortiSIEM 6.3 User Guide, Rule and Pattern Creation section, which details how grouping impacts incident generation.

asked 18/09/2024
Talal Elemam
51 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first