ExamGecko
Question list
Search
Search

Question 31 - NSE5_FSM-6.3 discussion

Report
Export

Refer to the exhibit.

The FortiSIEM administrator is examining events for two devices to investigate an issue. However, the administrator is not getting any results from their search.

Based on the selected filters shown in the exhibit, why is the search returning no results?

A.
Parenthesis are missing.
Answers
A.
Parenthesis are missing.
B.
The wrong boolean operator is selected in the Next column.
Answers
B.
The wrong boolean operator is selected in the Next column.
C.
The wrong option is selected in the Operator column.
Answers
C.
The wrong option is selected in the Operator column.
D.
An invalid IP subnet is typed in the Value column.
Answers
D.
An invalid IP subnet is typed in the Value column.
Suggested answer: B

Explanation:

Search Filters in FortiSIEM: When searching for events, the correct use of filters and logical operators is crucial to obtain accurate results.

Issue Analysis:

Selected Filters: The exhibit shows filters for two different Reporting IP addresses.

Logical Operators: The use of 'AND' between the two Reporting IP addresses implies that an event must match both IP addresses simultaneously, which is not possible for a single event.

Correct Usage: To search for events from either of the two IP addresses, parentheses should be used to group conditions logically.

Corrected Filter: (Reporting IP = 192.168.1.1 OR Reporting IP = 172.16.10.3) would return events from either IP address.

Reference: FortiSIEM 6.3 User Guide, Search and Filters section, which explains the use of logical operators and the importance of parentheses in constructing effective search queries.

asked 18/09/2024
Amardeep Kumar
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first