ExamGecko
Question list
Search
Search

Question 34 - NSE5_FSM-6.3 discussion

Report
Export

What does the Frequency field determine on a rule?

A.
How often the rule will evaluate the subpattern.
Answers
A.
How often the rule will evaluate the subpattern.
B.
How often the rule will trigger for the same condition.
Answers
B.
How often the rule will trigger for the same condition.
C.
How often the rule will trigger.
Answers
C.
How often the rule will trigger.
D.
How often the rule will take a clear action.
Answers
D.
How often the rule will take a clear action.
Suggested answer: B

Explanation:

Rule Evaluation in FortiSIEM: Rules in FortiSIEM are evaluated periodically to check if the defined conditions or subpatterns are met.

Frequency Field: The Frequency field in a rule determines the interval at which the rule's subpattern will be evaluated.

Evaluation Interval: This defines how often the system will check the incoming events against the rule's subpattern to determine if an incident should be triggered.

Impact on Performance: Setting an appropriate frequency is crucial to balance between timely detection of incidents and system performance.

Examples:

If the Frequency is set to 5 minutes, the rule will evaluate the subpattern every 5 minutes.

This means that every 5 minutes, the system will check if the conditions defined in the subpattern are met by the incoming events.

Reference: FortiSIEM 6.3 User Guide, Rules and Incidents section, which explains the Frequency field and how it impacts the evaluation of subpatterns in rules.

asked 18/09/2024
Franziska Kreuz
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first