ExamGecko
Question list
Search
Search

Question 41 - NSE5_FSM-6.3 discussion

Report
Export

If an incident's status is Cleared, what does this mean?

A.
Two hours have passed since the incident occurred and the incident has not reoccurred.
Answers
A.
Two hours have passed since the incident occurred and the incident has not reoccurred.
B.
A clear condition set on a rule was satisfied.
Answers
B.
A clear condition set on a rule was satisfied.
C.
A security rule issue has been resolved.
Answers
C.
A security rule issue has been resolved.
D.
The incident was cleared by an operator.
Answers
D.
The incident was cleared by an operator.
Suggested answer: B

Explanation:

Incident Status in FortiSIEM: The status of an incident indicates its current state and helps administrators track and manage incidents effectively.

Cleared Status: When an incident's status is 'Cleared,' it means that a specific condition set to clear the incident has been satisfied.

Clear Condition: This is typically a predefined condition that indicates the issue causing the incident has been resolved or no longer exists.

Automatic vs. Manual Clearance: While some incidents may be cleared automatically based on clear conditions, others might be manually cleared by an operator.

Reference: FortiSIEM 6.3 User Guide, Incident Management section, detailing the various incident statuses and the conditions that lead to an incident being marked as 'Cleared.'

asked 18/09/2024
Padmanabhan Kudiarasu
48 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first