ExamGecko
Question list
Search
Search

Question 45 - NSE5_FSM-6.3 discussion

Report
Export

What are the four possible incident status values?

A.
Active, dosed, cleared, open
Answers
A.
Active, dosed, cleared, open
B.
Active, cleared, cleared manually, system cleared
Answers
B.
Active, cleared, cleared manually, system cleared
C.
Active, closed, manual, resolved
Answers
C.
Active, closed, manual, resolved
D.
Active, auto cleared, manual, false positive
Answers
D.
Active, auto cleared, manual, false positive
Suggested answer: A

Explanation:

Incident Status Values: Incident statuses in FortiSIEM help administrators track and manage the lifecycle of incidents from detection to resolution.

Four Possible Status Values:

Active: Indicates that the incident is currently ongoing and needs attention.

Closed: Indicates that the incident has been resolved or addressed.

Cleared: Indicates that the incident has been resolved automatically based on predefined conditions.

Open: Indicates that the incident is acknowledged and under investigation but not yet resolved.

Usage: These statuses help in prioritizing and tracking incidents effectively, ensuring that all incidents are appropriately managed.

Reference: FortiSIEM 6.3 User Guide, Incident Management section, which details the different status values and their meanings.

asked 18/09/2024
Jose Castillo
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first