ExamGecko
Question list
Search
Search

Related questions











Question 40 - NSE7_OTS-7.2 discussion

Report
Export

Refer to the exhibit.

An operational technology rule is created and successfully activated to monitor the Modbus protocol on FortiSIEM. However, the rule does not trigger incidents despite Modbus traffic and application logs being received correctly by FortiSIEM.

Which statement correctly describes the issue on the rule configuration?

A.
The first condition on the SubPattern filter must use the OR logical operator.
Answers
A.
The first condition on the SubPattern filter must use the OR logical operator.
B.
The attributes in the Group By section must match the ones in Fitters section.
Answers
B.
The attributes in the Group By section must match the ones in Fitters section.
C.
The Aggregate attribute COUNT expression is incompatible with the filters.
Answers
C.
The Aggregate attribute COUNT expression is incompatible with the filters.
D.
The SubPattern is missing the filter to match the Modbus protocol.
Answers
D.
The SubPattern is missing the filter to match the Modbus protocol.
Suggested answer: B
asked 18/09/2024
Yasser Mohamed Mohamed
45 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first