List of questions
Related questions
Question 40 - NSE7_OTS-7.2 discussion
Refer to the exhibit.
An operational technology rule is created and successfully activated to monitor the Modbus protocol on FortiSIEM. However, the rule does not trigger incidents despite Modbus traffic and application logs being received correctly by FortiSIEM.
Which statement correctly describes the issue on the rule configuration?
A.
The first condition on the SubPattern filter must use the OR logical operator.
B.
The attributes in the Group By section must match the ones in Fitters section.
C.
The Aggregate attribute COUNT expression is incompatible with the filters.
D.
The SubPattern is missing the filter to match the Modbus protocol.
Your answer:
0 comments
Sorted by
Leave a comment first