FCP - FortiSIEM 7.2 Analyst Questions and Answers
Refer to the exhibit.
What is the Group: FortiSIEM Analysts value referring to?
Which items are used to define a subpattern?
Refer to the exhibit.
If you group the events by User and Count attributes, how many results will FortiSIEM display?
What are two required components of a rule? (Choose two.)
Refer to the exhibit.
If you group the events by User, Source IP, and Count attributes, how many results will FortiSIEM display?
What can you use to send data to FortiSIEM for user and entity behavior analytics (UEBA)?
Refer to the exhibit.
Which value would you expect the FortiSIEM parser to use to populate the Application Name field?
Refer to the exhibit.
As shown in the exhibit, why are some of the fields highlighted in red?
Refer to the exhibit.
An analyst wants the rule shown in the exhibit to trigger when three failed login attempts occur within three minutes.
What should the values be for the condition time window and aggregate count?