FCP_FAZ_AN-7.4 · Question #54
Refer to the exhibits. Assume these are all the events that exist on the FortiAnalyzer device. How many events will be added to the incident created after running this playbook?
The correct answer is D. Four events will be added. The playbook's Get Events task is configured with a filter using "Match Any Condition" for Severity = High, Event Type = Web Filter, or Tag = Malware. From the Event Monitor: Events with Severity High: 2 (IPS) Events with Event Type Web Filter: 2 (both Medium severity) Events…
Question
Refer to the exhibits. Assume these are all the events that exist on the FortiAnalyzer device. How many events will be added to the incident created after running this playbook?
Exhibit
Options
- AEleven events will be added.
- BSeven events will be added
- CNo events will be added.
- DFour events will be added.
How the community answered
(30 responses)- A3% (1)
- B13% (4)
- C3% (1)
- D80% (24)
Explanation
The playbook's Get Events task is configured with a filter using "Match Any Condition" for Severity = High, Event Type = Web Filter, or Tag = Malware. From the Event Monitor: Events with Severity High: 2 (IPS) Events with Event Type Web Filter: 2 (both Medium severity) Events tagged Malware: 3 (all Medium severity Antivirus events) The total distinct events matching any of these criteria are four: the two IPS High severity events, the two Web Filter events, and the three Malware-tagged Antivirus events overlap with the Web Filter events or are separate; counting distinct events from the table gives 4 matching events added to the incident.
Topics
Community Discussion
No community discussion yet for this question.
