nerdexam
Fortinet

FCSS_ADA_AR-6.7 · Question #40

Refer to the exhibit. The rule evaluates multiple VPN logon failures within a ten-minute window. Consider the following VPN failure events received within a ten-minute window: How many incidents are…

The correct answer is B. 2. The rule triggers an incident when there are two or more VPN logon failures within a 10-minute window, grouped by Source IP, Reporting Device, Reporting IP, and User. Let's analyze the Breakdown of Events: 1. Reporting IP: 1.1.1.1, Source IP: 2.2.2.2, Device: FortiGate, User…

Advanced FortiSIEM Analytics

Question

Refer to the exhibit. The rule evaluates multiple VPN logon failures within a ten-minute window. Consider the following VPN failure events received within a ten-minute window:

How many incidents are generated?

Exhibits

FCSS_ADA_AR-6.7 question #40 exhibit 1
FCSS_ADA_AR-6.7 question #40 exhibit 2

Options

  • A1
  • B2
  • C0
  • D3

How the community answered

(49 responses)
  • A
    6% (3)
  • B
    55% (27)
  • C
    27% (13)
  • D
    12% (6)

Explanation

The rule triggers an incident when there are two or more VPN logon failures within a 10-minute window, grouped by Source IP, Reporting Device, Reporting IP, and User. Let's analyze the Breakdown of Events: 1. Reporting IP: 1.1.1.1, Source IP: 2.2.2.2, Device: FortiGate, User: Sarah 2. Reporting IP: 1.1.1.1, Source IP: 2.2.2.2, Device: FortiGate, User: John 3. Reporting IP: 1.1.1.3, Source IP: 2.2.2.2, Device: FortiGate2, User: Tom 4. Reporting IP: 1.1.1.3, Source IP: 2.2.2.2, Device: FortiGate2, User: John 5. Reporting IP: 1.1.1.3, Source IP: 2.2.2.2, Device: FortiGate2, User: Sarah 6. Reporting IP: 1.1.1.1, Source IP: 2.2.2.2, Device: FortiGate, User: Tom Now, applying the grouping criteria (Source IP, Reporting Device, Reporting IP, and User): Group 1: (1.1.1.1, 2.2.2.2, FortiGate, John) 1 occurrence (not enough) Group 2: (1.1.1.1, 2.2.2.2, FortiGate, Sarah) 1 occurrence (not enough) Group 3: (1.1.1.1, 2.2.2.2, FortiGate, Tom) 2 occurrences (incident triggered) Group 4: (1.1.1.3, 2.2.2.2, FortiGate2, John) 2 occurrences (incident triggered) Group 5: (1.1.1.3, 2.2.2.2, FortiGate2, Sarah) 1 occurrence (not enough) Group 6: (1.1.1.3, 2.2.2.2, FortiGate2, Tom) 1 occurrence (not enough) Final Incident Count: One incident for Group 3 (Tom on FortiGate) One incident for Group 4 (John on FortiGate2)

Topics

#incident generation#VPN logon failures#correlation rules#time window

Community Discussion

No community discussion yet for this question.

Full FCSS_ADA_AR-6.7 Practice