nerdexam
Fortinet

NSE5_FSM-6.3 · Question #38

In the rules engine, which condition instructs FortiSIEM to summarize and count the matching evaluated data?

The correct answer is B. Aggregation. Rules Engine in FortiSIEM: The rules engine evaluates incoming events based on defined conditions to detect incidents and anomalies. Aggregation Condition: The aggregation condition instructs FortiSIEM to summarize and count the matching evaluated data. Function: Aggregation is…

Incident management

Question

In the rules engine, which condition instructs FortiSIEM to summarize and count the matching evaluated data?

Options

  • ATime Window
  • BAggregation
  • CGroup By
  • DFilters

How the community answered

(24 responses)
  • A
    17% (4)
  • B
    71% (17)
  • C
    8% (2)
  • D
    4% (1)

Explanation

Rules Engine in FortiSIEM: The rules engine evaluates incoming events based on defined conditions to detect incidents and anomalies. Aggregation Condition: The aggregation condition instructs FortiSIEM to summarize and count the matching evaluated data. Function: Aggregation is used to group events based on specified criteria and then perform operations such as counting the number of occurrences within a defined time window. Purpose: This allows for the detection of patterns and anomalies, such as a high number of failed login attempts within a short period.

Topics

#rules engine#aggregation#event correlation#rule conditions

Community Discussion

No community discussion yet for this question.

Full NSE5_FSM-6.3 Practice