nerdexam
Fortinet

NSE7_OTS-7.2 · Question #39

Refer to the exhibit. An operational technology rule is created and successfully activated to monitor the Modbus protocol on FortiSIEM. However, the rule does not trigger incidents despite Modbus…

The correct answer is D. The SubPattern is missing the filter to match the Modbus protocol. The subpattern only filters on TCP/UDP ports (group "OT Ports"); it never specifies Modbus. Without a protocol (or specific Modbus port) filter, FortiSIEM won't match Modbus events, so no incidents are triggered.

FortiAnalyzer for OT

Question

Refer to the exhibit. An operational technology rule is created and successfully activated to monitor the Modbus protocol on FortiSIEM. However, the rule does not trigger incidents despite Modbus traffic and application logs being received correctly by FortiSIEM. Which statement correctly describes the issue on the rule configuration?

Exhibit

NSE7_OTS-7.2 question #39 exhibit

Options

  • AThe first condition on the SubPattern filter must use the OR logical operator.
  • BThe attributes in the Group By section must match the ones in Fitters section.
  • CThe Aggregate attribute COUNT expression is incompatible with the filters.
  • DThe SubPattern is missing the filter to match the Modbus protocol.

How the community answered

(34 responses)
  • A
    3% (1)
  • B
    6% (2)
  • C
    12% (4)
  • D
    79% (27)

Explanation

The subpattern only filters on TCP/UDP ports (group "OT Ports"); it never specifies Modbus. Without a protocol (or specific Modbus port) filter, FortiSIEM won't match Modbus events, so no incidents are triggered.

Topics

#FortiSIEM#Modbus rule#SubPattern filter#OT rule configuration

Community Discussion

No community discussion yet for this question.

Full NSE7_OTS-7.2 Practice