NSE7_OTS-7.2 · Question #39
Refer to the exhibit. An operational technology rule is created and successfully activated to monitor the Modbus protocol on FortiSIEM. However, the rule does not trigger incidents despite Modbus…
The correct answer is D. The SubPattern is missing the filter to match the Modbus protocol. The subpattern only filters on TCP/UDP ports (group "OT Ports"); it never specifies Modbus. Without a protocol (or specific Modbus port) filter, FortiSIEM won't match Modbus events, so no incidents are triggered.
Question
Refer to the exhibit. An operational technology rule is created and successfully activated to monitor the Modbus protocol on FortiSIEM. However, the rule does not trigger incidents despite Modbus traffic and application logs being received correctly by FortiSIEM. Which statement correctly describes the issue on the rule configuration?
Exhibit
Options
- AThe first condition on the SubPattern filter must use the OR logical operator.
- BThe attributes in the Group By section must match the ones in Fitters section.
- CThe Aggregate attribute COUNT expression is incompatible with the filters.
- DThe SubPattern is missing the filter to match the Modbus protocol.
How the community answered
(34 responses)- A3% (1)
- B6% (2)
- C12% (4)
- D79% (27)
Explanation
The subpattern only filters on TCP/UDP ports (group "OT Ports"); it never specifies Modbus. Without a protocol (or specific Modbus port) filter, FortiSIEM won't match Modbus events, so no incidents are triggered.
Topics
Community Discussion
No community discussion yet for this question.
