nerdexam
Fortinet

NSE7_OTS-7.2 · Question #81

Refer to the exhibit. You are creating a new operational technology (OT) rule to monitor Modbus protocol traffic on FortiSIEM. Which action must you take to ensure that all Modbus messages on the…

The correct answer is D. In the Aggregate section, set the attribute value to equal to or greater than 0. The current Aggregate condition is set to COUNT(Matched Events) >= 1, which only triggers the rule after at least one event. To ensure all Modbus messages (including the first one) match the rule, the condition must be >= 0, so every event is considered, including the very…

FortiAnalyzer for OT

Question

Refer to the exhibit. You are creating a new operational technology (OT) rule to monitor Modbus protocol traffic on FortiSIEM. Which action must you take to ensure that all Modbus messages on the network match the rule?

Exhibit

NSE7_OTS-7.2 question #81 exhibit

Options

  • AThe condition on the SubPattern filter must use the AND logical operator.
  • BAdd a new condition to filter Modbus traffic based on the source TCP/UDP port.
  • CIn the Group By section, remove all attributes that are not configured in the Filter section.
  • DIn the Aggregate section, set the attribute value to equal to or greater than 0.

How the community answered

(45 responses)
  • A
    2% (1)
  • B
    9% (4)
  • C
    18% (8)
  • D
    71% (32)

Explanation

The current Aggregate condition is set to COUNT(Matched Events) >= 1, which only triggers the rule after at least one event. To ensure all Modbus messages (including the first one) match the rule, the condition must be >= 0, so every event is considered, including the very first occurrence.

Topics

#FortiSIEM#Modbus rule#aggregate filter#OT traffic monitoring

Community Discussion

No community discussion yet for this question.

Full NSE7_OTS-7.2 Practice