QuestionQ19

Configure incidents and automation

Which two components are required for a rule?

Choose two
  • A Exception policy
  • B Subpattern
  • C Detection Technology
  • D Clear policy
Explanation

A FortiSIEM rule specifies its detection method through Detection Technology and requires a Subpattern to define the event characteristics and thresholds that trigger an incident. Exception and clear conditions are optional configurations.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!