Q: 1
Refer to the exhibit.
Consider the five account locked events received by FortiSIEM from domain controllers within the
last 10 minutes (ten minutes is the evaluation window for the subpattern DomainAcctLockout):
If you look for one or more matching events and groupings by the same reporting IP address,
reporting device, and user, how many incidents are created?
Consider the five account locked events received by FortiSIEM from domain controllers within the
last 10 minutes (ten minutes is the evaluation window for the subpattern DomainAcctLockout):
If you look for one or more matching events and groupings by the same reporting IP address,
reporting device, and user, how many incidents are created?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.