Q: 1
Refer to the exhibit.
Consider the five account locked events received by FortiSIEM from domain controllers within the
last 10 minutes (ten minutes is the evaluation window for the subpattern DomainAcctLockout):
If you look for one or more matching events and groupings by the same reporting IP address,
reporting device, and user, how many incidents are created?
Consider the five account locked events received by FortiSIEM from domain controllers within the
last 10 minutes (ten minutes is the evaluation window for the subpattern DomainAcctLockout):
If you look for one or more matching events and groupings by the same reporting IP address,
reporting device, and user, how many incidents are created?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Why is the windows device still in the CMDB, even though the administrator uninstalled the windows
agent?
A service provider does not have a dedicated worker in the cluster, but still wants to add a collector
to an organization.
What option does the administrator have?