Refer to the exhibit.
The rule evaluates multiple VPN logon failures within a ten-minute window. Consider the following VPN failure events received within a ten-minute window:
How many incidents are generated?
Which two statements about the maximum device limit on FortiSIEM are true? (Choose two.)
FortiSIEM provides all rules with the ability to automatically change an active incident status to auto-cleared, based on an extra set of defined criteria.
Why would you configure FortiSIEM to automatically change an active incident status to auto-cleared?
In a customer network that includes a collector, which device performs device discoveries?
Refer to the exhibit.
Consider a custom lookup tableMalwareIPList. An analyst constructed an analytic query to reference theMalwareIPListlookup table.
What is the outcome of the analytic query?
Refer to the exhibit.
An administrator applies the rule exception shown in the exhibit.
How does this configuration impact the incident generation for that rule?
Refer to the exhibit.
Which devices will be added to the CMDB and mapped to Customer E?
Refer to the exhibit.
What are three possible reasons why theAgent StatusdisplaysRunning Inactive? (Choose three.)
Which three statements about collector communication with the FortiSIEM cluster are true? (Choose three.)