View all questions & answers for the NSE 6 - FortiSIEM 7.2 Analyst Exam Materials exam
Question 29 Discussion
Comments
Selected Answers: C
the attribute AVG(CPU Util) has operator (>) not (>=)
-
Brave-Dumps Admin
2025-09-14 12:55:02
I think C is not correct. Because the rule has two conditions for each host within the 10-minute window: COUNT(Matched Events) ≥ 2 AVG(CPU Util) > Critical Threshold (from the CMDB for each server) What do you think? -
Zaid Haitham
2025-09-15 23:54:50
Maybe You're right.
Selected Answers: C
Neither server meets the threshold even once, so neither can reach count ≥2.
C is correct
Selected Answers: A
Refer to the exhibits. Three events are collected over 10 minutes from two servers: Server A and Server B. Based on the settings for the rule subpattern and a 10-minute condition window, how many incidents will the servers generate? (Choose one answer)
Brave-Dump Clients Votes