Refer to the exhibit.

As shown in the exhibit, why are some of the fields highlighted in red?
How does FortiSIEM update the incident table if a performance rule triggers repeatedly?
How can you query the configuration management database (CMDB) in an analytics search?
Refer to the exhibit.

If you group the events by User and Count attributes, how many results will FortiSIEM display?
What can you use to send data to FortiSIEM for user and entity behavior analytics (UEBA)?
Refer to the exhibit.

If you group the events by User , Source IP , and Count attributes, how many results will FortiSIEM display?
Refer to the exhibit.

An analyst wants the rule shown in the exhibit to trigger when three failed login attempts occur within three minutes.
What should the values be for the condition time window and aggregate count?
Which two data areas can you use for user and entity behavior analytics (EBA) machine learning models? (Choose two.)
Refer to the exhibit.

How was this incident cleared?
Refer to the exhibit.

Which two actions can you select in an automation policy to trigger an API call to block an IP address on a FortiGate? (Choose two.)
Refer to the exhibit.

Which value would you expect the FortiSIEM parser to use to populate the Application Name field?
Refer to the exhibit.

An analyst is troubleshooting the rule shown in the exhibit. It is not generating any incidents, but the filter parameters are generating events on the Analytics tab.
What is wrong with the rule conditions?
Refer to the exhibit.

What will happen when a device being analyzed by the machine learning configuration shown in the exhibit has consistently high memory utilization?
Refer to the exhibit.

Which section contains the subpattern configuration that determines how many matching events are needed to trigger the rule?