New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Fortinet NSE 7 - Security Operations 7.6 Architect NSE7_SOC_AR-7.6 Question # 1 Topic 1 Discussion

Fortinet NSE 7 - Security Operations 7.6 Architect NSE7_SOC_AR-7.6 Question # 1 Topic 1 Discussion

NSE7_SOC_AR-7.6 Exam Topic 1 Question 1 Discussion:
Question #: 1
Topic #: 1

Refer to the exhibit.

You notice that the custom event handler you configured to detect SMTP reconnaissance activities is creating a large number of events. This is overwhelming your notification system.

How can you fix this?


A.

Increase the trigger count so that it identifies and reduces the count triggered by a particular group.


B.

Disable the custom event handler because it is not working as expected.


C.

Decrease the time range that the custom event handler covers during the attack.


D.

Increase the log field value so that it looks for more unique field values when it creates the event.


Get Premium NSE7_SOC_AR-7.6 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.