Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet NSE7_SOC_AR-7.6 Exam - Topic 1 Question 4 Discussion

Actual exam question for Fortinet's NSE7_SOC_AR-7.6 exam
Question #: 4
Topic #: 1
[All NSE7_SOC_AR-7.6 Questions]

Refer to the exhibit.

You are reviewing the Triggering Events page for a FortiSIEM incident. You want to remove the Reporting IP column because you have only one firewall in the topology. How do you accomplish this? (Choose one answer)

Show Suggested Answer Hide Answer
Suggested Answer: D

Comprehensive and Detailed Explanation From FortiSOAR 7.6., FortiSIEM 7.3 Exact Extract study guide:

In FortiSIEM 7.3, the Triggering Events view is a dynamic table that displays the individual logs that caused a specific rule to fire. To manage the visibility of data within this specific view:

Interface Customization: The 'Triggering Events' tab includes a column management feature. By clicking on the column headers or the table settings icon (typically found at the top right of the event list), an analyst can customize the display columns. This allows the user to uncheck the 'Reporting IP' attribute, effectively hiding it from the view without altering the underlying data or rule logic.

Operational Efficiency: This is a common task in environments with a simplified topology where the 'Reporting IP' is redundant information. Customizing the view helps the analyst focus on the most relevant data points, such as 'Source IP,' 'Destination IP,' and 'Destination Port.'

Why other options are incorrect:

A (Incident Action): Clearing a field from the Incident Action configuration affects what data is sent in an email alert or passed to a SOAR platform, but it does not change the layout of the FortiSIEM GUI 'Triggering Events' page.

B (Disable Correlation): Disabling correlation for an attribute determines whether that attribute is used by the rules engine to group events. It does not control the visual display of columns in the incident dashboard.

C (Parsing Rules): Removing attributes via parsing rules is a destructive process that prevents the SIEM from indexing that data entirely. This would make the 'Reporting IP' unavailable for all searches and reports, which is excessive for a simple display preference.


Contribute your Thoughts:

0/2000 characters
Corrinne
3 days ago
I’m surprised this is even an option!
upvoted 0 times
...
Becky
9 days ago
A is definitely not the way to go.
upvoted 0 times
...
Jenelle
14 days ago
Wait, can you really just remove it like that?
upvoted 0 times
...
Dulce
19 days ago
Agree, D makes the most sense here.
upvoted 0 times
...
Keneth
24 days ago
I think D is the right choice!
upvoted 0 times
...
Yolando
29 days ago
I’m a bit confused about the correlation rules. Could B actually be the right option if it disables the field?
upvoted 0 times
...
Arlette
1 month ago
This question seems similar to one we practiced where we had to adjust attributes in an incident. I think D could be the answer again.
upvoted 0 times
...
Emogene
1 month ago
I'm not entirely sure, but I feel like clearing fields in the Incident Action might not actually remove the column.
upvoted 0 times
...
Corinne
1 month ago
I think I remember something about customizing display columns, so maybe D is the right choice?
upvoted 0 times
...

Save Cancel