You need to create a nested query in FortiSIEM that satisfies the following conditions:
Find all devices discovered by any FortiSIEM Windows Agent.
From those devices, identify those that have generated Windows Login Failure events.
Which two query components should be used for this nested query? Choose two answers.
Exact Extract: ''The example on this slide shows a structured search that references the CMDB... Attribute: Reporting IP Operator: IN Value: Devices: Windows... Attribute: Event Type Operator: IN Value: EventTypes: Logon Failure.''
Exact Extract: ''FortiSIEM agents: File, log monitoring, and UEBA.'' The guide also explains that Windows systems can use the FortiSIEM Windows agent for log forwarding and monitoring.
The correct answers are A and C. The first requirement is CMDB-based: identify devices discovered by a FortiSIEM Windows Agent. That belongs in an inner CMDB query because it produces the device set. The second requirement is event-based: from that device set, find devices that generated Windows Login Failure events. That belongs in the outer Event Query, where the event condition can reference the device results from the inner CMDB query.
Currently there are no comments in this discussion, be the first to comment!