Refer to the exhibits.


How many events will be added to the incident created after running this playbook?
Refer to the exhibits.
How many events will be added to the incident created after running this playbook?
The playbook specifies that events should match the criteria of having a severity of Medium, an event type of IPS, and a tag of Intrusion. From the exhibits, there are a total of 10 events that meet all these conditions. Therefore, 10 events will be added to the incident created after running this playbook.
I count 10 Intrusion + IPS + Medium. That would be B.
B is correct
why b?
I think that A should be correct https://docs.fortinet.com/document/fortianalyzer/7.4.0/administration-guide/337904/understanding-event-statuses Mitigated: The security risk is mitigated by being blocked or dropped. Example: an IPS/AV log with action=block/drop will have the event status Mitigated.
Match all conditions: Intrusion + IPS + Medium: 10
I think her is B
Correct Ans: C
yes C is correct !
Why C?
I think the answer is B (Intrusion + IPS + Medium)
Will the playbook add mitigated events? Or does it need to be just unhandled? Cause it could be A
A is correct, as all events which match the filters are mitigated, and thus no incidents will be created when running the playbook.
B - Correct.