FCP – FortiSIEM Analyst 7.2 — Question 4

How does FortiSIEM update the incident table if a performance rule triggers repeatedly?

Answer options

Correct answer: B

Explanation

The correct answer is B because FortiSIEM tracks the frequency of incidents by incrementing the Incident Count and updating the Last Seen timestamp when a performance rule triggers repeatedly. Options A, C, and D are incorrect as they suggest changing the incident status or creating new incidents, which does not occur in this scenario.