What are four incident status options on FortiSIEM?
You are creating a rule to fill a gap in your organization's MITRE ATT&CK rule coverage matrix.
How can you associate the rule with an appropriate tactics, techniques and procedures (TTP) category?
Refer to the exhibit.

An analyst is troubleshooting the rule shown in the exhibit. It is not generating any incidents, but the filter parameters are generating events on the Analytics tab.
What is wrong with the rule conditions?
Which two attributes can you not select together in the Group By and Display Fields? (Choose two.)
Refer to the exhibit.

If a rule containing the automation policy shown in the exhibit triggers, what will happen?
An analyst wants to run a remediation playbook when a user fails a VPN login five times from an external machine. Where do they associate the remediation playbook with the triggering rule?
Refer to the exhibit.

You are investigating an issue with two destination IP addresses, but you are not getting any results from the search.
Based on the filters shown in the exhibit, why is this search returning no results?
When selecting multiple rules at once on FortiSIEM, which actions can you perform?
Which two ways can an automation service playbook can be triggered? (Choose two.)
In an automation policy, which two methods can you use to notify analysts when an incident is triggered? (Choose two.)