Practice Test Geeks home

FCP Threat Detection & Incident Response 2

A FortiSIEM correlation rule fires when five failed SSH logins occur within 60 seconds from the same source IP.
Which attack stage does this rule primarily detect?

Select your answer