The correct answer is B . Forcepoint DSPM Controls Orchestration rules are built around query-driven rule logic. In the rule configuration workflow, administrators select a dataset such as Files , Trustees , or Agent Activities , then configure the rule condition using GQL syntax . This GQL condition defines which records match the rule and therefore which results appear as incidents when the rule is triggered. Forcepoint documentation states that Controls Orchestration rules identify data matching specific criteria and that the Condition field uses GQL syntax to filter the selected dataset.
When reviewing incidents, Forcepoint’s Incidents page provides a top-down view of orchestration rules and available match results. Selecting an incident card opens a results preview, and choosing View in the Page displays those matched files in Enterprise Search , where additional review and action options are available. Enterprise Search is specifically designed to narrow scanned-file results using GetVisibility Query Language , and Forcepoint notes that GQL filtering helps reduce the result set to a more manageable subset for analysis and action.
Timestamp, Risk type, and keyword filtering may be useful in other contexts, but the documented advanced review mechanism for these results is GQL-based filtering. References/topics: Controls Orchestration, Incidents, Enterprise Search, GQL Filtering, Rule Match Review .