Special Summer Sale - Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70dumps

FCSS_ADA_AR-6.7 Questions and Answers

Question # 6

Which lookup table function can be either true or false?

A.

LookupTableHas

B.

LookupTableGet

C.

LookupTableFilter

D.

LookupTableRetriev

Full Access
Question # 7

A service provider purchased a 500-EPS license and configured a new collector with 100 EPS for customer A, and another collector with 200 EPS for customer B.

How much is in the remaining EPS pool for future customers and for MSSP itself?

A.

30

B.

200

C.

100

D.

50

Full Access
Question # 8

How can you empower SOC by deploying FortiSOAR? (Choose three.)

A.

Collaborative knowledge sharing

B.

Aggregate logs from distributed systems

C.

Address analyst skills gap

D.

Baseline user and traffic behavior

E.

Reduce human error

Full Access
Question # 9

Refer to the exhibit.

Which scenario is not a supported nested query scenario?

A.

The outer query is the event query, and the inner query is the event query.

B.

The outer query is the event query, and the inner query is the CMDB query.

C.

The outer query is the CMDB query, and the inner query is the event query.

D.

The outer query is the CMDB query, and the inner query is the CMDB query.

Full Access
Question # 10

Refer to the exhibit.

An administrator runs an analytic search for all FortiGate SSL VPN logon failures. The results are grouped by source IP, reporting IP, and user. The administrator wants to restrict the results to only those rows where the COUNT >=3.

Which user would meet that condition?

A.

Jan

B.

Sarah

C.

Admin

D.

Tom

Full Access
Question # 11

Which three statements about collector communication with the FortiSIEM cluster are true? (Choose three.)

A.

Collectors communicate periodically with the supervisor node.

B.

The supervisor periodically checks the health of the collector.

C.

The only communication between the collector and the supervisor is during the registration process.

D.

The supervisor does not initiate any connections to the collector node.

E.

Collector upload event data to any node in the worker upload list, but report their health directly to the supervisor node.

Full Access
Question # 12

Refer to the exhibit.

If the Z-score for this rule is greater than or equal to three, what does this mean?

A.

The rate of firewall connection is below historical average value.

B.

The rate of firewall connection is optimum.

C.

The rate firewall connection is above the historical average value.

D.

The rate of firewall connection is above the current average value.

Full Access
Question # 13

Why do collectors communicate with the Supervisor after registration? (Choose two.)

A.

To receive templates associated with agents

B.

To report the health status of the agents

C.

To upload event data if a worker down

D.

To report its own health status

Full Access
Question # 14

Refer to the exhibit.

Is the Windows agent delivering event logs correctly?

A.

The agent is registered and it is sending logs correctly.

B.

The logs are buffered by the agent and will be sent once the status changes to managed.

C.

Because the agent is unmanaged. the logs are dropped silently by the supervisor.

D.

The agent is not sending logs because it did not receive a monitoring template.

Full Access
Question # 15

Refer to the exhibit.

Consider a custom lookup tableMalwareIPList. An analyst constructed an analytic query to reference theMalwareIPListlookup table.

What is the outcome of the analytic query?

A.

The IP address from permitted traffic with a confidence score of 98 is displayed.

B.

The analyst receives an error because the LookupTableGet function can be used only in display filters to enrich data.

C.

The value for the LookupTableGet function in the analytic search can be either true or false.

D.

The permitted traffic IP address from the Phishing category is displayed.

Full Access
Question # 16

Which organization do agents belong to after registration? (Choose two.)

A.

The windows agents belong to the super organization.

B.

The agents belong to the organization specified in the agent installation setup wizard for Windows platforms.

C.

The Linux agents belong to the super local organization.

D.

The agents belong to the organization specified in the command line parameters for Linux platforms.

Full Access
Question # 17

A service provider purchases a licensed EPS of 520. The guaranteed EPS allocated to three customers is 50, 100, and 150 respectively. At the end of every three-minute interval, incoming EPS is calculated at every collector and the value is sent to the central decision-making engine on the supervisor node.

The incoming EPS for the first collector is 25. the incoming EPS for the second collector is 50, and the incoming EPS for the third collector is 75.

Based on the information provided, what is the unused events total calculated by the supervisor?

A.

76.000

B.

35.960

C.

75.960

D.

71.460

Full Access