Black Friday Biggest Discount Flat 70% Offer - Ends in 0d 00h 00m 00s - Coupon code: 70diswrap

Fortinet NSE7_ADA-6.3 Dumps

Fortinet NSE 7 - Advanced Analytics 6.3 Questions and Answers

Question 1

Refer to the exhibit.

as

Why was this incident auto cleared?

Options:

A.

Within five minutes the packet loss percentage dropped to a level where the reporting IP is the same as the host IP

B.

The original rule did not trigger within five minutes

C.

Within five minutes, the packet loss percentage dropped to a level where the reporting IP is same as the source IP

D.

Within five minutes, the packet loss percentage dropped to a level where the host IP of the original rule matches the host IP of the clear condition pattern

Question 2

Identify the processes associated with Machine Learning/Al on FortiSIEM. (Choose two.)

Options:

A.

phFortiInsightAI

B.

phReportMaster

C.

phRuleMaster

D.

phAnomaly

E.

phRuleWorker

Question 3

What is Tactic in the MITRE ATT&CK framework?

Options:

A.

Tactic is how an attacker plans to execute the attack

B.

Tactic is what an attacker hopes to achieve

C.

Tactic is the tool that the attacker uses to compromise a system

D.

Tactic is a specific implementation of the technique

Question 4

Which three statements about collector communication with the FortiSIEM cluster are true? (Choose three.)

Options:

A.

The only communication between the collector and the supervisor is during the registration process.

B.

Collectors communicate periodically with the supervisor node.

C.

The supervisor periodically checks the health of the collector.

D.

The supervisor does not initiate any connections to the collector node.

E.

Collectors upload event data to any node in the worker upload list, but report their health directly to the supervisor node.

Question 5

Refer to the exhibit.

as

Is the Windows agent delivering event logs correctly?

Options:

A.

The logs are buffered by the agent and will be sent once the status changes to managed.

B.

The agent is registered and it is sending logs correctly.

C.

The agent is not sending logs because it did not receive a monitoring template.

D.

Because the agent is unmanaged. the logs are dropped silently by the supervisor.

Question 6

In the event of a WAN link failure between the collector and the supervisor, by default, what is the maximum number of event files stored on the collector?

Options:

A.

30.000

B.

10.000

C.

40.000

D.

20.000

Question 7

On which disk are the SQLite databases that are used for the baselining stored?

Options:

A.

Disk1

B.

Disk4

C.

Disk2

D.

Disk3

Question 8

Refer to the exhibit.

as

Which statement about the rule filters events shown in the exhibit is true?

Options:

A.

The rule filters events with an event type that belong to the Domain Account Locked CMDB group or a reporting IP that belong to the Domain Controller applications group.

B.

The rule filters events with an event type that belong to the Domain Account Locked CMDB group and a reporting |P that belong to the Domain Controller applications group.

C.

The rule filters events with an event type that belong to the Domain Account Locked CMDB group and a user that belongs to the Domain Controller applications group.

D.

The rule filters events with an event type that equals Domain Account Locked and a reporting IP that equals Domain Controller applications.

Question 9

Which syntax will register a collector to the supervisor?

Options:

A.

phProvisionCollector --add

B.

phProvisionCollector --add

C.

phProvisionCollector --add

D.

phProvisionCollector --add

Question 10

Which of the following are two Tactics in the MITRE ATT&CK framework? (Choose two.)

Options:

A.

Root kit

B.

Reconnaissance

C.

Discovery

D.

BITS Jobs

E.

Phishing

Page: 1 / 3
Total 34 questions