Special Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Fortinet FCSS_ADA_AR-6.7 FCSS Advanced Analytics 6.7 Architect Exam Practice Test

Demo: 17 questions
Total 59 questions

FCSS Advanced Analytics 6.7 Architect Questions and Answers

Question 1

From where does the rule engine load the baseline data values?

Options:

A.

The memory

B.

The profile report

C.

The profile database

D.

The daily database

Question 2

Refer to the exhibit.

Consider a nested event query where both inner and outer queries are event queries.

Reporting IPis selected from the CMDB groupNetwork Device, Event Typeis selected from the CMDB groupLogon Success,andSource IPis selected from the reportFailed Logons to Network Devices.

An administrator is about to execute the nested query. The report time ranges must be set before execution. TheNested Time Rangewill be applied to which attributes?

Options:

A.

The nested time range will be configured for the Reporting IP attribute.

B.

The nested time range will be configured for the Reporting IP and Event Type attributes.

C.

The nested time range will be configured for the Source IP attribute.

D.

The nested time range will be configured for the Event Type attribute.

Question 3

Which three processes are collector processes? (Choose three.)

Options:

A.

phParser

B.

phAgentManager

C.

phMonitorAgent

D.

phReportMaster

E.

phRuleMaster

Question 4

Refer to the exhibit.

The exhibit shows the output of an SQL command that an administrator ran to view the natural_id value, after logging into the Postgres database.

What does the natural_id value identify?

Options:

A.

The collector

B.

An agent

C.

The worker

D.

The supervisor

Question 5

Refer to the exhibit.

An administrator deploys a new collector for the first time, and notices that all the processes expect the phMonitor are down.

How can the administrator bring the processes up?

Options:

A.

The collector was not deployed properly and must be redeployed.

B.

The administrator needs to run the command phtools - start all on the collector.

C.

Rebooting the collector will bring up the processes.

D.

The processes will come up after the collector is registered to the supervisor.

Question 6

What happens to events that the collector receives when there is a WAN link failure between the collector and the supervisor?

Options:

A.

Events are buffered for up to 24 hours.

B.

Events are buffered up to 10 MB before compression.

C.

Events are buffered up to 10.000 logs.

D.

Events are buffered up to 1 GB after compression.

Question 7

What is the disadvantage of automatic remediation?

Options:

A.

It can make a disruptive change to a user, block access to an application, or disconnect critical systems from the network.

B.

External threats or attacks detected by FortiSIEM will need user interaction to take action on an already overworked SOC team.

C.

It is equivalent to running an IPS in monitor-only mode-watches but does not block.

D.

Threat behavior occurring during the night could take hours to respond to.

Question 8

Refer to the exhibit.

Which deployment type is shown in the exhibit?

Options:

A.

Service provider with collectors

B.

Service provider without collectors

C.

Hybrid deployment with and without collectors

D.

Enterprise cloud deployment

Question 9

FortiSIEM provides all rules with the ability to automatically change an active incident status to auto-cleared, based on an extra set of defined criteria.

Why would you configure FortiSIEM to automatically change an active incident status to auto-cleared?

Options:

A.

Because availability or performance-related problems may trigger a threshold temporarily.

B.

Because too many active incidents can spike the resource usaqe on FortiSIEM.

C.

Because you need a way to reduce a backlog of incident responses.

D.

Because some security-related incidents occur on a temporary basis.

Question 10

How can you invoke an integration policy on FortiSIEM rules?

Options:

A.

Through Notification Policy settings

B.

Through External Authentication settings

C.

Through Incident Notification settings

D.

Through remediation scripts

Question 11

Refer to the exhibit.

Which scenario is not a supported nested query scenario?

Options:

A.

The outer query is the event query, and the inner query is the event query.

B.

The outer query is the event query, and the inner query is the CMDB query.

C.

The outer query is the CMDB query, and the inner query is the event query.

D.

The outer query is the CMDB query, and the inner query is the CMDB query.

Question 12

Refer to the exhibit.

The collector is registered and has pulled the license file from the supervisor.

What are the consequences of removing the license file?

Options:

A.

The collector must be re-registered with the supervisor to get the license file back.

B.

The collector processes will go down.

C.

The collector must be redeployed to get the license file back.

D.

The license file must be pushed manually from the supervisor.

Question 13

Refer to the exhibit.

Within what time window is the incident auto cleared?

Options:

A.

1800 seconds

B.

Null

C.

1 day

D.

30 minutes

Question 14

Refer to the exhibit.

Consider a custom lookup tableMalwareIPList. An analyst constructed an analytic query to reference theMalwareIPListlookup table.

What is the outcome of the analytic query?

Options:

A.

The IP address from permitted traffic with a confidence score of 98 is displayed.

B.

The analyst receives an error because the LookupTableGet function can be used only in display filters to enrich data.

C.

The value for the LookupTableGet function in the analytic search can be either true or false.

D.

The permitted traffic IP address from the Phishing category is displayed.

Question 15

Refer to the exhibit.

The rule evaluates multiple VPN logon failures within a ten-minute window. Consider the following VPN failure events received within a ten-minute window:

How many incidents are generated?

Options:

A.

1

B.

2

C.

0

D.

3

Question 16

A service provider purchased a 500-EPS license and configured a new collector with 100 EPS for customer A, and another collector with 200 EPS for customer B.

How much is in the remaining EPS pool for future customers and for MSSP itself?

Options:

A.

30

B.

200

C.

100

D.

50

Question 17

How do customers connect to a shared multi-tenant instance on FortiSOAR?

Options:

A.

The customer must install a tenant node to connect to the MSSP shared multi-tenant instance.

B.

The MSSP must provide secure network connectivity between the FortiSOAR manager node and the customer devices.

C.

The MSSP must install a Secure Message Exchange node to connect to the customer’s shared multi-tenant instance.

D.

The MSSP must install an agent node on the customer’s network to connect to the customer's shared multi-tenant instance.

Demo: 17 questions
Total 59 questions