Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exc65

Refer to the exhibit.

As shown in the exhibit, why are some of the fields highlighted in red?

A.

Unique values cannot be grouped

B.

The attribute COUNT(Matched Events) is an invalid expression.

C.

No RAW Event Log attribute information is available.

D.

The Event Receive Time attribute is not available for logs.

How does FortiSIEM update the incident table if a performance rule triggers repeatedly?

A.

FortiSIEM changes the incident status to Repeated, and updates the Last Seen timestamp.

B.

FortiSIEM updates the Incident Count value and Last Seen timestamp.

C.

FortiSIEM generates a new incident based on the Rule Frequency value, and updates the First Seen and Last Seen timestamps.

D.

FortiSIEM generates a new incident each time the rule triggers, and updates the First Seen and Last Seen timestamps.

Refer to the exhibit.

An analyst is trying to identify an issue using an expression based on the Expression Builder settings shown in the exhibit; however, the error message shown in the exhibit indicates that the expression is invalid.

What is the correct syntax to create an expression that generates a total count of matched events?

A.

COUNT(Matched Events)

B.

(COUNT) Matched Events

C.

Matched Events (COUNT)

D.

Matched Events COUNT()

Which information can FortiSIEM retrieve from FortiClient EMS through an API connection?

A.

Host software versions

B.

FortiSIEM license

C.

Host login credentials

D.

ZTNA tags

Refer to the exhibit.

An analyst is troubleshooting the rule shown in the exhibit. It is not generating any incidents, but the filter parameters are generating events on the Analytics tab.

What is wrong with the rule conditions?

A.

The Event Type refers to a CMDB lookup and should be an Event lookup.

B.

The Destination Host Name value is not fully qualified.

C.

The Group By attributes restricts which events are counted.

D.

The Aggregate attribute is too restrictive.

Refer to the exhibit.

If a rule containing the automation policy shown in the exhibit triggers, what will happen?

A.

Associated source IP addresses will be blocked on devices in the Aviation organization.

B.

Associated source IP addresses will be blocked on all FortiGate firewalls.

C.

Associated source IP addresses will be blocked on devices in the Network CMDB group.

D.

Associated source IP addresses will be blocked on two FortiGate firewalls.

Which items are used to define a subpattern?

A.

Filters, Aggregate, Group By definitions

B.

Filters, Aggregate, Time Window definitions

C.

Filters, Group By, Threshold definitions

D.

Filters, Threshold, Time Window definitions

Refer to the exhibit.

Which two lookup types can you reference as the subquery in a nested analytics query? (Choose two.)

A.

LDAP Query

B.

CMDB Query

C.

SNMP Query

D.

Event Query

Refer to the exhibit.

How was this incident cleared?

A.

The analyst manually cleared the incident from the incident table.

B.

FortiSIEM cleared the incident automatically after 24 hours.

C.

The incident was cleared automatically by the rule.

D.

The endpoint was rebooted and sent an all-clear signal to FortiSIEM.