Weekend Sale - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

In the rules engine, which condition instructs FortiSIEM to summarize and count the matching evaluated data?

A.

Time Window

B.

Aggregation

C.

Group By

D.

Filters

An administrator defines SMTP as a critical process on a Linux server.

It the SMTP process is stopped. FortiSIEM will generate a critical event with which event type?

A.

Postfix-Mail-Stop

B.

PH_DEV_MON_PROC_STOP

C.

PH_DEV_MON_SMTP_STOP

D.

Generic_SMTP_Procoss_Exit

An administrator is configuring FortiSIEM to discover network devices and receive syslog from network devices. Which statement is correct?

A.

FortiSIEM uses privileged credentials to tog in to devices and make network configuration changes.

B.

FortiSIEM automatically configures network devices to send syslog using the auto log discovery process.

C.

FortiSIEM automatically configures network devices to send syslog using the GUI discovery process

D.

Syslog configuration must be done manually on devices by the network administrator.

Which three ports can be used to send Syslogs to FortiSIEM? (Choose three.)

A.

UDP9999

B.

UDP 162

C.

TCP 514

D.

UDP 514

E.

TCP 1470

Refer to the exhibit.

It events are grouped by Event Type and User attributes in FortiSIEM. how many results will be displayed?

A.

Four results will be displayed.

B.

Eight results will be displayed.

C.

Two results will be displayed.

D.

No results will be displayed.

Refer to the exhibit.

A FortiSIEM administrator wants to group some attributes for a report, but is not able to do so successfully.

As shown in the exhibit, why are some of the fields highlighted in red?

A.

Unique attributes cannot be grouped.

B.

The Event Receive Time attribute is not available for logs.

C.

The attribute COUNT(Matched events) is an invalid expression.

D.

No RAW Event Log attribute is available for devices.

Refer to the exhibit.

The output shows that the license is in which condition?

A.

The license is supported.

B.

The license is in an active stale.

C.

The license is invalid.

D.

The offline registration of the license is successful.

An administrator is using SNMP credential only for discovery of a Windows device. How will FortiSIEM handle this?

A.

FortiSIEM will apply a job to collect application event logs.

B.

FortiSIEM will apply system monitor jobs to collect resources data.

C.

FortiSIEM will apply a Job to collect security event logs

D.

FortiSIEM will apply a job to collect system event logs.

What does the Frequency field determine on a rule?

A.

How often the rule will evaluate the subpattern.

B.

How often the rule will trigger for the same condition.

C.

How often the rule will trigger.

D.

How often the rule will take a clear action.