Weekend Sale - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

In the advanced analytical rules engine in FortiSIEM, multiple subpatterms can be referenced using which three operation?(Choose three.)

A.

ELSE

B.

NOT

C.

FOLLOWED_BY

D.

OR

E.

AND

Refer to the exhibit.

A FortiSIEM administrator wants to collect both SIEM event logs and performance and availability metrics (PAM) events from a Microsoft Windows server

Which protocol should the administrator select in the Access Protocol drop-down list so that FortiSIEM will collect both SIEM and PAM events?

A.

TELNET

B.

WMI

C.

LDAPS

D.

LDAP start TLS

Where do you configure rule notifications and automated remediation on FortiSIEM?

A.

Notification policy

B.

Remediation policy

C.

Notification engine

D.

Remediation engine

Refer to the exhibit.

Which value will FortiSIEM use to populate the Event Type field?

A.

PHL_INFO

B.

phPerfJob

C.

PH_DSV_MON_SYS_DISK_UTIL

D.

diskUtil

Which process converts raw log data to structured data?

A.

Data classification

B.

Data validation

C.

Data parsing

D.

Data enrichment

If FortiSIEM supervisor is deployed with the worker using the proprietary flat file database, which action is required?

A.

An event database must be placed on NFS

B.

Collectors must be deployed

C.

A FortiSIEM service provider license must be obtained

D.

A separate network interface must be used for the storage network

In FortiSIEM enterprise licensing mode, it the link between the collector and data center FortiSlEM cluster is down, what happens?

A.

The collector drops incoming events like syslog. but stops performance collection.

B.

The collector processes stop, and events ate dropped.

C.

The collector continues performance collection of devices, but slops receiving syslog.

D.

The collector buffers events

Refer to the exhibit.

Which value will FortiSIEM use to populate the Connection Id field?

A.

33909

B.

134

C.

The connection ID is not in the raw message.

D.

408228

Refer to the exhibit.

The FortiSIEM administrator is examining events for two devices to investigate an issue. However, the administrator is not getting any results from their search.

Based on the selected filters shown in the exhibit, why is the search returning no results?

A.

Parenthesis are missing.

B.

The wrong boolean operator is selected in the Next column.

C.

The wrong option is selected in the Operator column.

D.

An invalid IP subnet is typed in the Value column.

Which protocol do collectors use to communicate with a FortiSIEM cluster?

A.

Syslog

B.

SNMP

C.

HTTPS

D.

SMTP