Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

Which two data areas can you use for user and entity behavior analytics (EBA) machine learning models? (Choose two.)

A.

Process

B.

Location

C.

Resources

D.

Network

Refer to the exhibit.

How was this incident cleared?

A.

The analyst manually cleared the incident from the incident table.

B.

FortiSIEM cleared the incident automatically after 24 hours.

C.

The incident was cleared automatically by the rule.

D.

The endpoint was rebooted and sent an all-clear signal to FortiSIEM.

Refer to the exhibit.

What is the Group: FortiSIEM Analysts value referring to?

A.

FortiSIEM organization group

B.

LDAP user group

C.

CMDB user group

D.

Windows Active Directory user group

Refer to the exhibit.

If a rule containing the automation policy shown in the exhibit triggers, what will happen?

A.

Associated source IP addresses will be blocked on devices in the Aviation organization.

B.

Associated source IP addresses will be blocked on all FortiGate firewalls.

C.

Associated source IP addresses will be blocked on devices in the Network CMDB group.

D.

Associated source IP addresses will be blocked on two FortiGate firewalls.

What can you use to send data to FortiSIEM for user and entity behavior analytics (UEBA)?

A.

FortiSIEM agent

B.

SSH

C.

SNMP

D.

FortiSIEM worker

Refer to the exhibit.

What is the Group: VPN Gateway value a reference to? (Choose one answer)

A.

A configuration management database (CMDB) device group

B.

A FortiSIEM rule folder

C.

A FortiSIEM watchlist

D.

A FortiGate address group

How does FortiSIEM update the incident table if a performance rule triggers repeatedly?

A.

FortiSIEM changes the incident status to Repeated, and updates the Last Seen timestamp.

B.

FortiSIEM updates the Incident Count value and Last Seen timestamp.

C.

FortiSIEM generates a new incident based on the Rule Frequency value, and updates the First Seen and Last Seen timestamps.

D.

FortiSIEM generates a new incident each time the rule triggers, and updates the First Seen and Last Seen timestamps.

An analyst wants to create a rule from a newly created analytics search.

What is the quickest method?

A.

On the Analytics tab, click Actions > Create Rule.

B.

Create a new rule under Resources > Rules and fill in the search details.

C.

On the Analytics tab, click the New button next to the Filter By box.

D.

On the upper menu bar on any tab, click the pencil icon.

When configuring machine learning (ML), in which step can you modify how the model fits the training data set?

A.

Prepare Data

B.

Train

C.

Statistics

D.

Design

Refer to the exhibit.

Which two conditions will match this rule and subpatterns? (Choose two.)

A.

A user using RDP over SSL VPN fails to log in to an application five times.

B.

A user runs a brute force password cracker against an RDP server.

C.

A user fails twice to log in when connecting through RDP.

D.

A user connects to the wrong IP address for an RDP session five times.