Pre-Winter Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

Which statement about thresholds is true?

A.

FortiSIEM uses fixed, hardcoded global and device thresholds for all performance metrics.

B.

FortiSIEM uses only device thresholds for security metrics.

C.

FortiSIEM uses global and per-device thresholds for performance metrics.

D.

FortiSIEM uses only global thresholds for performance metrics.

Which analytics search can be used to apply a user and entity behavior analytics (UEBA) tag to an event for a failed login by the user JSmith?

A.

User = smith

B.

Username NOT END WITH jsmith

C.

User IS jsmith

D.

Username CONTAIN smit

Refer to the exhibit.

An analyst is troubleshooting the rule shown in the exhibit. It is not generating any incidents, but the filter parameters are generating events on the Analytics tab.

What is wrong with the rule conditions?

A.

The Event Type refers to a CMDB lookup and should be an Event lookup.

B.

The Destination Host Name value is not fully qualified.

C.

The Group By attributes restricts which events are counted.

D.

The Aggregate attribute is too restrictive.

Refer to the exhibit.

According to the automation policy configuration shown in the exhibit, what happens if an associated rule triggers?

A.

FortiSIEM runs the remediation script, because that takes precedence over all other options.

B.

FortiSIEM performs all selected actions.

C.

FortiSIEM fails to the integration policy, because no policy is defined.

D.

FortiSIEM sends an email, because that is first on the list.

Refer to the exhibit.

An analyst wants the rule shown in the exhibit to trigger when three failed login attempts occur within three minutes.

What should the values be for the condition time window and aggregate count?

A.

Time window 180 seconds, aggregate count 3

B.

Time window 180 seconds, aggregate count 2

C.

Time window 90 seconds, aggregate count 3

D.

Time window 90 seconds, aggregate count 2

When configuring anomaly detection machine learning, in which step must you select the fields to analyze?

A.

Design

B.

Schedule

C.

Prepare Data

D.

Train

Which two settings must you configure to allow FortiSIEM to apply tags to devices in FortiClient EMS? (Choose two.)

A.

FortiEMS API credentials defined on FortiSIEM

B.

Remediation script configured

C.

ZTNA tags defined on FortiSIEM

D.

FortiSIEM API credentials defined on FortiEMS

When selecting multiple rules at once on FortiSIEM, what actions can you perform?

A.

You can change the severity of multiple rules, and activate or deactivate them.

B.

You can only view, edit, and activate a single rule at one time.

C.

You can only change the severity of multiple rules.

D.

You can only activate or deactivate multiple rules.

In an automation policy, which two methods can you use to notify analysts when an incident is triggered? (Choose two.)

A.

Email

B.

FortiSIEM Case

C.

Syslog

D.

Pop-up window

Refer to the exhibit.

An analyst wants to perform a KMeans machine learning (ML) job on this data. How many N clusters would be a good fit for the data? (Choose one answer)

A.

Two

B.

50

C.

100

D.

One