Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exc65

Refer to the exhibit.

An administrator runs an analytic search for all FortiGate SSL VPN logon failures. The results are grouped by source IP, reporting IP, and user. The administrator wants to restrict the results to only those rows where the COUNT >= 3.

Which user would meet that condition?

A.

Sarah

B.

Jan

C.

Tom

D.

Admin

Which three statements about phRuleMaster are true? (Choose three.)

A.

phRuleMaster queues up the data being received from the phRuleWorkers into buckets.

B.

phRuleMaster is present on the supervisor and workers.

C.

phRuleMaster is present on the supervisor only

D.

phRuleMaster wakes up to evaluate all the rule data in series, every 30 seconds.

E.

phRuleMaster wakes up to evaluate all the rule data in parallel, even/ 30 seconds

In the event of a WAN link failure between the collector and the supervisor, by default, what is the maximum number of event files stored on the collector?

A.

30.000

B.

10.000

C.

40.000

D.

20.000

Which three statements about collector communication with the FortiSIEM cluster are true? (Choose three.)

A.

The only communication between the collector and the supervisor is during the registration process.

B.

Collectors communicate periodically with the supervisor node.

C.

The supervisor periodically checks the health of the collector.

D.

The supervisor does not initiate any connections to the collector node.

E.

Collectors upload event data to any node in the worker upload list, but report their health directly to the supervisor node.

Which statement about EPS bursting is true?

A.

FortiSIEM will let you burst up to five times the licensed EPS once during a 24-hour period.

B.

FortiSIEM must be provisioned with ten percent the licensed EPS to handle potential event surges.

C.

FortiSIEM will let you burst up to five times the licensed EPS at any given time, provided it has accumulated enough unused EPS.

D.

FortiSIEM will let you burst up to five times the licensed EPS at any given time, regardless of unused of EPS.

Refer to the exhibit.

Which statement about the rule filters events shown in the exhibit is true?

A.

The rule filters events with an event type that belong to the Domain Account Locked CMDB group or a reporting IP that belong to the Domain Controller applications group.

B.

The rule filters events with an event type that belong to the Domain Account Locked CMDB group and a reporting |P that belong to the Domain Controller applications group.

C.

The rule filters events with an event type that belong to the Domain Account Locked CMDB group and a user that belongs to the Domain Controller applications group.

D.

The rule filters events with an event type that equals Domain Account Locked and a reporting IP that equals Domain Controller applications.

Refer to the exhibit.

Is the Windows agent delivering event logs correctly?

A.

The logs are buffered by the agent and will be sent once the status changes to managed.

B.

The agent is registered and it is sending logs correctly.

C.

The agent is not sending logs because it did not receive a monitoring template.

D.

Because the agent is unmanaged. the logs are dropped silently by the supervisor.

From where does the rule engine load the baseline data values?

A.

The profile report

B.

The daily database

C.

The profile database

D.

The memory

Which of the following are two Tactics in the MITRE ATT&CK framework? (Choose two.)

A.

Root kit

B.

Reconnaissance

C.

Discovery

D.

BITS Jobs

E.

Phishing

Identify the processes associated with Machine Learning/Al on FortiSIEM. (Choose two.)

A.

phFortiInsightAI

B.

phReportMaster

C.

phRuleMaster

D.

phAnomaly

E.

phRuleWorker