Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

Match the FortiSIEM device type to its description. Select each FortiSIEM device type in the left column, hold and drag it to the blank space next to its corresponding description in the column on the right.

A partner organization recently suffered a distributed denial-of-service (DDoS) attack, but the adversary’s identity and TTPs remain unknown. Your SOC has not received any relevant threat intelligence from the partner organization, but you are asked to determine whether similar activity could be happening in your environment. Which threat hunting action should you perform first? Choose one answer.

A.

Configure SIEM rules to alert when inbound traffic exceeds baseline thresholds.

B.

Use a packet analyzer to capture and review all traffic flows on critical devices.

C.

Develop a hunting hypothesis based on how DDoS can be executed against your network.

D.

Use threat intelligence to enrich the IP addresses of all external source IP addresses.

You are using FortiSIEM analytics to reference the configuration management database (CMDB) event type categories with the following requirements:

    Attribute: Event Type

    Value: Group: Logon Success

Which operator must you use for the analytics search? Choose one answer.

A.

CONTAIN

B.

IN

C.

HAS

D.

IS

While monitoring your network, you discover that one FortiGate device is sending significantly more logs to FortiAnalyzer than all of the other FortiGate devices in the topology.

Additionally, the ADOM that the FortiGate devices are registered to consistently exceeds its quota.

What are two possible solutions? (Choose two.)

A.

Increase the storage space quota for the first FortiGate device.

B.

Create a separate ADOM for the first FortiGate device and configure a different set of storage policies.

C.

Reconfigure the first FortiGate device to reduce the number of logs it forwards to FortiAnalyzer.

D.

Configure data selectors to filter the data sent by the first FortiGate device.

You need to create a nested query in FortiSIEM that satisfies the following conditions:

    Find all devices discovered by any FortiSIEM Windows Agent.

    From those devices, identify those that have generated Windows Login Failure events.

Which two query components should be used for this nested query? Choose two answers.

A.

Outer Event Query

B.

Outer CMDB Query

C.

Inner CMDB Query

D.

Inner Event Query

When you use a manual trigger to save user input as a variable, what is the correct Jinja expression to reference the variable? (Choose one answer)

A.

{{ vars.input.params. < variable_name > }}

B.

{{ globalVars. < variable_name > }}

C.

{{ vars.item. < variable_name > }}

D.

{{ vars.steps. < variable_name > }}

Which three factors does the FortiSIEM rules engine use to determine the count when it evaluates the aggregate condition COUNT (Matched Events) on a specific subpattern? (Choose three answers)

A.

Group By attributes

B.

Data source

C.

Time window

D.

Search filter

E.

Incident action

Refer to the exhibit.

What is the correct Jinja expression to filter the results to show only the MD5 hash values?

{{ [slot 1]|[slot 2] [slot 3].[slot 4] }}

Select the jinja expression in the left column, hold and drag it to a blank position on the right. Place the four correct steps in order, placing the first

step in the first slot. Once you place an expression, you can move it again if you want to change your answer before moving to the next question. You

need to drop four jinja expressions in the work area.

Select and drag the screen divider to change the viewable area of the source and work areas.

Which role does a threat hunter play within a SOC?

A.

investigate and respond to a reported security incident

B.

Collect evidence and determine the impact of a suspected attack

C.

Search for hidden threats inside a network which may have eluded detection

D.

Monitor network logs to identify anomalous behavior

You created a war room and want to run a connector action to look up the reputation of a domain. Then, you need to save the output for your team to review. However, there is a lot of output, and you want to limit the amount of information attached to the war room. How do you accomplish this? Choose one answer.

A.

From the returned output, select only the output keys you want.

B.

Apply a workspace filter to show only relevant fields.

C.

Use the Investigate tab to map only the fields you want.

D.

Lower the playbook logging level before executing the connector.