Labour Day Special - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: top65certs

Fortinet NSE7_ADA-6.3 Dumps

Fortinet NSE 7 - Advanced Analytics 6.3 Questions and Answers

Question 1

How can you invoke an integration policy on FortiSIEM rules?

Options:

A.

Through Notification Policy settings

B.

Through Incident Notification settings

C.

Through remediation scripts

D.

Through External Authentication settings

Question 2

Refer to the exhibit.

The rule evaluates multiple VPN logon failures within a ten-minute window. Consider the following VPN failure events received within a ten-minute window:

How many incidents are generated?

Options:

A.

1

B.

2

C.

0

D.

3

Question 3

Which statement about EPS bursting is true?

Options:

A.

FortiSIEM will let you burst up to five times the licensed EPS once during a 24-hour period.

B.

FortiSIEM must be provisioned with ten percent the licensed EPS to handle potential event surges.

C.

FortiSIEM will let you burst up to five times the licensed EPS at any given time, provided it has accumulated enough unused EPS.

D.

FortiSIEM will let you burst up to five times the licensed EPS at any given time, regardless of unused of EPS.

Question 4

Which three statements about phRuleMaster are true? (Choose three.)

Options:

A.

phRuleMaster queues up the data being received from the phRuleWorkers into buckets.

B.

phRuleMaster is present on the supervisor and workers.

C.

phRuleMaster is present on the supervisor only

D.

phRuleMaster wakes up to evaluate all the rule data in series, every 30 seconds.

E.

phRuleMaster wakes up to evaluate all the rule data in parallel, even/ 30 seconds

Question 5

Refer to the exhibit.

The exhibit shows the output of an SQL command that an administrator ran to view the natural_id value, after logging into the Postgres database.

What does the natural_id value identify?

Options:

A.

The supervisor

B.

The worker

C.

An agent

D.

The collector

Question 6

What is the disadvantage of automatic remediation?

Options:

A.

It can make a disruptive change to a user, block access to an application, or disconnect critical systems from the network.

B.

It is equivalent to running an IPS in monitor-only mode — watches but does not block.

C.

External threats or attacks detected by FortiSIEM will need user interaction to take action on an already overworked SOC team.

D.

Threat behaviors occurring during the night could take hours to respond to.

Question 7

Refer to the exhibit.

The service provider deployed FortiSIEM without a collector and added three customers on the supervisor.

What mistake did the administrator make?

Options:

A.

Customer A and customer B have overlapping IP addresses.

B.

Collectors must be deployed on all customer premises before they are added to organizations on the supervisor.

C.

The number of workers on the FortiSIEM cluster must match the number of customers added.

D.

At least one collector must be deployed to collect logs from service provider infrastructure devices.

Question 8

Identify the processes associated with Machine Learning/Al on FortiSIEM. (Choose two.)

Options:

A.

phFortiInsightAI

B.

phReportMaster

C.

phRuleMaster

D.

phAnomaly

E.

phRuleWorker

Question 9

Refer to the exhibit.

An administrator runs an analytic search for all FortiGate SSL VPN logon failures. The results are grouped by source IP, reporting IP, and user. The administrator wants to restrict the results to only those rows where the COUNT >= 3.

Which user would meet that condition?

Options:

A.

Sarah

B.

Jan

C.

Tom

D.

Admin

Question 10

What are the modes of Data Ingestion on FortiSOAR? (Choose three.)

Options:

A.

Rule based

B.

Notification based

C.

App Push

D.

Policy based

E.

Schedule based