Pass the Fortinet Fortinet Certified Professional Security Operations FCSS_ADA_AR-6.7 Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

Which statement about EPS bursting is true?

Options:

A.

FortiSIEM will let you burst up to five times the licensed EPS at any given time, provided it has accumulated enough unused EPS.


B.

FortiSIEM will let you burst up to five times the licensed EPS once during a 24-hour period.


C.

FortiSIEM will let you burst up to five times the licensed EPS at any given time, regardless of unused of EPS.


D.

FortiSIEM must be provisioned with ten percent the licensed EPS to handle potential event surges.


Expert Solution
Questions # 2:

How can you customize the AI model on FortiSIEM?

Options:

A.

Retrain the AI model


B.

Reconfigure UEBA rules


C.

Adjust risk weighting for UEBA tags


D.

Adjust number of samples collected by the UEBA agents


Expert Solution
Questions # 3:

Refer to the exhibit.

Question # 3

The window for this rule is 30 minutes.

What is this rule tracking?

Options:

A.

A sudden 50% increase in WMI response times over a 30-minute time window


B.

A sudden 1.50 times increase in WMI response times over a 30-minute time window


C.

A sudden 150% increase in WMI response times over a 30-minute time window


D.

A sudden 75% increase in WMI response times over a 30-minute time window


Expert Solution
Questions # 4:

Refer to the exhibit.

Question # 4

Why was this incident auto cleared?

Options:

A.

Within five minutes, the packet loss percentage dropped to a level where the host IP of the original rule matches the host IP of the clear condition pattern


B.

Within five minutes the packet loss percentage dropped to a level where the reporting IP is the same as the host IP


C.

The original rule did not trigger within five minutes


D.

Within five minutes, the packet loss percentage dropped to a level where the reporting IP is same as the source IP


Expert Solution
Questions # 5:

From where does the rule engine load the baseline data values?

Options:

A.

The memory


B.

The profile report


C.

The profile database


D.

The daily database


Expert Solution
Questions # 6:

Refer to the exhibit.

Question # 6

Which workers are assigned tasks for the query ID13127? (Choose two.)

Options:

A.

Worker1 has no tasks for query ID 13127*.


B.

Worker1 has one task for query ID 13127*.


C.

Worker2 has two tasks for query ID 13127*.


D.

Worker3 has four tasks for query ID 13127*.


E.

Worker3 has two tasks for query ID 13127*.


Expert Solution
Questions # 7:

Refer to the exhibit.

Question # 7

Consider a nested event query where both inner and outer queries are event queries.

Reporting IPis selected from the CMDB groupNetwork Device, Event Typeis selected from the CMDB groupLogon Success,andSource IPis selected from the reportFailed Logons to Network Devices.

An administrator is about to execute the nested query. The report time ranges must be set before execution. TheNested Time Rangewill be applied to which attributes?

Options:

A.

The nested time range will be configured for the Reporting IP attribute.


B.

The nested time range will be configured for the Reporting IP and Event Type attributes.


C.

The nested time range will be configured for the Source IP attribute.


D.

The nested time range will be configured for the Event Type attribute.


Expert Solution
Questions # 8:

What is the hourly bucket used in baselining?

Options:

A.

To store hourly baselines reports for every hour of the day during weekdays and weekends


B.

To store data for specific baselines during the weekend, if there is a spike in network activity


C.

To store data for specific baselines during peak business hours of weekdays


D.

To store data for specific baselines for every hour of the day during weekdays and weekends


Expert Solution
Questions # 9:

How can you empower SOC by deploying FortiSOAR? (Choose three.)

Options:

A.

Collaborative knowledge sharing


B.

Aggregate logs from distributed systems


C.

Address analyst skills gap


D.

Baseline user and traffic behavior


E.

Reduce human error


Expert Solution
Questions # 10:

Which two statements about phRuleWorker are true? (Choose two.)

Options:

A.

phRuleWorker uses a 60-second bucket as an evaluation window.


B.

phRuleWorker evaluates non-aggregate conditions as defined in subpattern filters of a rule in memory.


C.

phRuleWorker exists on both the supervisor and workers.


D.

phRuleWorker exists on the worker only.


Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions