Pass the Fortinet Fortinet Certified Professional Security Operations FCSS_ADA_AR-6.7 Questions and answers with CertsForce

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

When you perform a Group By on a structured query, which two outcomes occur? (Choose two.)

Options:

A.

Group By automatically applies a COUNT aggregation.


B.

Group By is applied to real-time and historical searches.


C.

Group By cannot be applied to an aggregated function.


D.

Group By is applied to historical searches only.


Expert Solution
Questions # 12:

Refer to the exhibit.

Question # 12

If the Z-score for this rule is greater than or equal to three, what does this mean?

Options:

A.

The rate of firewall connection is below historical average value.


B.

The rate of firewall connection is optimum.


C.

The rate firewall connection is above the historical average value.


D.

The rate of firewall connection is above the current average value.


Expert Solution
Questions # 13:

What is the disadvantage of automatic remediation?

Options:

A.

It can make a disruptive change to a user, block access to an application, or disconnect critical systems from the network.


B.

External threats or attacks detected by FortiSIEM will need user interaction to take action on an already overworked SOC team.


C.

It is equivalent to running an IPS in monitor-only mode-watches but does not block.


D.

Threat behavior occurring during the night could take hours to respond to.


Expert Solution
Questions # 14:

Refer to the exhibit.

Question # 14

What are three possible reasons why theAgent StatusdisplaysRunning Inactive? (Choose three.)

Options:

A.

The agent was registered incorrectly


B.

The collector was not assigned to the agent


C.

The agent is temporarily down


D.

The template was not assigned


E.

The template was removed


Expert Solution
Questions # 15:

Which organization do agents belong to after registration? (Choose two.)

Options:

A.

The windows agents belong to the super organization.


B.

The agents belong to the organization specified in the agent installation setup wizard for Windows platforms.


C.

The Linux agents belong to the super local organization.


D.

The agents belong to the organization specified in the command line parameters for Linux platforms.


Expert Solution
Questions # 16:

Refer to the exhibit.

Question # 16

Consider the five account locked events received by FortiSIEM from domain controllers within the last 10 minutes (ten minutes is the evaluation window for the subpattern DomainAcctLockout):

Question # 16

If you look for one or more matching events and groupings by the same reporting IP address, reporting device, and user, how many incidents are created?

Options:

A.

3


B.

4


C.

2


D.

1


Expert Solution
Questions # 17:

Which statement accurately contrasts lookup tables with watchlists?

Options:

A.

Lookup table values age out after a period, whereas watchlist values do not have any time condition.


B.

You can populate lookup tables through an incident, whereas you cannot populate watchlists through an incident.


C.

Lookup tables can contain multiple columns, whereas watchlists contain only a single column.


D.

You can reference lookup table data in analytic queries and reports almost immediately, whereas you may have to wait up to 5-10 minutes for watchlist entries to be useable in queries and reports.


Expert Solution
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions