Pass the Fortinet NSE 7 Network Security Architect NSE7_ADA-6.3 Questions and answers with CertsForce

Viewing page 1 out of 1 pages
Viewing questions 1-10 out of questions
Questions # 1:

Refer to the exhibit.

Question # 1

An administrator runs an analytic search for all FortiGate SSL VPN logon failures. The results are grouped by source IP, reporting IP, and user. The administrator wants to restrict the results to only those rows where the COUNT >= 3.

Which user would meet that condition?

Options:

A.

Sarah


B.

Jan


C.

Tom


D.

Admin


Expert Solution
Questions # 2:

Which syntax will register a collector to the supervisor?

Options:

A.

phProvisionCollector --add


B.

phProvisionCollector --add


C.

phProvisionCollector --add


D.

phProvisionCollector --add


Expert Solution
Questions # 3:

Refer to the exhibit.

Question # 3

How long has the UEBA agent been operationally down?

Options:

A.

21 Hours


B.

9 Hours


C.

20 Hours


D.

2 Hours


Expert Solution
Questions # 4:

What are the modes of Data Ingestion on FortiSOAR? (Choose three.)

Options:

A.

Rule based


B.

Notification based


C.

App Push


D.

Policy based


E.

Schedule based


Expert Solution
Questions # 5:

Identify the processes associated with Machine Learning/Al on FortiSIEM. (Choose two.)

Options:

A.

phFortiInsightAI


B.

phReportMaster


C.

phRuleMaster


D.

phAnomaly


E.

phRuleWorker


Expert Solution
Questions # 6:

What is the disadvantage of automatic remediation?

Options:

A.

It can make a disruptive change to a user, block access to an application, or disconnect critical systems from the network.


B.

It is equivalent to running an IPS in monitor-only mode — watches but does not block.


C.

External threats or attacks detected by FortiSIEM will need user interaction to take action on an already overworked SOC team.


D.

Threat behaviors occurring during the night could take hours to respond to.


Expert Solution
Questions # 7:

Why can collectors not be defined before the worker upload address is set on the supervisor?

Options:

A.

Collectors can only upload data to a worker, and the supervisor is not a worker


B.

To ensure that the service provider has deployed at least one worker along with a supervisor


C.

Collectors receive the worker upload address during the registration process


D.

To ensure that the service provider has deployed a NFS server


Expert Solution
Questions # 8:

In the event of a WAN link failure between the collector and the supervisor, by default, what is the maximum number of event files stored on the collector?

Options:

A.

30.000


B.

10.000


C.

40.000


D.

20.000


Expert Solution
Questions # 9:

Refer to the exhibit.

Question # 9

Why was this incident auto cleared?

Options:

A.

Within five minutes the packet loss percentage dropped to a level where the reporting IP is the same as the host IP


B.

The original rule did not trigger within five minutes


C.

Within five minutes, the packet loss percentage dropped to a level where the reporting IP is same as the source IP


D.

Within five minutes, the packet loss percentage dropped to a level where the host IP of the original rule matches the host IP of the clear condition pattern


Expert Solution
Questions # 10:

Refer to the exhibit.

Question # 10

If the Z-score for this rule is greater than or equal to three, what does this mean?

Options:

A.

The rate of firewall connection is optimum.


B.

The rate of firewall connection is above the historical average value.


C.

The rate of firewall connection is above the current average value.


D.

The rate of firewall connection is below historical average value.


Expert Solution
Viewing page 1 out of 1 pages
Viewing questions 1-10 out of questions