Fortinet FCSS_ADA_AR-6.7 - FCSS-Advanced Analytics 6.7 Architect Exam

Question #11 (Topic: Exam A)
Refer to the exhibit.

Which devices will be added to the CMDB and mapped to Customer E?
A. 10.50.0.150 B. 10.50.0.1 C. 10.60.0.1 D. 10.50.0.149
Answer: BD
Question #12 (Topic: Exam A)
Refer to the exhibit.

An administrator applies the rule exception shown in the exhibit.
How does this configuration impact the incident generation for that rule?
A. Incidents will not be generated during the specified period. B. Incidents will be generated only during the specified period. C. Incidents will be generated without triggering an email alert during the specified
period.
D. Events will not be processed by the rule during the specified period.
Answer: A
Question #13 (Topic: Exam A)
Which two statements about phRuleWorker are true? (Choose two.)
A. phRuleWorker uses a 60-second bucket as an evaluation window. B. phRuleWorker evaluates non-aggregate conditions as defined in subpattern filters of a rule in memory. C. phRuleWorker exists on both the supervisor and workers. D. phRuleWorker exists on the worker only.
Answer: AC
Question #14 (Topic: Exam A)
Refer to the exhibit.

Which three fields from the organization destination are required while registering a collector? (Choose three.)
A. Account Number B. Admin Password C. Agent Password D. Organization E. Admin User
Answer: BDE
Question #15 (Topic: Exam A)
FortiSIEM provides all rules with the ability to automatically change an active incident status to auto-cleared, based on an extra set of defined criteria.
Why would you configure FortiSIEM to automatically change an active incident status to auto-cleared?
A. Because availability or performance-related problems may trigger a threshold temporarily. B. Because too many active incidents can spike the resource usage on FortiSIEM. C. Because you need a way to reduce a backlog of incident responses. D. Because some security-related incidents occur on a temporary basis.
Answer: A
Download Exam
Page: 3 / 12
Total 59 questions