Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: ecus65

Fortinet FCSS_ADA_AR-6.7 - FCSS Advanced Analytics 6.7 Architect

Page: 2 / 2
Total 59 questions

What happens to events that the collector receives when there is a WAN link failure between the collector and the supervisor?

A.

Events are buffered for up to 24 hours.

B.

Events are buffered up to 10 MB before compression.

C.

Events are buffered up to 10.000 logs.

D.

Events are buffered up to 1 GB after compression.

Refer to the exhibit.

How long has the UEBA agent been operationally down?

A.

2 Hours

B.

20 Hours

C.

21 Hours

D.

9 Hours

Where are the SQLite databases that are used for the baselining, stored?

A.

/opt/phoenix/cache

B.

/opt/phoenix/bin

C.

/opt/phoenix/config

D.

/opt/phoenix/delta

Refer to the exhibit.

An administrator runs an analytic search for all FortiGate SSL VPN logon failures. The results are grouped by source IP, reporting IP, and user. The administrator wants to restrict the results to only those rows where the COUNT >=3.

Which user would meet that condition?

A.

Jan

B.

Sarah

C.

Admin

D.

Tom

Why do collectors communicate with the Supervisor after registration? (Choose two.)

A.

To receive templates associated with agents

B.

To report the health status of the agents

C.

To upload event data if a worker down

D.

To report its own health status

In a customer network that includes a collector, which device performs device discoveries?

A.

Agent

B.

Supervisor

C.

Worker

D.

Collector

Refer to the exhibit.

Which scenario is not a supported nested query scenario?

A.

The outer query is the event query, and the inner query is the event query.

B.

The outer query is the event query, and the inner query is the CMDB query.

C.

The outer query is the CMDB query, and the inner query is the event query.

D.

The outer query is the CMDB query, and the inner query is the CMDB query.