Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Fortinet FCSS_ADA_AR-6.7 - FCSS Advanced Analytics 6.7 Architect

Page: 1 / 2
Total 59 questions

Refer to the exhibit.

Which devices will be added to the CMDB and mapped to Customer E?

A.

10.50.0.150

B.

10.50.0.1

C.

10.60.0.1

D.

10.50.0.149

Refer to the exhibit.

Which workers are assigned tasks for the query ID13127? (Choose two.)

A.

Worker1 has no tasks for query ID 13127*.

B.

Worker1 has one task for query ID 13127*.

C.

Worker2 has two tasks for query ID 13127*.

D.

Worker3 has four tasks for query ID 13127*.

E.

Worker3 has two tasks for query ID 13127*.

FortiSIEM provides all rules with the ability to automatically change an active incident status to auto-cleared, based on an extra set of defined criteria.

Why would you configure FortiSIEM to automatically change an active incident status to auto-cleared?

A.

Because availability or performance-related problems may trigger a threshold temporarily.

B.

Because too many active incidents can spike the resource usaqe on FortiSIEM.

C.

Because you need a way to reduce a backlog of incident responses.

D.

Because some security-related incidents occur on a temporary basis.

Refer to the exhibit.

The profile database contains CPU utilization values from day one. At midnight on the second day, the CPU utilization values from the daily database will be merged with the profile database.

In the profile database, in theHour of Daycolumn where9is the value, what will be the updated minimum, maximum, and average CPU utilization values?

A.

Min CPU Util=32.31, Max CPU

Util=33.50 and AVG CPU

Util=32.67

B.

Min CPU Util=32.31, Max CPU

Util=32.31 and AVG CPU

Util=32.31

C.

Min CPU Util=32.31, Max CPU

Util=33.50 and AVG CPU

Util 33.50

D.

Min CPU Util=33.50, Max CPU

Util=33.50 and AVG CPU

Util=33.50

What happens to UEBA events when a user is off-net?

A.

The agent will cache events locally if it cannot upload them to a FortiSIEM collector

B.

The agent will drop the events if it cannot upload them to a FortiSIEM collector

C.

The agent will upload the events to the Worker if it cannot upload them to a FortiSIEM collector

D.

The agent will upload the events the events to the Supervisor if it cannot upload them to a FortiSIEM collector

Which three statements about phRuleMaster are true? (Choose three.)

A.

phRuleMaster is present on the supervisor only.

B.

phRuleMaster is present on the supervisor and workers.

C.

phRuleMaster queues up the data being received from the phRuleWorkers into buckets.

D.

phRuleMaster wakes up to evaluate all the rule data in parallel, every 30 seconds.

E.

phRuleMaster wakes up to evaluate all the rule data in series, every 30 seconds.

Refer to the exhibit.

The window for this rule is 30 minutes.

What is this rule tracking?

A.

A sudden 50% increase in WMI response times over a 30-minute time window

B.

A sudden 1.50 times increase in WMI response times over a 30-minute time window

C.

A sudden 150% increase in WMI response times over a 30-minute time window

D.

A sudden 75% increase in WMI response times over a 30-minute time window

Which three processes are collector processes? (Choose three.)

A.

phParser

B.

phAgentManager

C.

phMonitorAgent

D.

phReportMaster

E.

phRuleMaster

Refer to the exhibit.

An administrator deploys a new collector for the first time, and notices that all the processes expect the phMonitor are down.

How can the administrator bring the processes up?

A.

The collector was not deployed properly and must be redeployed.

B.

The administrator needs to run the command phtools - start all on the collector.

C.

Rebooting the collector will bring up the processes.

D.

The processes will come up after the collector is registered to the supervisor.

Which two statements about phRuleWorker are true? (Choose two.)

A.

phRuleWorker uses a 60-second bucket as an evaluation window.

B.

phRuleWorker evaluates non-aggregate conditions as defined in subpattern filters of a rule in memory.

C.

phRuleWorker exists on both the supervisor and workers.

D.

phRuleWorker exists on the worker only.