Fortinet FCSS_ADA_AR-6.7 Practice Test - Questions Answers, Page 2

List of questions
Question 11

Refer to the exhibit.
Which devices will be added to the CMDB and mapped to Customer E?
Question 12

Refer to the exhibit.
An administrator applies the rule exception shown in the exhibit.
How does this configuration impact the incident generation for that rule?
Question 13

Which two statements about phRuleWorker are true? (Choose two.)
Question 14

Refer to the exhibit.
Which three fields from the organization destination are required while registering a collector? (Choose three.)
Question 15

FortiSIEM provides all rules with the ability to automatically change an active incident status to auto-cleared, based on an extra set of defined criteria.
Why would you configure FortiSIEM to automatically change an active incident status to auto-cleared?
Question 16

For what type of data values does the rule engine query the profile database?
Question 17

Which organization do agents belong to after registration? (Choose two.)
Question 18

What is the hourly bucket used in baselining?
Question 19

What are two functions of numpoints in a rule and profile database? (Choose two.)
Question 20

Refer to the exhibit.
Consider the five account locked events received by FortiSIEM from domain controllers within the last 10 minutes (ten minutes is the evaluation window for the subpattern DomainAcctLockout):
If you look for one or more matching events and groupings by the same reporting IP address, reporting device, and user, how many incidents are created?
Question