Fortinet FCSS_ADA_AR-6.7 Practice Test - Questions Answers, Page 6

List of questions
Question 51

Which three processes are collector processes? (Choose three.)
Question 52

Refer to the exhibit.
Consider a custom lookup table MalwareIPList. An analyst constructed an analytic query to reference the MalwareIPList lookup table.
What is the outcome of the analytic query?
Question 53

Which three statements about phRuleMaster are true? (Choose three.)
Question 54

Refer to the exhibit.
The service provider deployed FortiSIEM without a collector and added three customers on the supervisor.
What mistake did the administrator make?
Question 55

Where are the SQLite databases that are used for the baselining, stored?
Question 56

Refer to the exhibit.
If the Z-score for this rule is greater than or equal to three, what does this mean?
Question 57

Refer to the exhibit.
An administrator wants to remediate the incident from FortiSIEM shown in the exhibit.
What option is available to the administrator?
Question 58

Refer to the exhibit.
Is the Windows agent delivering event logs correctly?
Question 59

Refer to the exhibit.
An administrator runs an analytic search for all FortiGate SSL VPN logon failures. The results are grouped by source IP, reporting IP, and user. The administrator wants to restrict the results to only those rows where the COUNT >=3.
Which user would meet that condition?
Question