Fortinet NSE7_ADA-6.3 Practice Test - Questions Answers, Page 4
List of questions
Related questions
Refer to the exhibit.
Why was this incident auto cleared?
A.
Within five minutes the packet loss percentage dropped to a level where the reporting IP is the same as the host IP
B.
The original rule did not trigger within five minutes
C.
Within five minutes, the packet loss percentage dropped to a level where the reporting IP is same as the source IP
D.
Within five minutes, the packet loss percentage dropped to a level where the host IP of the original rule matches the host IP of the clear condition pattern
From where does the rule engine load the baseline data values?
A.
The profile report
B.
The daily database
C.
The profile database
D.
The memory
Refer to the exhibit.
Which statement about the rule filters events shown in the exhibit is true?
A.
The rule filters events with an event type that belong to the Domain Account Locked CMDB group or a reporting IP that belong to the Domain Controller applications group.
B.
The rule filters events with an event type that belong to the Domain Account Locked CMDB group and a reporting |P that belong to the Domain Controller applications group.
C.
The rule filters events with an event type that belong to the Domain Account Locked CMDB group and a user that belongs to the Domain Controller applications group.
D.
The rule filters events with an event type that equals Domain Account Locked and a reporting IP that equals Domain Controller applications.
Refer to the exhibit.
Why is the windows device still in the CMDB, even though the administrator uninstalled the windows agent?
A.
The device was not uninstalled properly
B.
The device must be deleted from backend of FortiSIEM
C.
The device has performance jobs assigned
D.
The device must be deleted manually from the CMDB
Question