ExamGecko
Question list
Search
Search

Question 19 - NSE5_FSM-6.3 discussion

Report
Export

An administrator defines SMTP as a critical process on a Linux server.

It the SMTP process is stopped. FortiSIEM will generate a critical event with which event type?

A.
Postfix-Mail-Stop
Answers
A.
Postfix-Mail-Stop
B.
PH_DEV_MON_PROC_STOP
Answers
B.
PH_DEV_MON_PROC_STOP
C.
PH_DEV_MON_SMTP_STOP
Answers
C.
PH_DEV_MON_SMTP_STOP
D.
Generic_SMTP_Procoss_Exit
Answers
D.
Generic_SMTP_Procoss_Exit
Suggested answer: B

Explanation:

Process Monitoring in FortiSIEM: FortiSIEM can monitor critical processes on managed devices, such as an SMTP process on a Linux server.

Event Generation: When a critical process stops, FortiSIEM generates an event to alert administrators.

Event Types: Specific event types correspond to different monitored conditions. For a stopped process, the event type PH_DEV_MON_PROC_STOP is used.

Reasoning: The name PH_DEV_MON_PROC_STOP (Device Monitoring Process Stop) is a generic event type used by FortiSIEM to indicate that any monitored process, including SMTP, has stopped.

Reference: FortiSIEM 6.3 User Guide, Event Types section, explains the predefined event types and their usage in different monitoring scenarios.

asked 18/09/2024
Bob Hanselman
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first