ExamGecko
Question list
Search
Search

Question 23 - NSE5_FSM-6.3 discussion

Report
Export

In FortiSIEM enterprise licensing mode, it the link between the collector and data center FortiSlEM cluster is down, what happens?

A.
The collector drops incoming events like syslog. but stops performance collection.
Answers
A.
The collector drops incoming events like syslog. but stops performance collection.
B.
The collector processes stop, and events ate dropped.
Answers
B.
The collector processes stop, and events ate dropped.
C.
The collector continues performance collection of devices, but slops receiving syslog.
Answers
C.
The collector continues performance collection of devices, but slops receiving syslog.
D.
The collector buffers events
Answers
D.
The collector buffers events
Suggested answer: C

Explanation:

Enterprise Licensing Mode: In FortiSIEM enterprise licensing mode, collectors are deployed in remote sites to gather and forward data to the central FortiSIEM cluster located in the data center.

Collector Functionality: Collectors are responsible for receiving logs, events (e.g., syslog), and performance metrics from devices.

Link Down Scenario: When the link between the collector and the FortiSIEM cluster is down, the collector needs a mechanism to ensure no data is lost during the disconnection.

Event Buffering: The collector buffers the events locally until the connection is restored, ensuring that no incoming events are lost. This buffered data is then forwarded to the FortiSIEM cluster once the link is re-established.

Reference: FortiSIEM 6.3 User Guide, Data Collection and Buffering section, explains the behavior of collectors during network disruptions.

asked 18/09/2024
Tatiana Castillo
29 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first