Which two statements about the maximum device limit on FortiSIEM are true? (Choose two.)
A. The device limit is defined per customer and every customer is assigned a fixed number of device limit by the service provider.
B. The device limit is only applicable to enterprise edition.
C. The device limit is based on the license type that was purchased from Fortinet.
D. The device limit is defined for the whole system and is shared by every customer on a service provider edition.
Refer to the exhibit.
Why was this incident auto cleared?
A. Within five minutes the packet loss percentage dropped to a level where the reporting IP is the same as the host IP
B. The original rule did not trigger within five minutes
C. Within five minutes, the packet loss percentage dropped to a level where the reporting IP is same as the source IP
D. Within five minutes, the packet loss percentage dropped to a level where the host IP of the original rule matches the host IP of the clear condition pattern
Refer to the exhibit.
How long has the UEBA agent been operationally down?
A. 21 Hours
B. 9 Hours
C. 20 Hours
D. 2 Hours
Refer to the exhibit. Click on the calculator button.
The profile database contains CPU utilization values from day one. At midnight on the second day, the CPU utilization values from the daily database will be merged with the profile database.
In the profile database, in the Hour of Day column where 9 is the value, what will be the updated minimum, maximum, and average CPU utilization values?
A. Min CPU Util=32.31, Max CPU Ucil=33.50 and AVG CPU Util=33.50
B. Min CPU Util=32.31, Max CPU Ucil=33.50 and AVG CPU Util=32.67
C. Min CPU Util=32.31, Max CPU Ucil=32.31 and AVG CPU Util=32.31
D. Min CPU Util=33.50, Max CPU Ucil=33.50 and AVG CPU Util=33.50
Which of the following are two Tactics in the MITRE ATTandCK framework? (Choose two.)
A. Root kit
B. Reconnaissance
C. Discovery
D. BITS Jobs
E. Phishing
Refer to the exhibit.
An administrator wants to remediate the incident from FortiSIEM shown in the exhibit.
What option is available to the administrator?
A. Quarantine IP FortiClient
B. Run the block MAC FortiOS.
C. Run the block IP FortiOS 5.4
D. Run the block domain Windows DNS
How can you empower SOC by deploying FortiSOAR? (Choose three.)
A. Aggregate logs from distributed systems
B. Collaborative knowledge sharing
C. Baseline user and traffic behavior
D. Reduce human error
E. Address analyst skills gap
What are the modes of Data Ingestion on FortiSOAR? (Choose three.)
A. Rule based
B. Notification based
C. App Push
D. Policy based
E. Schedule based
Which statement about EPS bursting is true?
A. FortiSIEM will let you burst up to five times the licensed EPS once during a 24-hour period.
B. FortiSIEM must be provisioned with ten percent the licensed EPS to handle potential event surges.
C. FortiSIEM will let you burst up to five times the licensed EPS at any given time, provided it has accumulated enough unused EPS.
D. FortiSIEM will let you burst up to five times the licensed EPS at any given time, regardless of unused of EPS.
Which three statements about phRuleMaster are true? (Choose three.)
A. phRuleMaster queues up the data being received from the phRuleWorkers into buckets.
B. phRuleMaster is present on the supervisor and workers.
C. phRuleMaster is present on the supervisor only
D. phRuleMaster wakes up to evaluate all the rule data in series, every 30 seconds.
E. phRuleMaster wakes up to evaluate all the rule data in parallel, even/ 30 seconds