11.11 Special Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

NSE7_ADA-6.3 Exam Dumps - Fortinet NSE 7 - Advanced Analytics 6.3

Question # 4

Refer to the exhibit.

An administrator runs an analytic search for all FortiGate SSL VPN logon failures. The results are grouped by source IP, reporting IP, and user. The administrator wants to restrict the results to only those rows where the COUNT >= 3.

Which user would meet that condition?

A.

Sarah

B.

Jan

C.

Tom

D.

Admin

Full Access
Question # 5

Refer to the exhibit. Click on the calculator button.

Based on the information provided in the exhibit, calculate the unused events for the next three minutes for a 520 EPS license.

A.

72460

B.

73460

C.

74460

D.

71460

Full Access
Question # 6

How do customers connect to a shared multi-tenant instance on FortiSOAR?

A.

The MSSP must provide secure network connectivity between the FortiSOAR manager node and the customer devices.

B.

The MSSP must install a Secure Message Exchange node to connect to the customer's shared multi-tenant instance.

C.

The customer must install a tenant node to connect to the MSSP shared multi-tenant instance.

D.

The MSSP must install an agent node on the customer's network to connect to the customer's shared multi-tenant instance.

Full Access
Question # 7

Refer to the exhibit.

An administrator deploys a new collector for the first time, and notices that all the processes except the phMonitor are down.

How can the administrator bring the processes up?

A.

The administrator needs to run the command phtools --start all on the collector.

B.

Rebooting the collector will bring up the processes.

C.

The processes will come up after the collector is registered to the supervisor.

D.

The collector was not deployed properly and must be redeployed.

Full Access
Question # 8

Identify the processes associated with Machine Learning/Al on FortiSIEM. (Choose two.)

A.

phFortiInsightAI

B.

phReportMaster

C.

phRuleMaster

D.

phAnomaly

E.

phRuleWorker

Full Access
Question # 9

Refer to the exhibit.

Is the Windows agent delivering event logs correctly?

A.

The logs are buffered by the agent and will be sent once the status changes to managed.

B.

The agent is registered and it is sending logs correctly.

C.

The agent is not sending logs because it did not receive a monitoring template.

D.

Because the agent is unmanaged. the logs are dropped silently by the supervisor.

Full Access
Question # 10

Refer to the exhibit.

Which statement about the rule filters events shown in the exhibit is true?

A.

The rule filters events with an event type that belong to the Domain Account Locked CMDB group or a reporting IP that belong to the Domain Controller applications group.

B.

The rule filters events with an event type that belong to the Domain Account Locked CMDB group and a reporting |P that belong to the Domain Controller applications group.

C.

The rule filters events with an event type that belong to the Domain Account Locked CMDB group and a user that belongs to the Domain Controller applications group.

D.

The rule filters events with an event type that equals Domain Account Locked and a reporting IP that equals Domain Controller applications.

Full Access