Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Pass the Fortinet Certified Professional Security Operations FCP_FSM_AN-7.2 Questions and answers with ValidTests

Exam FCP_FSM_AN-7.2 All Questions
Exam FCP_FSM_AN-7.2 Premium Access

View all detail and faqs for the FCP_FSM_AN-7.2 exam

Viewing page 1 out of 1 pages
Viewing questions 1-10 out of questions
Questions # 1:

Refer to the exhibit.

Question # 1

An analyst is trying to identify an issue using an expression based on the Expression Builder settings shown in the exhibit; however, the error message shown in the exhibit indicates that the expression is invalid.

What is the correct syntax to create an expression that generates a total count of matched events?

Options:

A.

COUNT(Matched Events)

B.

(COUNT) Matched Events

C.

Matched Events (COUNT)

D.

Matched Events COUNT()

Expert Solution
Questions # 2:

Which running mode takes the most time to perform machine learning tasks?

Options:

A.

Local auto

B.

Local

C.

Forecasting

D.

Regression

Expert Solution
Questions # 3:

Refer to the exhibit.

Question # 3

What happens when an analyst clears an incident generated by a rule containing the automation policy shown in the exhibit?

Options:

A.

No notification is sent.

B.

An email is sent to the SOC manager.

C.

The remediation script is run.

D.

A notification is sent to the SOC manager dashboard.

Expert Solution
Questions # 4:

Refer to the exhibit.

Question # 4

Which value would you expect the FortiSIEM parser to use to populate the Application Name field?

Options:

A.

applist

B.

Network.Service

C.

SSL

D.

wan1

Expert Solution
Questions # 5:

Refer to the exhibit.

Question # 5

Which two lookup types can you reference as the subquery in a nested analytics query? (Choose two.)

Options:

A.

LDAP Query

B.

CMDB Query

C.

SNMP Query

D.

Event Query

Expert Solution
Questions # 6:

Refer to the exhibit.

Question # 6

What will happen when a device being analyzed by the machine learning configuration shown in the exhibit has a consistently high memory utilization?

Options:

A.

FortiSIEM will update the regression tables for memory utilization, and average sent and received bytes.

B.

FortiSIEM will trigger an incident for high memory utilization.

C.

FortiSIEM will lower the CPU utilization trigger requirement for CPU utilization.

D.

FortiSIEM will update the model with a higher memory utilization average value.

Expert Solution
Questions # 7:

Refer to the exhibit.

Question # 7

How was this incident cleared?

Options:

A.

The analyst manually cleared the incident from the incident table.

B.

FortiSIEM cleared the incident automatically after 24 hours.

C.

The incident was cleared automatically by the rule.

D.

The endpoint was rebooted and sent an all-clear signal to FortiSIEM.

Expert Solution
Questions # 8:

Refer to the exhibit.

Question # 8

If you group the events by Reporting Device, Reporting IP, and Application Category, how many results will FortiSIEM display?

Options:

A.

Four

B.

Five

C.

One

D.

Six

E.

Two

Expert Solution
Questions # 9:

Refer to the exhibit.

Question # 9

What is the Group: FortiSIEM Analysts value referring to?

Options:

A.

FortiSIEM organization group

B.

LDAP user group

C.

CMDB user group

D.

Windows Active Directory user group

Expert Solution
Viewing page 1 out of 1 pages
Viewing questions 1-10 out of questions