Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Pass the Fortinet Certified Professional Security Operations FCSS_ADA_AR-6.7 Questions and answers with ValidTests

Exam FCSS_ADA_AR-6.7 All Questions
Exam FCSS_ADA_AR-6.7 Premium Access

View all detail and faqs for the FCSS_ADA_AR-6.7 exam

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

What happens to UEBA events when a user is off-net?

Options:

A.

The agent will cache events locally if it cannot upload them to a FortiSIEM collector

B.

The agent will drop the events if it cannot upload them to a FortiSIEM collector

C.

The agent will upload the events to the Worker if it cannot upload them to a FortiSIEM collector

D.

The agent will upload the events the events to the Supervisor if it cannot upload them to a FortiSIEM collector

Expert Solution
Questions # 2:

Refer to the exhibit.

Question # 2

The service provider deployed FortiSIEM without a collector and added three customers on the supervisor.

What mistake did the administrator make?

Options:

A.

The number of workers on the FortiSIEM cluster must match the number of customers added

B.

Collectors must be deployed on all customer premises before they are added to organization on the supervisor.

C.

At least one collector must be deployed to collect logs from service provider infrastructure devices.

D.

Customer A and customer B have overlapping IP addresses.

Expert Solution
Questions # 3:

Which lookup table function can be either true or false?

Options:

A.

LookupTableHas

B.

LookupTableGet

C.

LookupTableFilter

D.

LookupTableRetriev

Expert Solution
Questions # 4:

A service provider purchases a licensed EPS of 520. The guaranteed EPS allocated to three customers is 50, 100, and 150 respectively. At the end of every three-minute interval, incoming EPS is calculated at every collector and the value is sent to the central decision-making engine on the supervisor node.

The incoming EPS for the first collector is 25. the incoming EPS for the second collector is 50, and the incoming EPS for the third collector is 75.

Based on the information provided, what is the unused events total calculated by the supervisor?

Options:

A.

76.000

B.

35.960

C.

75.960

D.

71.460

Expert Solution
Questions # 5:

Which three statements about collector communication with the FortiSIEM cluster are true? (Choose three.)

Options:

A.

Collectors communicate periodically with the supervisor node.

B.

The supervisor periodically checks the health of the collector.

C.

The only communication between the collector and the supervisor is during the registration process.

D.

The supervisor does not initiate any connections to the collector node.

E.

Collector upload event data to any node in the worker upload list, but report their health directly to the supervisor node.

Expert Solution
Questions # 6:

Refer to the exhibit.

Question # 6

Which workers are assigned tasks for the query ID13127? (Choose two.)

Options:

A.

Worker1 has no tasks for query ID 13127*.

B.

Worker1 has one task for query ID 13127*.

C.

Worker2 has two tasks for query ID 13127*.

D.

Worker3 has four tasks for query ID 13127*.

E.

Worker3 has two tasks for query ID 13127*.

Expert Solution
Questions # 7:

What are two functions of numpoints in a rule and profile database? (Choose two.)

Options:

A.

To prevent premature triggering of a rule before a baseline is set and becomes active

B.

To ensure that the data points do not exceed a threshold value

C.

To fetch only values from the profile database that have numPoints greater than a certain threshold

D.

To track the hour of the dayfor each data value

Expert Solution
Questions # 8:

Which three processes are collector processes? (Choose three.)

Options:

A.

phParser

B.

phAgentManager

C.

phMonitorAgent

D.

phReportMaster

E.

phRuleMaster

Expert Solution
Questions # 9:

Refer to the exhibit.

Question # 9

Which scenario is not a supported nested query scenario?

Options:

A.

The outer query is the event query, and the inner query is the event query.

B.

The outer query is the event query, and the inner query is the CMDB query.

C.

The outer query is the CMDB query, and the inner query is the event query.

D.

The outer query is the CMDB query, and the inner query is the CMDB query.

Expert Solution
Questions # 10:

Which three statements about phRuleMaster are true? (Choose three.)

Options:

A.

phRuleMaster is present on the supervisor only.

B.

phRuleMaster is present on the supervisor and workers.

C.

phRuleMaster queues up the data being received from the phRuleWorkers into buckets.

D.

phRuleMaster wakes up to evaluate all the rule data in parallel, every 30 seconds.

E.

phRuleMaster wakes up to evaluate all the rule data in series, every 30 seconds.

Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions