Special Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70special

Fortinet FCSS_ADA_AR-6.7 FCSS Advanced Analytics 6.7 Architect Exam Practice Test

FCSS Advanced Analytics 6.7 Architect Questions and Answers

Testing Engine

  • Product Type: Testing Engine
$37.5  $124.99

PDF Study Guide

  • Product Type: PDF Study Guide
$33  $109.99
Question 1

For what type of data values does the rule engine query the profile database?

Options:

A.

High and/or low values for the current hour of the day

B.

Minimum and/or maximum values for the current hour of the day

C.

First and/or last values for the current hour of the day

D.

Statistical average and/or standard deviation values for the current hour of the day

Question 2

Where are the SQLite databases that are used for the baselining, stored?

Options:

A.

/opt/phoenix/cache

B.

/opt/phoenix/bin

C.

/opt/phoenix/config

D.

/opt/phoenix/delta

Question 3

Refer to the exhibit.

Is the Windows agent delivering event logs correctly?

Options:

A.

The agent is registered and it is sending logs correctly.

B.

The logs are buffered by the agent and will be sent once the status changes to managed.

C.

Because the agent is unmanaged. the logs are dropped silently by the supervisor.

D.

The agent is not sending logs because it did not receive a monitoring template.

Question 4

Which three processes are collector processes? (Choose three.)

Options:

A.

phParser

B.

phAgentManager

C.

phMonitorAgent

D.

phReportMaster

E.

phRuleMaster

Question 5

Refer to the exhibit.

Which three fields from the organization destination are required while registering a collector? (Choose three.)

Options:

A.

Account Number

B.

Admin Password

C.

Agent Password

D.

Organization

E.

Admin User

Question 6

What is the hourly bucket used in baselining?

Options:

A.

To store hourly baselines reports for every hour of the day during weekdays and weekends

B.

To store data for specific baselines during the weekend, if there is a spike in network activity

C.

To store data for specific baselines during peak business hours of weekdays

D.

To store data for specific baselines for every hour of the day during weekdays and weekends

Question 7

Refer to the exhibit.

The profile database contains CPU utilization values from day one. At midnight on the second day, the CPU utilization values from the daily database will be merged with the profile database.

In the profile database, in theHour of Daycolumn where9is the value, what will be the updated minimum, maximum, and average CPU utilization values?

Options:

A.

Min CPU Util=32.31, Max CPU

Util=33.50 and AVG CPU

Util=32.67

B.

Min CPU Util=32.31, Max CPU

Util=32.31 and AVG CPU

Util=32.31

C.

Min CPU Util=32.31, Max CPU

Util=33.50 and AVG CPU

Util 33.50

D.

Min CPU Util=33.50, Max CPU

Util=33.50 and AVG CPU

Util=33.50

Question 8

Refer to the exhibit.

Which deployment type is shown in the exhibit?

Options:

A.

Service provider with collectors

B.

Service provider without collectors

C.

Hybrid deployment with and without collectors

D.

Enterprise cloud deployment

Question 9

Which statement about EPS bursting is true?

Options:

A.

FortiSIEM will let you burst up to five times the licensed EPS at any given time, provided it has accumulated enough unused EPS.

B.

FortiSIEM will let you burst up to five times the licensed EPS once during a 24-hour period.

C.

FortiSIEM will let you burst up to five times the licensed EPS at any given time, regardless of unused of EPS.

D.

FortiSIEM must be provisioned with ten percent the licensed EPS to handle potential event surges.

Question 10

Refer to the exhibit.

If the Z-score for this rule is greater than or equal to three, what does this mean?

Options:

A.

The rate of firewall connection is below historical average value.

B.

The rate of firewall connection is optimum.

C.

The rate firewall connection is above the historical average value.

D.

The rate of firewall connection is above the current average value.

Question 11

Refer to the exhibit.

The rule evaluates multiple VPN logon failures within a ten-minute window. Consider the following VPN failure events received within a ten-minute window:

How many incidents are generated?

Options:

A.

1

B.

2

C.

0

D.

3

Question 12

Which organization do agents belong to after registration? (Choose two.)

Options:

A.

The windows agents belong to the super organization.

B.

The agents belong to the organization specified in the agent installation setup wizard for Windows platforms.

C.

The Linux agents belong to the super local organization.

D.

The agents belong to the organization specified in the command line parameters for Linux platforms.

Question 13

Which three statements about collector communication with the FortiSIEM cluster are true? (Choose three.)

Options:

A.

Collectors communicate periodically with the supervisor node.

B.

The supervisor periodically checks the health of the collector.

C.

The only communication between the collector and the supervisor is during the registration process.

D.

The supervisor does not initiate any connections to the collector node.

E.

Collector upload event data to any node in the worker upload list, but report their health directly to the supervisor node.

Question 14

How can you empower SOC by deploying FortiSOAR? (Choose three.)

Options:

A.

Collaborative knowledge sharing

B.

Aggregate logs from distributed systems

C.

Address analyst skills gap

D.

Baseline user and traffic behavior

E.

Reduce human error

Question 15

Refer to the exhibit.

An administrator deploys a new collector for the first time, and notices that all the processes expect the phMonitor are down.

How can the administrator bring the processes up?

Options:

A.

The collector was not deployed properly and must be redeployed.

B.

The administrator needs to run the command phtools - start all on the collector.

C.

Rebooting the collector will bring up the processes.

D.

The processes will come up after the collector is registered to the supervisor.

Question 16

How do customers connect to a shared multi-tenant instance on FortiSOAR?

Options:

A.

The customer must install a tenant node to connect to the MSSP shared multi-tenant instance.

B.

The MSSP must provide secure network connectivity between the FortiSOAR manager node and the customer devices.

C.

The MSSP must install a Secure Message Exchange node to connect to the customer’s shared multi-tenant instance.

D.

The MSSP must install an agent node on the customer’s network to connect to the customer's shared multi-tenant instance.

Question 17

Which syntax will register a collector to the supervisor?

Options:

A.

phProvisionCollector -add

B.

phProvisionCollector -add

C.

phProvisionCollector -add

D.

phProvisionCollector -add