Black Friday Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70special

Fortinet NSE7_ADA-6.3 Fortinet NSE 7 - Advanced Analytics 6.3 Exam Practice Test

Fortinet NSE 7 - Advanced Analytics 6.3 Questions and Answers

Testing Engine

  • Product Type: Testing Engine
$37.5  $124.99

PDF Study Guide

  • Product Type: PDF Study Guide
$33  $109.99
Question 1

From where does the rule engine load the baseline data values?

Options:

A.

The profile report

B.

The daily database

C.

The profile database

D.

The memory

Question 2

Which syntax will register a collector to the supervisor?

Options:

A.

phProvisionCollector --add

B.

phProvisionCollector --add

C.

phProvisionCollector --add

D.

phProvisionCollector --add

Question 3

Refer to the exhibit.

Why was this incident auto cleared?

Options:

A.

Within five minutes the packet loss percentage dropped to a level where the reporting IP is the same as the host IP

B.

The original rule did not trigger within five minutes

C.

Within five minutes, the packet loss percentage dropped to a level where the reporting IP is same as the source IP

D.

Within five minutes, the packet loss percentage dropped to a level where the host IP of the original rule matches the host IP of the clear condition pattern

Question 4

Refer to the exhibit.

Is the Windows agent delivering event logs correctly?

Options:

A.

The logs are buffered by the agent and will be sent once the status changes to managed.

B.

The agent is registered and it is sending logs correctly.

C.

The agent is not sending logs because it did not receive a monitoring template.

D.

Because the agent is unmanaged. the logs are dropped silently by the supervisor.

Question 5

How do customers connect to a shared multi-tenant instance on FortiSOAR?

Options:

A.

The MSSP must provide secure network connectivity between the FortiSOAR manager node and the customer devices.

B.

The MSSP must install a Secure Message Exchange node to connect to the customer's shared multi-tenant instance.

C.

The customer must install a tenant node to connect to the MSSP shared multi-tenant instance.

D.

The MSSP must install an agent node on the customer's network to connect to the customer's shared multi-tenant instance.

Question 6

Refer to the exhibit.

Why is the windows device still in the CMDB, even though the administrator uninstalled the windows agent?

Options:

A.

The device was not uninstalled properly

B.

The device must be deleted from backend of FortiSIEM

C.

The device has performance jobs assigned

D.

The device must be deleted manually from the CMDB

Question 7

How can you invoke an integration policy on FortiSIEM rules?

Options:

A.

Through Notification Policy settings

B.

Through Incident Notification settings

C.

Through remediation scripts

D.

Through External Authentication settings

Question 8

Which three statements about collector communication with the FortiSIEM cluster are true? (Choose three.)

Options:

A.

The only communication between the collector and the supervisor is during the registration process.

B.

Collectors communicate periodically with the supervisor node.

C.

The supervisor periodically checks the health of the collector.

D.

The supervisor does not initiate any connections to the collector node.

E.

Collectors upload event data to any node in the worker upload list, but report their health directly to the supervisor node.

Question 9

What is the disadvantage of automatic remediation?

Options:

A.

It can make a disruptive change to a user, block access to an application, or disconnect critical systems from the network.

B.

It is equivalent to running an IPS in monitor-only mode — watches but does not block.

C.

External threats or attacks detected by FortiSIEM will need user interaction to take action on an already overworked SOC team.

D.

Threat behaviors occurring during the night could take hours to respond to.

Question 10

Refer to the exhibit.

If the Z-score for this rule is greater than or equal to three, what does this mean?

Options:

A.

The rate of firewall connection is optimum.

B.

The rate of firewall connection is above the historical average value.

C.

The rate of firewall connection is above the current average value.

D.

The rate of firewall connection is below historical average value.