Special Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Question # 4

Which lookup table function can be either true or false?

A.

LookupTableHas

B.

LookupTableGet

C.

LookupTableFilter

D.

LookupTableRetriev

Full Access
Question # 5

Refer to the exhibit.

Which deployment type is shown in the exhibit?

A.

Service provider with collectors

B.

Service provider without collectors

C.

Hybrid deployment with and without collectors

D.

Enterprise cloud deployment

Full Access
Question # 6

When you perform a Group By on a structured query, which two outcomes occur? (Choose two.)

A.

Group By automatically applies a COUNT aggregation.

B.

Group By is applied to real-time and historical searches.

C.

Group By cannot be applied to an aggregated function.

D.

Group By is applied to historical searches only.

Full Access
Question # 7

Refer to the exhibit.

What are three possible reasons why theAgent StatusdisplaysRunning Inactive? (Choose three.)

A.

The agent was registered incorrectly

B.

The collector was not assigned to the agent

C.

The agent is temporarily down

D.

The template was not assigned

E.

The template was removed

Full Access
Question # 8

Refer to the exhibit.

A service provider does not have a dedicated worker in the cluster, but still wants to add a collector to an organization.

What option does the administrator have?

A.

Define a pseudo address as a worker IP address

B.

Install a worker

C.

Ignore the warning and continue adding the collector

D.

Define the supervisorIP address as a worker unload address

Full Access
Question # 9

How do customers connect to a shared multi-tenant instance on FortiSOAR?

A.

The customer must install a tenant node to connect to the MSSP shared multi-tenant instance.

B.

The MSSP must provide secure network connectivity between the FortiSOAR manager node and the customer devices.

C.

The MSSP must install a Secure Message Exchange node to connect to the customer’s shared multi-tenant instance.

D.

The MSSP must install an agent node on the customer’s network to connect to the customer's shared multi-tenant instance.

Full Access
Question # 10

Refer to the exhibit.

An administrator applies the rule exception shown in the exhibit.

How does this configuration impact the incident generation for that rule?

A.

Incidents will not be generated during the specified period.

B.

Incidents will be generated only during the specified period.

C.

Incidents will be generated without triggering an email alert during the specified period.

D.

Events will not be processed by the rule during the specified period.

Full Access
Question # 11

Where are the SQLite databases that are used for the baselining, stored?

A.

/opt/phoenix/cache

B.

/opt/phoenix/bin

C.

/opt/phoenix/config

D.

/opt/phoenix/delta

Full Access
Question # 12

Refer to the exhibit.

Which devices will be added to the CMDB and mapped to Customer E?

A.

10.50.0.150

B.

10.50.0.1

C.

10.60.0.1

D.

10.50.0.149

Full Access
Question # 13

Refer to the exhibit.

This is an example of a baseline profile that is configured in the backend of FortiSIEM.

Which two Group By attributes are configured for this profile? (Choose two.)

A.

Logon Failure

B.

Reporting Device

C.

Reporting IP

D.

Distinct User

Full Access
Question # 14

Refer to the exhibit.

The collector is registered and has pulled the license file from the supervisor.

What are the consequences of removing the license file?

A.

The collector must be re-registered with the supervisor to get the license file back.

B.

The collector processes will go down.

C.

The collector must be redeployed to get the license file back.

D.

The license file must be pushed manually from the supervisor.

Full Access
Question # 15

Refer to the exhibit.

The window for this rule is 30 minutes.

What is this rule tracking?

A.

A sudden 50% increase in WMI response times over a 30-minute time window

B.

A sudden 1.50 times increase in WMI response times over a 30-minute time window

C.

A sudden 150% increase in WMI response times over a 30-minute time window

D.

A sudden 75% increase in WMI response times over a 30-minute time window

Full Access
Question # 16

Which statement about EPS bursting is true?

A.

FortiSIEM will let you burst up to five times the licensed EPS at any given time, provided it has accumulated enough unused EPS.

B.

FortiSIEM will let you burst up to five times the licensed EPS once during a 24-hour period.

C.

FortiSIEM will let you burst up to five times the licensed EPS at any given time, regardless of unused of EPS.

D.

FortiSIEM must be provisioned with ten percent the licensed EPS to handle potential event surges.

Full Access
Question # 17

From where does the rule engine load the baseline data values?

A.

The memory

B.

The profile report

C.

The profile database

D.

The daily database

Full Access