FCSS_ADA_AR-6.7 Exam Questions
69 real FCSS_ADA_AR-6.7 exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1
A service provider purchases a licensed EPS of 520. The guaranteed EPS allocated to three customers is 50, 100, and 150 respectively. At the end of every three-minute interval, inc...
- Question #2
Which statement accurately contrasts lookup tables with watchlists?
- Question #3
Refer to the exhibit. How long has the UEBA agent been operationally down?
- Question #4
How can you empower SOC by deploying FortiSOAR? (Choose three.)
- Question #5
Refer to the exhibit. This is an example of a baseline profile that is configured in the backend of FortiSIEM. Which two Group By attributes are configured for this profile? (Choos...
- Question #6
Refer to the exhibit. Which scenario is not a supported nested query scenario?
- Question #7
When you perform a Group By on a structured query, which two outcomes occur? (Choose two.)
- Question #8
Refer to the exhibit. Within what time window is the incident auto cleared?
- Question #9
Refer to the exhibit. Which statement about the rule filters events shown in the exhibit is true?
- Question #10
Refer to the exhibit. Why was this incident auto cleared?
- Question #11
Refer to the exhibit. Which devices will be added to the CMDB and mapped to Customer E?
- Question #12
Refer to the exhibit. An administrator applies the rule exception shown in the exhibit. How does this configuration impact the incident generation for that rule?
- Question #13
Which two statements about phRuleWorker are true? (Choose two.)
- Question #14
Refer to the exhibit. Which three fields from the organization destination are required while registering a collector? (Choose three.)
- Question #15
FortiSIEM provides all rules with the ability to automatically change an active incident status to auto- cleared, based on an extra set of defined criteria. Why would you configure...
- Question #16
For what type of data values does the rule engine query the profile database?
- Question #17
Which organization do agents belong to after registration? (Choose two.)
- Question #18
What is the hourly bucket used in baselining?
- Question #19
What are two functions of numpoints in a rule and profile database? (Choose two.)
- Question #20
Refer to the exhibit. Consider the five account locked events received by FortiSIEM from domain controllers within the last 10 minutes (ten minutes is the evaluation window for the...
- Question #21
How do customers connect to a shared multi-tenant instance on FortiSOAR?
- Question #22
How can you customize the AI model on FortiSIEM?
- Question #23
Refer to the exhibit. Which deployment type is shown in the exhibit?
- Question #24
Refer to the exhibit. What are three possible reasons why the Agent Status displays Running Inactive? (Choose three.)
- Question #25
What happens to events that the collector receives when there is a WAN link failure between the collector and the supervisor?
- Question #26
Refer to the exhibit. The collector is registered and has pulled the license file from the supervisor. What are the consequences of removing the license file?
- Question #27
What are the modes of Data Ingestion on FortiSOAR? (Choose three.)
- Question #28
Why do collectors communicate with the Supervisor after registration? (Choose two.)
- Question #29
A service provider purchased a 500-EPS license and configured a new collector with 100 EPS for customer A, and another collector with 200 EPS for customer B. How much is in the rem...
- Question #30
Refer to the exhibit. A service provider does not have a dedicated worker in the cluster, but still wants to add a collector to an organization. What option does the administrator...
- Question #31
In a customer network that includes a collector, which device performs device discoveries?
- Question #32
Refer to the exhibit. Why is the windows device still in the CMDB, even though the administrator uninstalled the windows agent?
- Question #33
Refer to the exhibit. An administrator deploys a new collector for the first time, and notices that all the processes expect the phMonitor are down. How can the administrator bring...
- Question #34
Which syntax will register a collector to the supervisor?
- Question #35
How can you invoke an integration policy on FortiSIEM rules?
- Question #36
Why can collectors not be defined before the worker upload address is set on the supervisor?
- Question #37
Refer to the exhibit. The profile database contains CPU utilization values from day one. At midnight on the second day, the CPU utilization values from the daily database will be m...
- Question #38
Which lookup table function can be either true or false?
- Question #39
Refer to the exhibit. The window for this rule is 30 minutes. What is this rule tracking?
- Question #40
Refer to the exhibit. The rule evaluates multiple VPN logon failures within a ten-minute window. Consider the following VPN failure events received within a ten-minute window: How...
- Question #41
Which statement about EPS bursting is true?
- Question #42
Refer to the exhibit. Which workers are assigned tasks for the query ID 13127? (Choose two.)
- Question #43
What happens to UEBA events when a user is off-net?
- Question #44
What is the disadvantage of automatic remediation?
- Question #45
From where does the rule engine load the baseline data values?
- Question #46
In the event of a WAN link failure between the collector and the supervisor, by default, what is the maximum number of event files stored on the collector?
- Question #47
Refer to the exhibit. The exhibit shows the output of an SQL command that an administrator ran to view the natural_id value, after logging into the Postgres database. What does the...
- Question #48
Which three statements about collector communication with the FortiSIEM cluster are true? (Choose three.)
- Question #49
Which two statements about the maximum device limit on FortiSIEM are true? (Choose two.)
- Question #50
Refer to the exhibit. Consider a nested event query where both inner and outer queries are event queries. Reporting IP is selected from the CMDB group Network Device, Event Type is...