nerdexam
Fortinet

FCSS_ADA_AR-6.7 · Question #59

Refer to the exhibit. An administrator runs an analytic search for all FortiGate SSL VPN logon failures. The results are grouped by source IP, reporting IP, and user. The administrator wants to…

The correct answer is C. Admin. The administrator is running an analytic search that groups results by Source IP, Reporting IP, and User, and filters only those with a COUNT >= 3. Looking at the data: Admin has three failed attempts from the same Source IP (203.0.113.4) and Reporting IP Jan and Sarah appear…

Advanced FortiSIEM Analytics

Question

Refer to the exhibit. An administrator runs an analytic search for all FortiGate SSL VPN logon failures. The results are grouped by source IP, reporting IP, and user. The administrator wants to restrict the results to only those rows where the COUNT >=3. Which user would meet that condition?

Exhibit

FCSS_ADA_AR-6.7 question #59 exhibit

Options

  • AJan
  • BSarah
  • CAdmin
  • DTom

How the community answered

(63 responses)
  • A
    3% (2)
  • B
    17% (11)
  • C
    71% (45)
  • D
    8% (5)

Explanation

The administrator is running an analytic search that groups results by Source IP, Reporting IP, and User, and filters only those with a COUNT >= 3. Looking at the data: Admin has three failed attempts from the same Source IP (203.0.113.4) and Reporting IP Jan and Sarah appear only once or twice in the dataset. Tom has multiple entries, but they are from different Source IPs and Reporting IPs, meaning they are not counted as three under the

Topics

#analytic search#COUNT filter#SSL VPN logon failures#query results

Community Discussion

No community discussion yet for this question.

Full FCSS_ADA_AR-6.7 Practice