nerdexam
Fortinet

NSE7_SOC_AR-7.6 · Question #51

Refer to the exhibit. You are trying to find traffic flows to destinations that are in Europe or Asia, for hosts in the local LAN segment. However, the query returns no results. Assume these logs…

The correct answer is C. There are missing parentheses between the first row (Group: Europe) and the second row (Group: D. The Source IP row operator must be BETWEEN 10.0.0.0, 10.200.200.254. E. The logical operator for the first row (Group: Europe) must be OR. You've hit your limit · resets 5am (America/New_York)

FortiSIEM Deployment and Configuration

Question

Refer to the exhibit. You are trying to find traffic flows to destinations that are in Europe or Asia, for hosts in the local LAN segment. However, the query returns no results. Assume these logs exist on FortiSIEM. Which three mistakes can you see in the query shown in the exhibit? (Choose three answers)

Exhibit

NSE7_SOC_AR-7.6 question #51 exhibit

Options

  • AThe null value cannot be used with the IS NOT operator.
  • BThe time range must be Absolute for queries that use configuration management database
  • CThere are missing parentheses between the first row (Group: Europe) and the second row (Group:
  • DThe Source IP row operator must be BETWEEN 10.0.0.0, 10.200.200.254.
  • EThe logical operator for the first row (Group: Europe) must be OR.

How the community answered

(33 responses)
  • A
    21% (7)
  • B
    9% (3)
  • C
    70% (23)

Explanation

You've hit your limit · resets 5am (America/New_York)

Topics

#FortiSIEM query construction#logical operators#search filters#geolocation filtering

Community Discussion

No community discussion yet for this question.

Full NSE7_SOC_AR-7.6 Practice