Month End Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dumps65

Fortinet FCP_FSM_AN-7.2 Dumps

FCP - FortiSIEM 7.2 Analyst Questions and Answers

Question 1

Refer to the exhibit.

as

What is the Group: FortiSIEM Analysts value referring to?

Options:

A.

FortiSIEM organization group

B.

LDAP user group

C.

CMDB user group

D.

Windows Active Directory user group

Question 2

Which items are used to define a subpattern?

Options:

A.

Filters, Aggregate, Group By definitions

B.

Filters, Aggregate, Time Window definitions

C.

Filters, Group By, Threshold definitions

D.

Filters, Threshold, Time Window definitions

Question 3

Refer to the exhibit.

as

If you group the events by User and Count attributes, how many results will FortiSIEM display?

Options:

A.

Two

B.

Six

C.

Three

D.

Five

E.

One

Question 4

What are two required components of a rule? (Choose two.)

Options:

A.

Exception policy

B.

Subpattern

C.

Detection Technology

D.

Clear policy

Question 5

Refer to the exhibit.

as

If you group the events by User, Source IP, and Count attributes, how many results will FortiSIEM display?

Options:

A.

Two

B.

Six

C.

Three

D.

Five

E.

Four

Question 6

What can you use to send data to FortiSIEM for user and entity behavior analytics (UEBA)?

Options:

A.

FortiSIEM agent

B.

SSH

C.

SNMP

D.

FortiSIEM worker

Question 7

Refer to the exhibit.

as

Which value would you expect the FortiSIEM parser to use to populate the Application Name field?

Options:

A.

applist

B.

Network.Service

C.

SSL

D.

wan1

Question 8

Refer to the exhibit.

as

As shown in the exhibit, why are some of the fields highlighted in red?

Options:

A.

Unique values cannot be grouped

B.

The attribute COUNT(Matched Events) is an invalid expression.

C.

No RAW Event Log attribute information is available.

D.

The Event Receive Time attribute is not available for logs.

Question 9

Refer to the exhibit.

as

An analyst wants the rule shown in the exhibit to trigger when three failed login attempts occur within three minutes.

What should the values be for the condition time window and aggregate count?

Options:

A.

Time window 180 seconds, aggregate count 3

B.

Time window 180 seconds, aggregate count 2

C.

Time window 90 seconds, aggregate count 3

D.

Time window 90 seconds, aggregate count 2

Page: 1 / 3
Total 32 questions