Weekend Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Fortinet FCSS_ADA_AR-6.7 Practice Exam with Questions & Answers

Questions 1

Refer to the exhibit.

FCSS_ADA_AR-6.7 Question 1

The window for this rule is 30 minutes.

What is this rule tracking?

Options:
A.

A sudden 50% increase in WMI response times over a 30-minute time window

B.

A sudden 1.50 times increase in WMI response times over a 30-minute time window

C.

A sudden 150% increase in WMI response times over a 30-minute time window

D.

A sudden 75% increase in WMI response times over a 30-minute time window

Fortinet FCSS_ADA_AR-6.7 Premium Access
Questions 2

Which lookup table function can be either true or false?

Options:
A.

LookupTableHas

B.

LookupTableGet

C.

LookupTableFilter

D.

LookupTableRetriev

Questions 3

How can you empower SOC by deploying FortiSOAR? (Choose three.)

Options:
A.

Collaborative knowledge sharing

B.

Aggregate logs from distributed systems

C.

Address analyst skills gap

D.

Baseline user and traffic behavior

E.

Reduce human error

Questions 4

Refer to the exhibit.

FCSS_ADA_AR-6.7 Question 4

The service provider deployed FortiSIEM without a collector and added three customers on the supervisor.

What mistake did the administrator make?

Options:
A.

The number of workers on the FortiSIEM cluster must match the number of customers added

B.

Collectors must be deployed on all customer premises before they are added to organization on the supervisor.

C.

At least one collector must be deployed to collect logs from service provider infrastructure devices.

D.

Customer A and customer B have overlapping IP addresses.

Questions 5

Which three statements about phRuleMaster are true? (Choose three.)

Options:
A.

phRuleMaster is present on the supervisor only.

B.

phRuleMaster is present on the supervisor and workers.

C.

phRuleMaster queues up the data being received from the phRuleWorkers into buckets.

D.

phRuleMaster wakes up to evaluate all the rule data in parallel, every 30 seconds.

E.

phRuleMaster wakes up to evaluate all the rule data in series, every 30 seconds.

Questions 6

What happens to events that the collector receives when there is a WAN link failure between the collector and the supervisor?

Options:
A.

Events are buffered for up to 24 hours.

B.

Events are buffered up to 10 MB before compression.

C.

Events are buffered up to 10.000 logs.

D.

Events are buffered up to 1 GB after compression.

Questions 7

How can you customize the AI model on FortiSIEM?

Options:
A.

Retrain the AI model

B.

Reconfigure UEBA rules

C.

Adjust risk weighting for UEBA tags

D.

Adjust number of samples collected by the UEBA agents

Questions 8

Refer to the exhibit.

FCSS_ADA_AR-6.7 Question 8

A service provider does not have a dedicated worker in the cluster, but still wants to add a collector to an organization.

What option does the administrator have?

Options:
A.

Define a pseudo address as a worker IP address

B.

Install a worker

C.

Ignore the warning and continue adding the collector

D.

Define the supervisorIP address as a worker unload address

Questions 9

What happens to UEBA events when a user is off-net?

Options:
A.

The agent will cache events locally if it cannot upload them to a FortiSIEM collector

B.

The agent will drop the events if it cannot upload them to a FortiSIEM collector

C.

The agent will upload the events to the Worker if it cannot upload them to a FortiSIEM collector

D.

The agent will upload the events the events to the Supervisor if it cannot upload them to a FortiSIEM collector

Questions 10

Refer to the exhibit.

FCSS_ADA_AR-6.7 Question 10

Which three fields from the organization destination are required while registering a collector? (Choose three.)

Options:
A.

Account Number

B.

Admin Password

C.

Agent Password

D.

Organization

E.

Admin User