A FortiSIEM analyst is investigating an issue by examining events related to two destination IP addresses. However, the analyst is not getting any results from the search.
Based on the selected filters shown in the exhibit, why is the search returning no results?
AParentheses are missing between the two items.
BAn invalid IP address is typed in the Value column.
CThe wrong boolean operator is selected in the Next column.
DThe wrong option is selected in the Operator column.
Refer to the exhibit.
What will FortiSIEM display if you apply the Group By and Display Fields configuration to a list of allowed firewall connections?
AA list of connections between unique source and destination IP addresses
BA running count of connections, regardless of source or destination
CA list of connections ordered by destination IP address hit count
DA list of connections ordered by the number of unique connections started by each source IP address
You need a model for predicting a target field based on other fields in a dataset and then trigger an anomaly if the value does not match the prediction.
Which machine learning algorithm will build this type of model?
ARegression
BForecasting
CClustering
DRegression
When FortiSIEM is configured to apply ZTNA tags, what is the order of events when an analyst wants to automatically block a ZTNA tagged host?
AFortiEMS tags host > FortiSIEM receives tag information > FortiSIEM tags host > ZTNA tags enforced on FortiGate
BFortiEMS tags host > FortiEMS receives tag information > FortiSIEM tags host > ZTNA tags enforced on FortiGate
CFortiSIEM tags host > FortiEMS receives tag information > FortiEMS tags host > ZTNA tags enforced on FortiGate
DFortiEMS receives tag information > FortiEMS tags host > FortiSIEM tags host > ZTNA tags enforced on FortiGate
Question 9
Collect and analyze event data
0
Question 10
Configure incidents and automation
Question 11
Collect and analyze event data
Question 12
Configure incidents and automation
Question 13
Configure incidents and automation
Question 14
Collect and analyze event data
Question 15
Configure incidents and automation
Question 16
Configure incidents and automation
Question 17
Collect and analyze event data
Question 18
Collect and analyze event data
Question 19
Configure incidents and automation
Question 20
Configure incidents and automation
Question 21
Collect and analyze event data
Question 22
Perform searches and investigations
Question 23
Configure incidents and automation
Question 24
Configure incidents and automation
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ad
Want a break from the ads?
Become a Supporter and enjoy a completely ad-free experience, plus unlock Learn Mode, Exam Mode, AstroTutor AI, and more.
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
In FortiSIEM, which database stores discovery information?
AProfile DB
BSVN DB
CCMDB
DEvent DB
Refer to the exhibits.
Three events are collected over 10 minutes from two servers: Server A and Server B.
Based on the settings for the rule subpattern and a 10-minute condition window, how many incidents will the servers generate?
AServer A will not generate any incidents and Server B will not generate any incidents.
BServer A will generate one incident and Server B will generate one incident.
CServer A will not generate any incidents and server B will generate one incident.
DServer A will generate one incident and Server B will not generate any incidents.
What must match when referencing an inner query from an outer query?
ABoth must be event queries.
BBoth must be CMDB lookups.
CBoth must reference IP addresses.
DBoth must have the same data type.
Where must you define and assign a custom python script as a remediation action?
ARemediation Policy
BAutomation Policy
CScript Policy
DRule Engine Policy
In an automation policy, which two methods can you use to notify analysts when an incident is triggered? (Choose two.)
AFortiSIEM Case
BSyslog
CPop-up window
DEmail
Refer to the exhibit.
If you group the events by Reporting IP, Event Type, and User attributes, how many results will FortiSIEM display?
AThree
BFive
CTwo
DFour
What are the four incident status values on FortiSIEM?