QuestionQ1
Rules and subpatternsWhen selecting multiple rules simultaneously in FortiSIEM, which actions can you take?
- A You can change the severity, activate, or deactivate multiple rules at a time.
- B You can view, edit, or activate only one rule at a time
- C You can only activate or deactivate multiple rules at a time.
- D You can only change the severity of multiple rules at a time.
QuestionQ2
ML, UEBA, and ZTNAWhich data-collection method produces the most comprehensive information for FortiSIEM user entity and behavior analytics (UEBA) models?
- A FortiSIEM Linux agent
- B Windows UEBA agent
- C Windows Sysmon
- D Linux log
Community Discussion
QuestionQ3
Rules and subpatternsFortiSIEM rules are typically evaluated as events are received (streaming).
How can a rule be created to evaluate events over an 8-hour interval?
- A Configure a report to run the analytical query and run the report every 8 hours.
- B Configure a crontab process on the FortiSIEM supervisor.
- C Configure a 28,000-second time window under the Define Conditions tab.
- D Set the Evaluation Mode to Scheduled under the General tab.
Community Discussion
QuestionQ4
AnalyticsWhich two categories can be mapped to the MITRE ATT&CK coverage tables in FortiSIEM?
- A Incidents
- B CMDB Entries
- C Rules
- D Threats
- E Procedures
Community Discussion
QuestionQ5
AnalyticsRefer to the exhibit below.

Which event-type attribute value will the FortiSIEM parser store for this event?
- A sysUpTime
- B PH_DEV_MON_SYS_UPTIME
- C phLogDetail
- D PHL_INFO











Community Discussion