option
Cuestiones
ayuda
daypo
buscar.php

SIEM

COMENTARIOS ESTADÍSTICAS RÉCORDS
REALIZAR TEST
Título del Test:
SIEM

Descripción:
SIEM Analitica24

Fecha de Creación: 2026/08/20

Categoría: Otros

Número Preguntas: 24

Valoración:(0)
COMPARTE EL TEST
Nuevo ComentarioNuevo Comentario
Comentarios
NO HAY REGISTROS
Temario:

Which statement about the time range settings defined in the nested query is accurate? (Choose one answer). FortiSIEM will list source IP addresses found in the last 10 minutes of events from each day in the Approved Devices report from the last 30 days. FortiSIEM will search in real time using 10-minute blocks for a source IP address that is not in the Approved Devices report from the last 30 days. FortiSIEM will search the last 30 days of events for a source IP address that is not in the Approved Devices report. FortiSIEM will search the last 10 minutes of events for a source IP address that is not in the Approved Devices report from the last 30 days.

How does FortiSIEM update the incident table if a performance rule triggers repeatedly?. FortiSIEM changes the incident status to Repeated, and updates the Last Seen timestamp. FortiSIEM updates the Incident Count value and Last Seen timestamp. FortiSIEM generates a new incident based on the Rule Frequency value, and updates the First Seen and Last Seen timestamps. FortiSIEM generates a new incident each time the rule triggers, and updates the First Seen and Last Seen timestamps.

As shown in the exhibit, why are some of the fields highlighted in red?. Unique values cannot be grouped. The attribute COUNT(Matched Events) is an invalid expression. No RAW Event Log attribute information is available. The Event Receive Time attribute is not available for logs.

If a rule containing the automation policy shown in the exhibit triggers, what will happen?. Associated source IP addresses will be blocked on devices in the Aviation organization. Associated source IP addresses will be blocked on all FortiGate firewalls. Associated source IP addresses will be blocked on devices in the Network CMDB group. Associated source IP addresses will be blocked on two FortiGate firewalls.

The configuration shown in the exhibit is incorrect. What must you change to allow this configuration to be successfully applied to FortiSIEM?. The Train factor must be 70% or greater. Run Mode must be set to ML. Only one AVG type field must be selected under Fields to use for Prediction. The selection in Fields to use for Prediction and Field to Predict must match.

The analyst is troubleshooting the analytics query shown in the exhibit. Why is this search not producing any results?. The Time Range is set incorrectly. The inner and outer nested query attribute types do not match. You cannot reference User and Event Type attributes in the same search. The Boolean operator is wrong between the attributes.

An analyst is trying to generate an incident with a title that includes the Source IP, Destination IP, User, and Destination Host Name. They are unable to add Destination Host Name as an incident attribute. What must be changed to allow the analyst to select Destination Host Name as an attribute?. The Destination Host Name must be selected as a Triggered Attribute. The Destination Host Name must be set as an aggregate item in a subpattern. The Destination Host Name must be added as an Event Type in FortiSIEM. The Destination IP event attribute must be removed.

Refer to the exhibit.What will FortiSIEM display if you apply the Group By and Display Fields configuration to a list of allowed firewall connections?. A list of connections between unique source and destination IP addresses. A list of connections ordered by destination IP address hit count. A running count of connections, regardless of source or destination. A list of connections ordered by the number of unique connections started by each source IP address.

What is this rule attempting to match? (Choose one answer). Failed VPN logon attempts from three or more different outside countries. Failed VPN logon events from a source outside the home country. Failed VPN logon attempts from three or more different sources inside the home country. Excessive VPN logon failures from a source inside the home country.

What is the Group: FortiSIEM Analysts value referring to?. FortiSIEM organization group. LDAP user group. CMDB user group. Windows Active Directory user group.

According to the automation policy configuration shown in the exhibit, what happens if an associated rule triggers?. FortiSIEM runs the remediation script, because that takes precedence over all other options. FortiSIEM performs all selected actions. FortiSIEM fails to the integration policy, because no policy is defined. FortiSIEM sends an email, because that is first on the list.

Which two actions can you select in an automation policy to trigger an API call to block an IP address on a FortiGate? (Choose two.). Open Remedy ticket using the configuration set in Analytics. Send Email/SMS/Webhook to the target users. Invoke an Integration Policy. Run Remediation/Script. Run Playbook on Incident Trigger.

An analyst wants the rule shown in the exhibit to trigger when three failed login attempts occur within three minutes. What should the values be for the condition time window and aggregate count?. Time window 180 seconds, aggregate count 3. Time window 180 seconds, aggregate count 2. Time window 90 seconds, aggregate count 3. Time window 90 seconds, aggregate count 2.

An analyst is trying to identify an issue using an expression based on the Expression Builder settings shown in the exhibit; however, the error message shown in the exhibit indicates that the expression is invalid. What is the correct syntax to create an expression that generates a total count of matched events?. COUNT(Matched Events). (COUNT) Matched Events. Matched Events (COUNT). Matched Events COUNT().

What happens when an analyst clears an incident generated by a rule containing the automation policy shown in the exhibit?. No notification is sent. An email is sent to the SOC manager. The remediation script is run. A notification is sent to the SOC manager dashboard.

What are two required components of a rule? (Choose two.). Exception policy. Subpattern. Detection Technology. Clear policy.

Which items are used to define a subpattern?. Filters, Aggregate, Group By definitions. Filters, Aggregate, Time Window definitions. Filters, Group By, Threshold definitions. Filters, Threshold, Time Window definitions.

Which two conditions will match this rule and subpatterns? (Choose two.). A user using RDP over SSL VPN fails to log in to an application five times. A user runs a brute force password cracker against an RDP server. A user fails twice to log in when connecting through RDP. A user connects to the wrong IP address for an RDP session five times.

What is the Group: VPN Gateway value a reference to? (Choose one answer). A configuration management database (CMDB) device group. A FortiSIEM rule folder. A FortiSIEM watchlist. A FortiGate address group.

When selecting multiple rules at once on FortiSIEM, what actions can you perform?. You can change the severity of multiple rules, and activate or deactivate them. You can only view, edit, and activate a single rule at one time. You can only change the severity of multiple rules. You can only activate or deactivate multiple rules.

How can you query the configuration management database (CMDB) in an analytics search?. Click Value > Select from CMDB. On the CMDB tab, select an entry, and then click Create Search. On the Admin tab, click CMDB Search. Click Attribute > Select from CMDB.

A FortiSIEM analyst is investigating an issue by examining events to two destination IP addresses. However, the analyst is not getting any results from the search. Based on the selected filter shown in the exhibit, why is the search returning no results?. Parentheses are missing between the two items. The wrong Boolean operator is selected in the Next column. The wrong option is selected in the Operator column. An invalid IP address is typed in the Value column.

How was this incident cleared?. The analyst manually cleared the incident from the incident table. FortiSIEM cleared the incident automatically after 24 hours. The incident was cleared automatically by the rule. The endpoint was rebooted and sent an all-clear signal to FortiSIEM.

When configuring machine learning (ML), in which step can you modify how the model fits the training data set?. Prepare Data. Train. Statistics. Design.

Denunciar Test