SIEM_AN
|
|
Título del Test:
![]() SIEM_AN Descripción: SIEM_ Analitica 23 |



| Comentarios |
|---|
NO HAY REGISTROS |
|
What can you use to send data to FortiSIEM for user and entity behavior analytics (UEBA)?. FortiSIEM agent. SSH. SNMP. FortiSIEM worker. You need to model for predicting a target based on other fields in the dataset and then trigger an anomaly if the value does not match the prediction. Which machine learning algorithm will build this type of model?. Classification. Clustering. Regression. Forecasting. Refer to the exhibit. What will happen when a device being analyzed by the machine learning configuration shown in the exhibit has consistently high memory utilization?. FortiSIEM will update the regression tables for memory utilization, and average sent and received bytes. FortiSIEM will trigger an incident for high memory utilization. FortiSIEM will lower the CPU utilization trigger requirement for CPU utilization. FortiSIEM will update the model with a higher memory utilization average value. Which two settings must you configure to allow FortiSIEM to apply tags to devices in FortiClient EMS? (Choose two.). FortiEMS API credentials defined on FortiSIEM. Remediation script configured. ZTNA tags defined on FortiSIEM. FortiSIEM API credentials defined on FortiEMS. Three events are collected over 10 minutes from two servers: Server A and Server B. Based on the settings for the rule subpattern and a 10-minute condition window, how many incidents will the servers generate?. Server A will generate one incident and Server B will generate one incident. Server A will not generate any incidents and server B will generate one incident. Server A will not generate any incidents and Server B will not generate any incidents. Server A will generate one incident and Server B will not generate any incidents. You want to create a rule with multiple subpatterns but trigger an incident only if three different subpatterns are matched over a 24-hour period. Where must you define the time period that the rule uses to evaluate all the subpatterns? (Choose one answer). Define the time window in each individual subpattern. Define the time window under the General tab of the rule. Define the time window under the Define Condition tab of the rule. Define the time window in the Define Action section of the rule. Which two data areas can you use for user and entity behavior analytics (EBA) machine learning models? (Choose two.). Process. Location. Resources. Network. Which analytics search can be used to apply a user and entity behavior analytics (UEBA) tag to an event for a failed login by the user JSmith?. User = smith. username NOT END WITH jsmith. User IS jsmith. Username CONTAIN smit. Refer to the exhibits. You are troubleshooting why the rule shown in the exhibit is generating incidents for successful Remote Desktop Protocol (RDP) connections with correct logins. It should only be triggering when a person fails to log in three or more times to the target device when connecting with RDP. What is causing the rule to be triggered by correct login events? (Choose one answer). The subpattern relationship RDP_Connection:User = Failed_Logon:User never matches. The Boolean between the subpatterns is incorrect. The attribute types in the subpatterns do not match. The RDP login is different from the login used to access the target device. Refer to the exhibit. Which section contains the subpattern configuration that determines how many matching events are needed to trigger the rule?. Aggregate. Group By. Actions. Filters. Which two lookup types can you reference as the subquery in a nested analytics query? (Choose two.). LDAP Query. CMDB Query. SNMP Query. Event Query. If you group the events by Reporting Device , Reporting IP , and Application Category , how many results will FortiSIEM display?. Four. Five. One. Six. Two. A FortiSIEM device is receiving syslog events from a FortiGate firewall. The FortiSIEM analyst is trying to search the raw event logs for the last two hours that contain the keyword " udp " . However, they are getting no results from the search, which they know should be available. Based on the filter shown in the exhibit, why are there no search results?. The analyst selected AND in the Next column. This is the wrong Boolean operator. The Time Range value should be set to Real-Time. The keyword is case sensitive. Instead of typing udp in the Value field, the analyst should type UDP. The analyst selected = in the Operator column. That is the wrong operator. If you group the events by User and Count attributes, how many results will FortiSIEM display?. two. six. three. five. one. When configuring anomaly detection machine learning, in which step must you select the fields to analyze?. Design. Schedule. Prepare Data. Train. In an automation policy, which two methods can you use to notify analysts when an incident is triggered? (Choose two.). Email. FortiSIEM Case. Syslog. Pop-up window. An analyst wants to perform a KMeans machine learning (ML) job on this data. How many N clusters would be a good fit for the data? (Choose one answer). Two. 50. 100. one. Which value would you expect the FortiSIEM parser to use to populate the Application Name field?. applist. Network.Service. SSL. wan1. An analyst wants to create a rule from a newly created analytics search. What is the quickest method?. On the Analytics tab, click Actions > Create Rule. Create a new rule under Resources > Rules and fill in the search details. On the Analytics tab, click the New button next to the Filter By box. On the upper menu bar on any tab, click the pencil icon. Which information can FortiSIEM retrieve from FortiClient EMS through an API connection?. Host software versions. FortiSIEM license. Host login credentials. ZTNA tags. analyst is troubleshooting the rule shown in the exhibit. It is not generating any incidents, but the filter parameters are generating events on the Analytics tab. What is wrong with the rule conditions?. The Event Type refers to a CMDB lookup and should be an Event lookup. The Destination Host Name value is not fully qualified. The Group By attributes restricts which events are counted. The Aggregate attribute is too restrictive. If you group the events by User , Source IP , and Count attributes, how many results will FortiSIEM display?. two. six. three. five. four. Which statement about thresholds is true?. FortiSIEM uses fixed, hardcoded global and device thresholds for all performance metrics. FortiSIEM uses only device thresholds for security metrics. FortiSIEM uses global and per-device thresholds for performance metrics. FortiSIEM uses only global thresholds for performance metrics. Which run mode takes the most time to perform machine learning tasks?. Local Auto. Local. Forecasting. Regression. |




