A FortiSIEM supervisor at headquarters is struggling to keep up with an increase of EPS (Events Per Second) being reported across the enterprise. What components should an administrator consider deploying to assist the supervisor with processing data?
A. Supervisor
B. Worker
C. Collector
D. Agent
What protocol can be used to collect Windows event logs in an agentless method?
A. SSH
B. SNMP
C. WMI
D. SMTP
If the reported packet loss is between 50% and 98%. which status is assigned to the device in the Availability column of summary dashboard?
A. Down status is assigned because of packet loss.
B. Up status is assigned because of received packets
C. Critical status is assigned because of reduction in number of packets received
D. Degraded status is assigned because of packet loss
To determine SNMP discovery issues, which is the best command from the backend?
A. snmpwalk
B. phSNMPTest
C. snmptest
D. ssh
In the advanced analytical rules engine in FortiSIEM, multiple subpatterms can be referenced using which three operation?(Choose three.)
A. ELSE
B. NOT
C. FOLLOWED_BY
D. OR
E. AND
Which two FortiSIEM components work together to provide real-time event correlation?
A. Collector and Windows agent
B. Supervisor and worker
C. Worker and collector
D. Supervisor and collector
Which protocol is almost always required for the FortiSIEM GUI discovery process?
A. SNMP
B. WMI
C. Syslog D. Telnet
Which item is required to register a FortiSIEM appliance license?
A. Static storage
B. Static MAC address
C. Static IP address
D. Static Hardware ID
Which database is used for storing anomaly data, that is calculated for different parameters, such as traffic and device resource usage running averages, and standard deviation values?
A. Profile DB
B. Event DB
C. CMDB
D. SVN DB
What are the four categories of incidents?
A. Devices, users, high risk, and low risk
B. Performance, availability, security, and change
C. Performance, devices, high risk, and low risk
D. Security, change, high risk, and low risk