Which two statements about the maximum device limit on FortiSIEM are true? (Choose two.)
A. The device limit is defined per customer and every customer is assigned a fixed number of device limit by the service provider.
B. The device limit is only applicable to enterprise edition.
C. The device limit is based on the license type that was purchased from Fortinet.
D. The device limit is defined for the whole system and is shared by every customer on a service provider edition.
On which disk are the SQLite databases that are used for the baselining stored?
A. Disk1
B. Disk4
C. Disk2
D. Disk3
What happens to UEBA events when a user is off-net?
A. The agent will upload the events to the Worker if it cannot upload them to a FortiSIEM collector
B. The agent will cache events locally if it cannot upload them to a FortiSIEM collector
C. The agent will upload the events to the Supervisor if it cannot upload them to a FortiSIEM collector
D. The agent will drop the events if it cannot upload them to a FortiSIEM collector
Refer to the exhibit.
How long has the UEBA agent been operationally down?
A. 21 Hours
B. 9 Hours
C. 20 Hours
D. 2 Hours
Refer to the exhibit.
The service provider deployed FortiSIEM without a collector and added three customers on the supervisor. What mistake did the administrator make?
A. Customer A and customer B have overlapping IP addresses.
B. Collectors must be deployed on all customer premises before they are added to organizations on the supervisor.
C. The number of workers on the FortiSIEM cluster must match the number of customers added.
D. At least one collector must be deployed to collect logs from service provider infrastructure devices.
Refer to the exhibit.
An administrator wants to remediate the incident from FortiSIEM shown in the exhibit.
What option is available to the administrator?
A. Quarantine IP FortiClient
B. Run the block MAC FortiOS.
C. Run the block IP FortiOS 5.4
D. Run the block domain Windows DNS
How can you empower SOC by deploying FortiSOAR? (Choose three.)
A. Aggregate logs from distributed systems
B. Collaborative knowledge sharing
C. Baseline user and traffic behavior
D. Reduce human error
E. Address analyst skills gap
Which statement about EPS bursting is true?
A. FortiSIEM will let you burst up to five times the licensed EPS once during a 24-hour period.
B. FortiSIEM must be provisioned with ten percent the licensed EPS to handle potential event surges.
C. FortiSIEM will let you burst up to five times the licensed EPS at any given time, provided it has accumulated enough unused EPS.
D. FortiSIEM will let you burst up to five times the licensed EPS at any given time, regardless of unused of EPS.
Refer to the exhibit.
Is the Windows agent delivering event logs correctly?
A. The logs are buffered by the agent and will be sent once the status changes to managed.
B. The agent is registered and it is sending logs correctly.
C. The agent is not sending logs because it did not receive a monitoring template.
D. Because the agent is unmanaged. the logs are dropped silently by the supervisor.
Which three statements about phRuleMaster are true? (Choose three.)
A. phRuleMaster queues up the data being received from the phRuleWorkers into buckets.
B. phRuleMaster is present on the supervisor and workers.
C. phRuleMaster is present on the supervisor only
D. phRuleMaster wakes up to evaluate all the rule data in series, every 30 seconds.
E. phRuleMaster wakes up to evaluate all the rule data in parallel, even/ 30 seconds