Which two statements about the maximum device limit on FortiSIEM are true? (Choose two.)
A. The device limit is defined per customer and every customer is assigned a fixed number of device limit by the service provider.
B. The device limit is only applicable to enterprise edition.
C. The device limit is based on the license type that was purchased from Fortinet.
D. The device limit is defined for the whole system and is shared by every customer on a service provider edition.
Refer to the exhibit.
If the Z-score for this rule is greater than or equal to three, what does this mean?
A. The rate of firewall connection is optimum.
B. The rate of firewall connection is above the historical average value.
C. The rate of firewall connection is above the current average value.
D. The rate of firewall connection is below historical average value.
Refer to the exhibit. Click on the calculator button.
Based on the information provided in the exhibit, calculate the unused events for the next three minutes for a 520 EPS license.
A. 72460
B. 73460
C. 74460
D. 71460
Refer to the exhibit.
The exhibit shows the output of an SQL command that an administrator ran to view the natural_id value, after logging into the Postgres database. What does the natural_id value identify?
A. The supervisor
B. The worker
C. An agent
D. The collector
Which syntax will register a collector to the supervisor?
A. phProvisionCollector --add
B. phProvisionCollector --add
C. phProvisionCollector --add
D. phProvisionCollector --add
Which of the following are two Tactics in the MITRE ATTandCK framework? (Choose two.)
A. Root kit
B. Reconnaissance
C. Discovery
D. BITS Jobs
E. Phishing
Refer to the exhibit.
The service provider deployed FortiSIEM without a collector and added three customers on the supervisor. What mistake did the administrator make?
A. Customer A and customer B have overlapping IP addresses.
B. Collectors must be deployed on all customer premises before they are added to organizations on the supervisor.
C. The number of workers on the FortiSIEM cluster must match the number of customers added.
D. At least one collector must be deployed to collect logs from service provider infrastructure devices.
How can you invoke an integration policy on FortiSIEM rules?
A. Through Notification Policy settings
B. Through Incident Notification settings
C. Through remediation scripts
D. Through External Authentication settings
Refer to the exhibit.
Why is the windows device still in the CMDB, even though the administrator uninstalled the windows agent?
A. The device was not uninstalled properly
B. The device must be deleted from backend of FortiSIEM
C. The device has performance jobs assigned
D. The device must be deleted manually from the CMDB
In the event of a WAN link failure between the collector and the supervisor, by default, what is the maximum number of event files stored on the collector?
A. 30.000
B. 10.000
C. 40.000
D. 20.000