Fortinet FCSS—Advanced Analytics 6.7 Architect - FCSS_ADA_AR-6.7 Exam Practice Test
How can you empower SOC by deploying FortiSOAR? (Choose three.)
Correct Answer: A,D,E
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Refer to the exhibit.

An administrator wants to remediate the incident from FortiSIEM shown in the exhibit.
What option is available to the administrator?

An administrator wants to remediate the incident from FortiSIEM shown in the exhibit.
What option is available to the administrator?
Correct Answer: A
Refer to the exhibit.

Is the Windows agent delivering event logs correctly?

Is the Windows agent delivering event logs correctly?
Correct Answer: C
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Refer to the exhibit.

An administrator deploys a new collector for the first time, and notices that all the processes expect the phMonitor are down.
How can the administrator bring the processes up?

An administrator deploys a new collector for the first time, and notices that all the processes expect the phMonitor are down.
How can the administrator bring the processes up?
Correct Answer: A
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
For what type of data values does the rule engine query the profile database?
Correct Answer: B
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Refer to the exhibit.

Consider a nested event query where both inner and outer queries are event queries.
Reporting IP is selected from the CMDB group Network Device, Event Type is selected from the CMDB group Logon Success, and Source IP is selected from the report Failed Logons to Network Devices.
An administrator is about to execute the nested query. The report time ranges must be set before execution. The Nested Time Range will be applied to which attributes?

Consider a nested event query where both inner and outer queries are event queries.
Reporting IP is selected from the CMDB group Network Device, Event Type is selected from the CMDB group Logon Success, and Source IP is selected from the report Failed Logons to Network Devices.
An administrator is about to execute the nested query. The report time ranges must be set before execution. The Nested Time Range will be applied to which attributes?
Correct Answer: B
Refer to the exhibit.

Consider a custom lookup table MalwareIPList. An analyst constructed an analytic query to reference the MalwareIPList lookup table.
What is the outcome of the analytic query?

Consider a custom lookup table MalwareIPList. An analyst constructed an analytic query to reference the MalwareIPList lookup table.
What is the outcome of the analytic query?
Correct Answer: A
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).