لا تريد أن تفوت شيئا؟

نصائح اجتياز امتحان الشهادة

آخر أخبار الامتحانات ومعلومات الخصم

برعاية وحديثة من قبل خبرائنا

نعم، أرسل لي النشرة الإخبارية

خذ اختبارات أخرى عبر الإنترنت

السؤال #1
Which statement about sending notifications with incident update is true?
A. You can send notifications to multiple external platforms
B. Notifications can be sent only by email
C. If you use multiple fabric connectors, all connectors must have the same settings
D. Notifications can be sent only when an incident is updated or deleted
عرض الإجابة
اجابة صحيحة: A
السؤال #2
Which three modules does FortiAnalyzer automatically download content from with a valid SOC Automation service license? (Choose three.)
A. Report templates
B. Dashboards
C. Event handlers
D. Active Connectors
E. Playbooks
F. Incident templates
عرض الإجابة
اجابة صحيحة: CEF
السؤال #3
Which statement describes archive logs on FortiAnalyzer?
A. Logs that are indexed and stored in the SQL database
B. Logs a FortiAnalyzer administrator can access in FortiView
C. Logs compressed and saved in files with the
D. Logs previously collected from devices that are offline
عرض الإجابة
اجابة صحيحة: C
السؤال #4
Exhibit.Which statement about the event displayed is correct?
A. The risk source is isolated
B. The security risk was blocked or dropped
C. The security event risk is considered open
D. An incident was created from this event
عرض الإجابة
اجابة صحيحة: C
السؤال #5
Which FortiAnalyzer feature allows you to use a proactive approach when managing your network security?
A. FortiView Monitor
B. Outbreak alert services
C. Incidents dashboard
D. Threat hunting
عرض الإجابة
اجابة صحيحة: D
السؤال #6
An analyst needs to move reports between two ADOMs.Which two statements are true? (Choose two.)
A. All charts and datasets associated with the report will be imported together
B. The date and time will be appended to the original report name to avoid conflicts
C. The ADOMs must be compatible types
D. The reports must be converted into templates first
عرض الإجابة
اجابة صحيحة: AC
السؤال #7
Which statement about sending notifications with incident update is true?
A. You can send notifications to multiple external platforms
B. Notifications can be sent only by email
C. If you use multiple fabric connectors, all connectors must have the same settings
D. Notifications can be sent only when an incident is updated or deleted
عرض الإجابة
اجابة صحيحة: A
السؤال #8
You created a playbook on FortiAnalyzer that uses a FortiOS connector.When configuring the FortiGate side, which type of trigger must be used so that the actions in an automation stich are available in the FortiOS connector?
A. FortiAnalyzer Event Handler
B. Fabric Connector event
C. FortiOS Event Log
D. Incoming webhook
عرض الإجابة
اجابة صحيحة: D
السؤال #9
Which log will generate an event with the status Unhandled?
A. An AV log with action=quarantine
B. An IPS log with action=pass
C. A WebFilter log will action=dropped
D. An AppControl log with action=blocked
عرض الإجابة
اجابة صحيحة: B
السؤال #10
Exhibit.Which statement about the event displayed is correct?
A. The risk source is isolated
B. The security risk was blocked or dropped
C. The security event risk is considered open
D. An incident was created from this event
عرض الإجابة
اجابة صحيحة: B
السؤال #11
What happens when the indicator of compromise (IOC) engine on FortiAnalyzer finds web logs that match blacklisted IP addresses?
A. FortiAnalyzer flags the associated host for further analysis
B. A new infected entry is added for the corresponding endpoint under Compromised Hosts
C. The detection engine classifies those logs as Suspicious
D. The endpoint is marked as Compromised and, optionally, can be put in quarantine
عرض الإجابة
اجابة صحيحة: B
السؤال #12
Which two actions should an administrator take to vide Compromised Hosts on FortiAnalyzer? (Choose two.)
A. Enable device detection on the FotiGate device that are sending logs to FortiAnalyzer
B. Enable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent to fortiAnalyzer
C. Make sure all endpoints are reachable by FortiAnalyzer
D. Subscribe FortiAnalyzer to FortiGuard to keep its local threat database up to date
عرض الإجابة
اجابة صحيحة: AB
السؤال #13
Which SQL query is in the correct order to query to database in the FortiAnalyzer?
A. SELECT devid FROM $log GROUP BY devid WHERE `user',,' users1'
B. SELECT FROM $log WHERE devid `user',, USER1' GROUP BY devid
C. SELCT devid WHERE 'user'-` USER1' FROM $log GROUP By devid
D. SELECT devid FROM $log WHERE `user'=' GROUP BY devid
عرض الإجابة
اجابة صحيحة: D
السؤال #14
Refer to the exhibit.What can you conclude about these search results? (Choose two.)
A. They were searched by using text mode
B. They can be downloaded to a file
C. They are sortable by columns and customizable
D. They are not available for analysis in FortiView
عرض الإجابة
اجابة صحيحة: AB
السؤال #15
Which two parameters does FortiAnalyzer use to identify an indicator of compromise (IOC)? (Choose two.)
A. Application category
B. IP address
C. URL
D. Policy ID
عرض الإجابة
اجابة صحيحة: BC
السؤال #16
Which statement about sending notifications with incident update is true?
A. You can send notifications to multiple external platforms
B. Notifications can be sent only by email
C. If you use multiple fabric connectors, all connectors must have the same settings
D. Notifications can be sent only when an incident is updated or deleted
عرض الإجابة
اجابة صحيحة: A
السؤال #17
When managing incidents on FortiAnalyzer, what must an analyst be aware of?
A. The status of the incident is always linked to the status of the attached event
B. Incidents must be acknowledged before they can be analyzed
C. Severity incidents rated with the level High have an initial service-level agreement (SLA) response time of 1 hour
D. You can manually attach generated reports to incidents
عرض الإجابة
اجابة صحيحة: D
السؤال #18
Which two actions should an administrator take to vide Compromised Hosts on FortiAnalyzer? (Choose two.)
A. Enable device detection on the FotiGate device that are sending logs to FortiAnalyzer
B. Enable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent to fortiAnalyzer
C. Make sure all endpoints are reachable by FortiAnalyzer
D. Subscribe FortiAnalyzer to FortiGuard to keep its local threat database up to date
عرض الإجابة
اجابة صحيحة: AB
السؤال #19
Exhibit.Based on the partial outputs displayed, which devices can be members of a FotiAnalyzer Fabric?
A. FortiAnalayzer1 and FortiAnalyzer3
B. FortiAnalyzer1 and FortiAnalyzer2
C. FortiAnalyzer2 and FortiAnalyzer3
D. All devices listed can be members
عرض الإجابة
اجابة صحيحة: D
السؤال #20
Which two actions should an administrator take to vide Compromised Hosts on FortiAnalyzer? (Choose two.)
A. Enable device detection on the FotiGate device that are sending logs to FortiAnalyzer
B. Enable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent to fortiAnalyzer
C. Make sure all endpoints are reachable by FortiAnalyzer
D. Subscribe FortiAnalyzer to FortiGuard to keep its local threat database up to date
عرض الإجابة
اجابة صحيحة: AB
السؤال #21
In firmware version 7.6, how does on-premises FortiAnalyzer store logs? (Choose one answer)
A. ses Elasticsearch database
B. ses ClickHouse database
C. ses MySQL database
D. ses Postgres SQL database
عرض الإجابة
اجابة صحيحة: B
السؤال #22
Exhibit.Based on the partial outputs displayed, which devices can be members of a FotiAnalyzer Fabric?
A. FortiAnalayzer1 and FortiAnalyzer3
B. FortiAnalyzer1 and FortiAnalyzer2
C. FortiAnalyzer2 and FortiAnalyzer3
D. All devices listed can be members
عرض الإجابة
اجابة صحيحة: D
السؤال #23
You created a playbook on FortiAnalyzer that uses a FortiOS connector.When configuring the FortiGate side, which type of trigger must be used so that the actions in an automation stich are available in the FortiOS connector?
A. FortiAnalyzer Event Handler
B. Fabric Connector event
C. FortiOS Event Log
D. Incoming webhook
عرض الإجابة
اجابة صحيحة: D
السؤال #24
Refer to the exhibit.The playbook shown in the exhibit requires fine-tuning. A task needs to be configured to run a report on the updated asset list that the FortiAnalyzer receives from the FortiClient EMS.Which SOC role is responsible for making this change?
A. Threat hunter
B. SOC engineer
C. Security analyst
D. Incident responder
عرض الإجابة
اجابة صحيحة: B
السؤال #25
Why must you wait for several minutes before you run a playbook that you just created?
A. ortiAnalyzer needs that time to parse the new playbook
B. ortiAnalyzer needs that time to debug the new playbook
C. ortiAnalyzer needs that time to back up the current playbooks
D. ortiAnalyzer needs that time to ensure there are no other playbooks running
عرض الإجابة
اجابة صحيحة: A
السؤال #26
Which FortiAnalyzer feature allows you to use a proactive approach when managing your network security?
A. ncidents dashboard
B. hreat hunting
C. utbreak alert services
D. ortiView Monitor
عرض الإجابة
اجابة صحيحة: B
السؤال #27
Which two actions should an administrator take to vide Compromised Hosts on FortiAnalyzer? (Choose two.)
A. Enable device detection on the FotiGate device that are sending logs to FortiAnalyzer
B. Enable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent to fortiAnalyzer
C. Make sure all endpoints are reachable by FortiAnalyzer
D. Subscribe FortiAnalyzer to FortiGuard to keep its local threat database up to date
عرض الإجابة
اجابة صحيحة: AB
السؤال #28
Which SQL query is in the correct order to query to database in the FortiAnalyzer?
A. SELECT devid FROM $log GROUP BY devid WHERE `user',,' users1'
B. SELECT FROM $log WHERE devid `user',, USER1' GROUP BY devid
C. SELCT devid WHERE 'user'-` USER1' FROM $log GROUP By devid
D. SELECT devid FROM $log WHERE `user'=' GROUP BY devid
عرض الإجابة
اجابة صحيحة: D
السؤال #29
Exhibit.Which statement about the event displayed is correct?
A. The risk source is isolated
B. The security risk was blocked or dropped
C. The security event risk is considered open
D. An incident was created from this event
عرض الإجابة
اجابة صحيحة: B
السؤال #30
When managing incidents on FortiAnalyzer, what must an analyst be aware of?
A. ncidents must be acknowledged before they can be analyzed
B. everity incidents rated with the level High have an initial service-level agreement (SLA) response time of 1 hour
C. ou can manually attach generated reports to incidents
D. he status of the incident is always linked to the status of the attached event
عرض الإجابة
اجابة صحيحة: C
السؤال #31
Which statement about the FortiSIEM management extension is correct?
A. t can be installed as a dedicated VM
B. t requires a licensed FortiSIEM supervisor
C. ts use of the available disk space is capped at 50%
D. t allows you to manage the entire life cycle of a threat or breach
عرض الإجابة
اجابة صحيحة: B
السؤال #32
Which SQL query is in the correct order to query to database in the FortiAnalyzer?
A. SELECT devid FROM $log GROUP BY devid WHERE `user',,' users1'
B. SELECT FROM $log WHERE devid `user',, USER1' GROUP BY devid
C. SELCT devid WHERE 'user'-` USER1' FROM $log GROUP By devid
D. SELECT devid FROM $log WHERE `user'=' GROUP BY devid
عرض الإجابة
اجابة صحيحة: D
السؤال #33
Which two statements about exporting and importing playbooks are true? (Choose two.)
A. You can export only one playbook at a time
B. A playbook that was disabled when it was exported will be disabled when it is imported
C. You can import a playbook even if there is another one with the same name in the destination
D. Playbooks can be imported to a different FortiAnalyzer device, but only if the connectors already exist
عرض الإجابة
اجابة صحيحة: BC

View The Updated Fortinet Exam Questions

SPOTO Provides 100% Real Fortinet Exam Questions for You to Pass Your Fortinet Exam!

عرض الإجابات بعد التقديم

يرجى إرسال البريد الإلكتروني الخاص بك والواتس اب للحصول على إجابات الأسئلة.

ملحوظة: يرجى التأكد من صلاحية معرف البريد الإلكتروني وWhatsApp حتى تتمكن من الحصول على نتائج الاختبار الصحيحة.

بريد إلكتروني:
رقم الواتس اب/الهاتف:
Contact Us