لا تريد أن تفوت شيئا؟

نصائح اجتياز امتحان الشهادة

آخر أخبار الامتحانات ومعلومات الخصم

برعاية وحديثة من قبل خبرائنا

نعم، أرسل لي النشرة الإخبارية

خذ اختبارات أخرى عبر الإنترنت

السؤال #1
Refer to the exhibit.You are investigating an open incident and want to add records from the Tickets module, a custom module, to the visual correlation widget. Assume there are already linked ticket records to the incident.How do you accomplish this?
A. Edit the incident template and add the Tickets module to the graph
B. Define move module relationships under Correlation Settings
C. Tag ticket records with the incident ID
D. Ingest ticket records through a custom connector
عرض الإجابة
اجابة صحيحة: A
السؤال #2
Refer to the exhibit.You are reviewing the Triggering Events page for a FortiSIEM incident. You want to remove the Reporting IP column because you have only one firewall in the topology.How do you accomplish this?
A. Customize the display columns for this incident
B. Remove the Reporting IP attribute from the raw logs using parsing rules
C. Disable correlation for the Reporting IP field in the rule subpattern
D. Clear the Reporting IP field from the Triggered Attributes section when you configure the Incident Action
عرض الإجابة
اجابة صحيحة: A
السؤال #3
Refer to the exhibits.Assume that the traffic flows are identical, except for the destination IP address. There is only one FortiGate in network address translation (NAT) mode in this environment.Based on the exhibits, which two conclusions can you make about this FortiSIEM incident? (Choose two answers)
A. The client 10
B. FortiGate is not routing the packets to the destination hosts
C. The destination hosts are not responding
D. FortiGate is blocking the return flows
عرض الإجابة
اجابة صحيحة: AC
السؤال #4
Review the incident report:An attacker identified employee names, roles, and email patterns from public press releases, which were then used to craft tailored emails.The emails were directed to recipients to review an attached agenda using a link hosted off the corporate domain.Which two MITRE ATT&CK tactics best fit this report? (Choose two answers)
A. Reconnaissance
B. Discovery
C. Initial Access
D. Defense Evasion
عرض الإجابة
اجابة صحيحة: AC
السؤال #5
Refer to the exhibit.How do you add a piece of evidence to the Action Logs Marked As Evidence area? (Choose one answer)
A. By tagging output or a workspace comment with the keyword Evidence
B. By linking an indicator to the war room
C. By creating an evidence collection task and attaching a file
D. By executing a playbook with the Save Execution Logs option enabled
عرض الإجابة
اجابة صحيحة: A
السؤال #6
Refer to the exhibit.How do you add a piece of evidence to the Action Logs Marked As Evidence area? (Choose one answer)
A. By tagging output or a workspace comment with the keyword Evidence
B. By linking an indicator to the war room
C. By creating an evidence collection task and attaching a file
D. By executing a playbook with the Save Execution Logs option enabled
عرض الإجابة
اجابة صحيحة: A
السؤال #7
Review the incident report:An attacker identified employee names, roles, and email patterns from public press releases, which were then used to craft tailored emails.The emails were directed to recipients to review an attached agenda using a link hosted off the corporate domain.Which two MITRE ATT&CK tactics best fit this report? (Choose two answers)
A. Reconnaissance
B. Discovery
C. Initial Access
D. Defense Evasion
عرض الإجابة
اجابة صحيحة: AC
السؤال #8
Based on the Pyramid of Pain model, which two statements accurately describe the value of an indicator and how it is for an adversary to change? (Choose two.)
A. Tactics, techniques, and procedures are hard because adversaries must adapt their methods
B. Tools are easy because often, multiple alternatives exist
C. IP addresses are easy because adversaries can spoof them or move them to new resources
D. Artifacts are easy because adversaries can alter file paths or registry keys
عرض الإجابة
اجابة صحيحة: AC
السؤال #9
When you use a manual trigger to save user input as a variable, what is the correct Jinja expression to reference the variable? (Choose one answer)
A. {{ vars
B. {{ globalVars
C. {{ vars
D. {{ vars
عرض الإجابة
اجابة صحيحة: A
السؤال #10
When you use a manual trigger to save user input as a variable, what is the correct Jinja expression to reference the variable? (Choose one answer)
A. {{ vars
B. {{ globalVars
C. {{ vars
D. {{ vars
عرض الإجابة
اجابة صحيحة: A
السؤال #11
A partner organization recently suffered a distributed denial-of-service (DDoS) attack, but the adversary's identity and TTPs remain unknown. Your SOC has not received any relevant threat intelligence from the partner organization, but you are asked to determine whether similar activity could be happening in your environment. Which threat hunting action should you perform first? Choose one answer.
A. onfigure SIEM rules to alert when inbound traffic exceeds baseline thresholds
B. se threat intelligence to enrich the IP addresses of all external source IP addresses
C. se a packet analyzer to capture and review all traffic flows on critical devices
D. evelop a hunting hypothesis based on how DDoS can be executed against your network
عرض الإجابة
اجابة صحيحة: D
السؤال #12
Refer to the exhibit.You configured a playbook named False Positive Close, and want to run it to verify if it works. However, when you click Execute and search for the playbook, you do not see it listed.Which two reasons could be the cause of the problem? (Choose two.)
A. The manual trigger is configured to require record input to run
B. The playbook must first be published using the Application Editor
C. The Alerts module is not among the list of modules the playbook can execute on
D. Another instance of the playbook is currently executing
عرض الإجابة
اجابة صحيحة: AC
السؤال #13
Refer to the exhibits.Assume that the traffic flows are identical, except for the destination IP address. There is only one FortiGate in network address translation (NAT) mode in this environment.Based on the exhibits, which two conclusions can you make about this FortiSIEM incident? (Choose two answers)
A. The client 10
B. FortiGate is not routing the packets to the destination hosts
C. The destination hosts are not responding
D. FortiGate is blocking the return flows
عرض الإجابة
اجابة صحيحة: AC
السؤال #14
Which three are threat hunting activities? (Choose three answers)
A. Enrich records with threat intelligence
B. Automate workflows
C. Generate a hypothesis
D. Perform packet analysis
E. Tune correlation rules
عرض الإجابة
اجابة صحيحة: ACD
السؤال #15
Review the incident report:An attacker identified employee names, roles, and email patterns from public press releases, which were then used to craft tailored emails.The emails were directed to recipients to review an attached agenda using a link hosted off the corporate domain.Which two MITRE ATT&CK tactics best fit this report? (Choose two answers)
A. Reconnaissance
B. Discovery
C. Initial Access
D. Defense Evasion
عرض الإجابة
اجابة صحيحة: AC
السؤال #16
Refer to the exhibits.The DOS attack playbook is configured to create an incident when an event handler generates a denial-of-ser/ice (DoS) attack event.Why did the DOS attack playbook fail to execute?
A. he Attach_Data_To_lncident task failed
B. he Attach_Data_To_lncident task is expecting an integer value but is receiving the incorrect data type
C. he Create SMTP Enumeration incident task is expecting an integer value but is receiving the incorrect data type
D. he Get Events task is configured to execute in the incorrect order
عرض الإجابة
اجابة صحيحة: C
السؤال #17
Review the incident report:An attacker identified employee names, roles, and email patterns from public press releases, which were then used to craft tailored emails.The emails were directed to recipients to review an attached agenda using a link hosted off the corporate domain.Which two MITRE ATT&CK tactics best fit this report? (Choose two answers)
A. Reconnaissance
B. Discovery
C. Initial Access
D. Defense Evasion
عرض الإجابة
اجابة صحيحة: AC
السؤال #18
Which two ways can you create an incident on FortiAnalyzer? (Choose two answers)
A. Using a custom event handler
B. Using a connector action
C. Manually, on the Event Monitor page
D. By running a playbook
عرض الإجابة
اجابة صحيحة: AD
السؤال #19
Refer to the exhibit.How do you add a piece of evidence to the Action Logs Marked As Evidence area? (Choose one answer)
A. By tagging output or a workspace comment with the keyword Evidence
B. By linking an indicator to the war room
C. By creating an evidence collection task and attaching a file
D. By executing a playbook with the Save Execution Logs option enabled
عرض الإجابة
اجابة صحيحة: A
السؤال #20
Refer to the exhibit.How do you add a piece of evidence to the Action Logs Marked As Evidence area? (Choose one answer)
A. By tagging output or a workspace comment with the keyword Evidence
B. By linking an indicator to the war room
C. By creating an evidence collection task and attaching a file
D. By executing a playbook with the Save Execution Logs option enabled
عرض الإجابة
اجابة صحيحة: A
السؤال #21
When you use a manual trigger to save user input as a variable, what is the correct Jinja expression to reference the variable? (Choose one answer)
A. {{ vars
B. {{ globalVars
C. {{ vars
D. {{ vars
عرض الإجابة
اجابة صحيحة: A
السؤال #22
Refer to the exhibits.Assume that the traffic flows are identical, except for the destination IP address. There is only one FortiGate in network address translation (NAT) mode in this environment.Based on the exhibits, which two conclusions can you make about this FortiSIEM incident? (Choose two answers)
A. The client 10
B. FortiGate is not routing the packets to the destination hosts
C. The destination hosts are not responding
D. FortiGate is blocking the return flows
عرض الإجابة
اجابة صحيحة: AC
السؤال #23
Which three are threat hunting activities? (Choose three.)
A. Generate a hypothesis
B. Tune correlation rules
C. Perform packet analysis
D. Automate workflows
E. Enrich records with threat intelligence
عرض الإجابة
اجابة صحيحة: ACE

View The Updated Fortinet Exam Questions

SPOTO Provides 100% Real Fortinet Exam Questions for You to Pass Your Fortinet Exam!

عرض الإجابات بعد التقديم

يرجى إرسال البريد الإلكتروني الخاص بك والواتس اب للحصول على إجابات الأسئلة.

ملحوظة: يرجى التأكد من صلاحية معرف البريد الإلكتروني وWhatsApp حتى تتمكن من الحصول على نتائج الاختبار الصحيحة.

بريد إلكتروني:
رقم الواتس اب/الهاتف:
Contact Us