A FortiSIEM administrator wants to restrict a network administrator to running searches for only
firewall devices. Under role management, which option does the FortiSIEM administrator need to
configure to achieve this scenario?
A.CMDBReportConditions
B.DataConditions
C. UI Access
B
A FortiSIEM supervisor at headquarters is struggling to keep up with an increase of EPS (Events Per
Second) being reported across the enterprise. What components should an administrator consider
deploying to assist the supervisor with processing data?
A.Supervisor
B. Worker
C. Collector
D. Agent
B
What protocol can be used to collect Windows event logs in an agentless method?
A.SSH
B.SNMP
C.WMI
D. SMTP
C
What
operating
system
is
FortiSIEM
based
on?
A.CentOS
B.MicrosoftWindows
C.RedHat
D. Ubuntu
A
To determine SNMP discovery issues, which is the best command from the backend?
A.snmpwalk
B.phSNMPTest
C.snmptest
D. ssh
A
Which
item
is
required
to
register
a
FortiSIEM
appliance
license?
A.Staticstorage
B.StaticMACaddress
C.StaticIPaddress
D. Static Hardware ID
D
What is the best discovery scan option for a network environment where ping is disabled on all
network
devices?
A.Smartscan
B.Rangescan
C.CMDBscan
D. L2 scan
A
Which protocol is almost always required for the FortiSIEM GUI discovery process?
A.SNMP
B.WMI
C.Syslog
D. Telnet
A
To determine whether or not syslog is being received from a network device, which is the best
command
from
the
backend?
A.tcpdump
B.phDeviceTest
C.netcat
D. phSyslogRecorder
A
What are the minimum memory requirements for the FortiSIEM supervisor virtual appliance, when
the
proprietary
flat
file
database
is
used?
A.16GBRAM
B.32GBRAM
C.64GBRAM
D. 24GB RAM
D
Which two export methods are available for FortiSIEM analytics results? (Choose two.)
A.CSV
B.PNG
C.HTML
D. PDF
AD
What is a prerequisite for a FortiSIEM supervisor with a worker deployment, using the proprietary
flat file database?
A.The
CMDB
database
must
be
on
NFS
B.The
event
database
must
be
on
NFS
C.The
event
database
must
be
on
a
local
disk
D. The \archive mount must be on a local disk
B
An administrator wants to search for events received from Linux and Windows agents.
Which attribute should the administrator use in search filters, to view events received from agents
only.
A
If a performance rule is triggered repeatedly due to high CPU use. what occurs m the incident table?
A
What is a prerequisite for FortiSIEM Linux agent installation?
D
Data Conditions