Fortinet FCSS—Advanced Analytics 6.7 Architect - FCSS_ADA_AR-6.7 Exam Practice Test
Question 1
Refer to the exhibit.

The exhibit shows the output of an SQL command that an administrator ran to view the natural_id value, after logging into the Postgres database.
What does the natural_id value identify?

The exhibit shows the output of an SQL command that an administrator ran to view the natural_id value, after logging into the Postgres database.
What does the natural_id value identify?
Correct Answer: C
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 2
Refer to the exhibit.

Which devices will be added to the CMDB and mapped to Customer E?

Which devices will be added to the CMDB and mapped to Customer E?
Correct Answer: A,B
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 3
From where does the rule engine load the baseline data values?
Correct Answer: A
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 4
Which statement about EPS bursting is true?
Correct Answer: D
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 5
Refer to the exhibit.

How long has the UEBA agent been operationally down?

How long has the UEBA agent been operationally down?
Correct Answer: A
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 6
Refer to the exhibit.

The window for this rule is 30 minutes.
What is this rule tracking?

The window for this rule is 30 minutes.
What is this rule tracking?
Correct Answer: C
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).
Question 7
Refer to the exhibit.

Consider the five account locked events received by FortiSIEM from domain controllers within the last 10 minutes (ten minutes is the evaluation window for the subpattern DomainAcctLockout):

If you look for one or more matching events and groupings by the same reporting IP address, reporting device, and user, how many incidents are created?

Consider the five account locked events received by FortiSIEM from domain controllers within the last 10 minutes (ten minutes is the evaluation window for the subpattern DomainAcctLockout):

If you look for one or more matching events and groupings by the same reporting IP address, reporting device, and user, how many incidents are created?
Correct Answer: A
Explanation: Only visible for Actualtests4sure members. You can sign-up / login (it's free).

