Free NSE7_ADA-6.3 Exam Braindumps (page: 4)

Page 3 of 10

Refer to the exhibit.



An administrator wants to remediate the incident from FortiSIEM shown in the exhibit.

What option is available to the administrator?

  1. Quarantine IP FortiClient
  2. Run the block MAC FortiOS.
  3. Run the block IP FortiOS 5.4
  4. Run the block domain Windows DNS

Answer(s): C

Explanation:

The incident from FortiSIEM shown in the exhibit is a brute force attack on a FortiGate device. The remediation option available to the administrator is to run the block IP FortiOS 5.4 action, which will block the source IP address of the attacker on the FortiGate device using a firewall policy.



Refer to the exhibit.



The window for this rule is 30 minutes.

What is this rule tracking?

  1. A sudden 50% increase in WMI response times over a 30-minute time window
  2. A sudden 1.50 times increase in WMI response times over a 30-minute time window
  3. A sudden 75% increase in WMI response times over a 30-minute time window
  4. A sudden 150% increase in WMI response times over a 30-minute time window

Answer(s): B

Explanation:

The rule is tracking the WMI response times from Windows devices using a baseline calculation. The rule will trigger an incident if the current WMI response time is greater than or equal to 1.50 times the average WMI response time in the last 30 minutes.



Which three processes are collector processes? (Choose three.)

  1. phAgentManaqer
  2. phParser
  3. phRuleMaster
  4. phReportM aster
  5. phMonitorAgent

Answer(s): B,C,E

Explanation:

The collector processes are responsible for receiving, parsing, normalizing, correlating, and monitoring events from various sources. The collector processes are phParser, phRuleMaster, and phMonitorAgent.



Which statement about EPS bursting is true?

  1. FortiSIEM will let you burst up to five times the licensed EPS once during a 24-hour period.
  2. FortiSIEM must be provisioned with ten percent the licensed EPS to handle potential event surges.
  3. FortiSIEM will let you burst up to five times the licensed EPS at any given time, provided it has accumulated enough unused EPS.
  4. FortiSIEM will let you burst up to five times the licensed EPS at any given time, regardless of unused of EPS.

Answer(s): C

Explanation:

FortiSIEM allows EPS bursting to handle event spikes without dropping events or violating the license agreement. EPS bursting means that FortiSIEM will let you burst up to five times the licensed EPS at any given time, provided it has accumulated enough unused EPS from previous time intervals.






Post your Comments and Discuss Fortinet NSE7_ADA-6.3 exam with other Community members: