Free NSE7_ADA-6.3 Exam Braindumps (page: 2)

Page 1 of 9

How can you invoke an integration policy on FortiSIEM rules?

  1. Through Notification Policy settings
  2. Through Incident Notification settings
  3. Through remediation scripts
  4. Through External Authentication settings

Answer(s): A

Explanation:

You can invoke an integration policy on FortiSIEM rules by configuring the Notification Policy settings. You can select an integration policy from the drop-down list and specify the conditions for triggering it. For example, you can invoke an integration policy when an incident is created, updated, or closed.


Reference:

Fortinet NSE 7 - Advanced Analytics 6.3 Exam Description, page 9



How do customers connect to a shared multi-tenant instance on FortiSOAR?

  1. The MSSP must provide secure network connectivity between the FortiSOAR manager node and the customer devices.
  2. The MSSP must install a Secure Message Exchange node to connect to the customer's shared multi-tenant instance.
  3. The customer must install a tenant node to connect to the MSSP shared multi-tenant instance.
  4. The MSSP must install an agent node on the customer's network to connect to the customer's shared multi-tenant instance.

Answer(s): D

Explanation:

To connect to a shared multi-tenant instance on FortiSOAR, the MSSP must install an agent node on the customer's network. The agent node acts as a proxy between the customer's devices and the FortiSOAR manager node. The agent node also performs data collection, enrichment, and normalization for the customer's data sources.


Reference:

Fortinet NSE 7 - Advanced Analytics 6.3 Exam Description, page 11



In the event of a WAN link failure between the collector and the supervisor, by default, what is the maximum number of event files stored on the collector?

  1. 30.000
  2. 10.000
  3. 40.000
  4. 20.000

Answer(s): B

Explanation:

By default, the maximum number of event files stored on the collector in the event of a WAN link failure between the collector and the supervisor is 10.000. This value can be changed in the collector.properties file by modifying the parameter max_event_files_to_store.


Reference:

Fortinet NSE 7 - Advanced Analytics 6.3 Exam Description, page 13



What is the disadvantage of automatic remediation?

  1. It can make a disruptive change to a user, block access to an application, or disconnect critical systems from the network.
  2. It is equivalent to running an IPS in monitor-only mode -- watches but does not block.
  3. External threats or attacks detected by FortiSIEM will need user interaction to take action on an already overworked SOC team.
  4. Threat behaviors occurring during the night could take hours to respond to.

Answer(s): A

Explanation:

The disadvantage of automatic remediation is that it can make a disruptive change to a user, block access to an application, or disconnect critical systems from the network. Automatic remediation can have unintended consequences if not carefully planned and tested. Therefore, it is recommended to use manual or semi-automatic remediation for sensitive or critical systems.


Reference:

Fortinet NSE 7 - Advanced Analytics 6.3 Exam Description, page 15






Post your Comments and Discuss Fortinet NSE7_ADA-6.3 exam with other Community members:

NSE7_ADA-6.3 Discussions & Posts