What protocol can be used to collect Windows event logs in an agentless method?

What protocol can be used to collect Windows event logs in an agentless method?A . SSHB . SNMPC . WMID . SMTPView AnswerAnswer: C

September 23, 2023 No Comments READ MORE +

If a performance rule is triggered repeatedly due to high CPU use. what occurs m the incident table?

If a performance rule is triggered repeatedly due to high CPU use. what occurs m the incident table?A . A new incident is created each time the rule is triggered, and the First Seen and Last Seen times are updated.B . The incident status changes to Repeated and the First...

September 21, 2023 No Comments READ MORE +

To determine whether or not syslog is being received from a network device, which is the best command from the backend?

To determine whether or not syslog is being received from a network device, which is the best command from the backend?A . tcpdumpB . phDeviceTestC . netcatD . phSyslogRecorderView AnswerAnswer: A

September 20, 2023 No Comments READ MORE +

What operating system is FortiSIEM based on?

What operating system is FortiSIEM based on?A . Cent OSB . Microsoft WindowsC . RedHatD . UbuntuView AnswerAnswer: A

September 19, 2023 No Comments READ MORE +

If the reported packet loss is between 50% and 98%. which status is assigned to the device in the Availability column of summary dashboard?

If the reported packet loss is between 50% and 98%. which status is assigned to the device in the Availability column of summary dashboard?A . Down status is assigned because of packet loss. B. Up status is assigned because of received packets C. Critical status is assigned because of reduction...

April 22, 2023 No Comments READ MORE +

Which FortiSIEM components are capable of performing device discovery?

Which FortiSIEM components are capable of performing device discovery?A . FortiSIEM Windows agent B. Worker C. FortiSIEM Linux agent D. CollectorView AnswerAnswer: D

April 21, 2023 No Comments READ MORE +

In FotiSlEM enterprise licensing mode, if the link between the collector and data center FortiSlEM cluster a down what happens?

In FotiSlEM enterprise licensing mode, if the link between the collector and data center FortiSlEM cluster a down what happens?A . The collector drops incoming events like syslog. but slops performance collection B. The collector continues performance collection of devices, but stops receiving syslog C. The collector buffers events D....

April 21, 2023 No Comments READ MORE +

To determine whether or not syslog is being received from a network device, which is the best command from the backend?

To determine whether or not syslog is being received from a network device, which is the best command from the backend?A . tcpdump B. phDeviceTest C. netcat D. phSyslogRecorderView AnswerAnswer: A

April 21, 2023 No Comments READ MORE +

If a performance rule is triggered repeatedly due to high CPU use. what occurs m the incident table?

If a performance rule is triggered repeatedly due to high CPU use. what occurs m the incident table?A . A new incident is created each time the rule is triggered, and the First Seen and Last Seen times are updated. B. The incident status changes to Repeated and the First...

April 20, 2023 No Comments READ MORE +

Under role management, which option does the FortiSIEM administrator need to configure to achieve this scenario?

A FortiSIEM administrator wants to restrict a network administrator to running searches for only firewall devices. Under role management, which option does the FortiSIEM administrator need to configure to achieve this scenario?A . CMDB Report Conditions B. Data Conditions C. UI AccessView AnswerAnswer: B

April 20, 2023 No Comments READ MORE +