問題1
Your company is doing a security audit To pass the audit, you must take an inventory of all software and applications running on all Windows devices Which FortiAnalyzer connector must you use?
Your company is doing a security audit To pass the audit, you must take an inventory of all software and applications running on all Windows devices Which FortiAnalyzer connector must you use?
正確答案: B
說明:(僅 NewDumps 成員可見)
問題2
Refer to the exhibit,

which shows the partial output of the MITRE ATT&CK Enterprise matrix on FortiAnalyzer.
Which two statements are true? (Choose two.)
Refer to the exhibit,

which shows the partial output of the MITRE ATT&CK Enterprise matrix on FortiAnalyzer.
Which two statements are true? (Choose two.)
正確答案: A,D
說明:(僅 NewDumps 成員可見)
問題3
In configuring FortiAnalyzer collectors, what should be prioritized to manage large volumes of data efficiently?
In configuring FortiAnalyzer collectors, what should be prioritized to manage large volumes of data efficiently?
正確答案: D
問題4
While monitoring your network, you discover that one FortiGate device is sending significantly more logs to FortiAnalyzer than all of the other FortiGate devices in the topology.
Additionally, the ADOM that the FortiGate devices are registered to consistently exceeds its quota.
What are two possible solutions? (Choose two.)
While monitoring your network, you discover that one FortiGate device is sending significantly more logs to FortiAnalyzer than all of the other FortiGate devices in the topology.
Additionally, the ADOM that the FortiGate devices are registered to consistently exceeds its quota.
What are two possible solutions? (Choose two.)
正確答案: B,C
說明:(僅 NewDumps 成員可見)
問題5
Which statement best describes the MITRE ATT&CK framework?
Which statement best describes the MITRE ATT&CK framework?
正確答案: C
說明:(僅 NewDumps 成員可見)
問題6
Which trigger type requires manual input to run a playbook?
Which trigger type requires manual input to run a playbook?
正確答案: A
問題7
Refer to the exhibit.

You notice that the custom event handler you configured to detect SMTP reconnaissance activities is creating a large number of events. This is overwhelming your notification system.
How can you fix this?
Refer to the exhibit.

You notice that the custom event handler you configured to detect SMTP reconnaissance activities is creating a large number of events. This is overwhelming your notification system.
How can you fix this?
正確答案: C
說明:(僅 NewDumps 成員可見)
問題8
What should be prioritized when analyzing threat hunting information feeds?
(Choose Two)
What should be prioritized when analyzing threat hunting information feeds?
(Choose Two)
正確答案: C,D
問題9
Refer to the exhibits.

The FortiMail Sender Blocklist playbook is configured to take manual input and add those entries to the FortiMail abc. com domain-level block list. The playbook is configured to use a FortiMail connector and the ADD_SENDER_TO_BLOCKLIST action.
Why is the FortiMail Sender Blocklist playbook execution failing7
Refer to the exhibits.

The FortiMail Sender Blocklist playbook is configured to take manual input and add those entries to the FortiMail abc. com domain-level block list. The playbook is configured to use a FortiMail connector and the ADD_SENDER_TO_BLOCKLIST action.
Why is the FortiMail Sender Blocklist playbook execution failing7
正確答案: B
說明:(僅 NewDumps 成員可見)