Free FCSS-ADA-AR-6-7 sample questions
Real questions from the Fortinet FCSS Advanced Analytics 6.7 Architect practice bank, with the correct answer and an explanation for each one. No junk, no filler.
Try them in the simulator Same questions, with study, timed and flashcard modes.
Showing 10 of 20 free sample questions.
A security analyst needs to create a FortiSIEM rule that detects a user logging in successfully from two different countries within a 10-minute window. Which rule components are essential for this detection logic? (Select TWO)
An administrator at a financial institution has configured a baseline profile to monitor the number of daily failed credit card transactions for each customer. The learning period was set to 14 days. After 20 days, the baseline rule is generating a high number of false positive alerts. What is the most likely cause of the false positives?
A SOC has integrated FortiSIEM with FortiSOAR to automate responses to malware detection incidents. An analyst observes that when a malware incident is triggered in FortiSIEM, a ticket is created in FortiSOAR, but the associated playbook to isolate the endpoint fails to execute. The FortiSOAR connector test is successful. What is the most probable cause of this issue?
True or False: In a multi-tenant FortiSIEM environment, a report created by an MSSP administrator for a specific customer organization is automatically visible to all other customer organizations.
A security architect is using a lookup table to enrich firewall logs with information about internal application owners. The lookup table is a CSV file containing `IP_Address`, `AppName`, and `AppOwnerEmail`. The architect needs to add the `AppOwnerEmail` to any firewall log where the `srcIp` matches an `IP_Address` in the table. Which function or method should be used within a rule's display fields to achieve this?
A hospital's security team wants to use FortiSIEM UEBA to detect anomalous access to its Electronic Health Record (EHR) database. They have deployed UEBA agents on the database servers. Which of the following UEBA models would be most effective at detecting a compromised administrator account that starts accessing an unusually high number of unique patient records?
The command to run a remediation script on FortiSIEM for an incident is found to be failing. The script is a Python script intended to add an IP to a blocklist on a FortiGate. Which of the following is the BEST first step to troubleshoot the issue?
An MSSP is configuring event parsing for a new customer's bespoke application. The logs are unstructured and require a complex parsing logic that involves conditional matching and data extraction. The performance of the collector processing these logs is critical. Which FortiSIEM component should the architect use to define this parsing logic?
A FortiSIEM rule is configured to detect '5 failed logins followed by 1 successful login for the same user from the same IP address within 2 minutes'. This is an example of what type of rule?
10 more free samples are waiting
Create a free account to unlock the whole FCSS-ADA-AR-6-7 sample bank, or get full access to all 208 practice questions in the simulator.