Fortinet FCP_FSM_AN-7.2更新版、FCP_FSM_AN-7.2キャリアパスあなたに安心にFortinetのFCP_FSM_AN-7.2ソフトを購入させるために、我々は最も安全的な支払手段を提供します。PayPalは国際的に最大の安全的な支払システムです。そのほかに、我々はあなたの個人情報の安全性を保証します。FortinetのFCP_FSM_AN-7.2試験の資料についてあなたは何か問題があったら、それとも、ほかの試験ソフトに興味があったら、直ちにオンラインで我々を連絡したり、メールで問い合わせたりすることができます。我々は尽力してあなたにFortinetのFCP_FSM_AN-7.2試験に合格させます。 Fortinet FCP - FortiSIEM 7.2 Analyst 認定 FCP_FSM_AN-7.2 試験問題 (Q20-Q25):質問 # 20
Refer to the exhibit.
What happens when an analyst clears an incident generated by a rule containing the automation policy shown in the exhibit?
A. The remediation script is run.
B. An email is sent to the SOC manager.
C. A notification is sent to the SOC manager dashboard.
D. No notification is sent.
正解:D
解説:
The automation policy has the option "Do not notify when an incident is cleared manually" enabled. Therefore, when an analyst manually clears an incident, no notification or automation action is triggered.
質問 # 21
Refer to the exhibit.
What is the Group: FortiSIEM Analysts value referring to?
A. Windows Active Directory user group
B. FortiSIEM organization group
C. LDAP user group
D. CMDB user group
正解:D
解説:
In FortiSIEM, the value Group: FortiSIEM Analysts under the User attribute refers to a CMDB user group. These groups are defined within FortiSIEM's CMDB and used to logically organize users for analytics, correlation rules, and reporting.
質問 # 22
Refer to the exhibit.
If you group the events by User and Count attributes, how many results will FortiSIEM display?
A. Three
B. Six
C. Five
D. One
E. Two
正解:C
解説:
Grouping by User and Count yields five unique pairs: (Mike,4), (Bob,3), (Alice,2), (Bob,6), (Mike,5).
質問 # 23
Refer to the exhibit.
If you group the events by Reporting Device, Reporting IP, and Application Category, how many results will FortiSIEM display?
A. Six
B. Four
C. Five
D. One
E. Two
正解:C
解説:
Grouping by Reporting Device, Reporting IP, and Application Category yields five unique tuples: (FW01, 10.1.1.1, DB), (FW02, 10.1.1.2, WebApp), (FW01, 10.1.1.1, SSH), (FW03, 10.1.1.3, DB), and (FW04, 10.1.1.4, SSH).
質問 # 24
Refer to the exhibit.
According to the automation policy configuration shown in the exhibit, what happens if an associated rule triggers?
A. FortiSIEM performs all selected actions.
B. FortiSIEM fails to the integration policy, because no policy is defined.
C. FortiSIEM runs the remediation script, because that takes precedence over all other options.
D. FortiSIEM sends an email, because that is first on the list.
正解:A
解説:
When an associated rule triggers, FortiSIEM performs all selected actions in the automation policy. In this case, it will send an email/SMS/webhook, run the remediation script, invoke the integration policy (even if none is currently defined), and create a case. All checked actions are executed.