Pre-Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: get65

Fortinet Updated NSE7_SOC_AR-7.6 Exam Questions and Answers by arla

Page: 4 / 4

Fortinet NSE7_SOC_AR-7.6 Exam Overview :

Exam Name: Fortinet NSE 7 - Security Operations 7.6 Architect
Exam Code: NSE7_SOC_AR-7.6 Dumps
Vendor: Fortinet Certification: Fortinet Certified Professional Security Operations
Questions: 57 Q&A's Shared By: arla
Question 16

Refer to the exhibit.

You notice that the custom event handler you configured to detect SMTP reconnaissance activities is creating a large number of events. This is overwhelming your notification system.

How can you fix this?

Options:

A.

Increase the trigger count so that it identifies and reduces the count triggered by a particular group.

B.

Disable the custom event handler because it is not working as expected.

C.

Decrease the time range that the custom event handler covers during the attack.

D.

Increase the log field value so that it looks for more unique field values when it creates the event.

Discussion
Question 17

While monitoring your network, you discover that one FortiGate device is sending significantly more logs to FortiAnalyzer than all of the other FortiGate devices in the topology.

Additionally, the ADOM that the FortiGate devices are registered to consistently exceeds its quota.

What are two possible solutions? (Choose two.)

Options:

A.

Increase the storage space quota for the first FortiGate device.

B.

Create a separate ADOM for the first FortiGate device and configure a different set of storage policies.

C.

Reconfigure the first FortiGate device to reduce the number of logs it forwards to FortiAnalyzer.

D.

Configure data selectors to filter the data sent by the first FortiGate device.

Discussion
Page: 4 / 4

NSE7_SOC_AR-7.6
PDF

$36.75  $104.99

NSE7_SOC_AR-7.6 Testing Engine

$43.75  $124.99

NSE7_SOC_AR-7.6 PDF + Testing Engine

$57.75  $164.99