FORTISIEM Architecture

FORTISIEM Architecture

Assessment

Quiz

Other

Professional Development

Medium

Created by

Zcire Delmendo

Used 1+ times

FREE Resource

Student preview

quiz-placeholder

8 questions

Show all answers

1.

MULTIPLE SELECT QUESTION

45 sec • 2 pts

Which of the following Linux OSs supports Linux Agent (Choose two).

Cent OS 6.x

Amazon Linux 2

Tiny Core Linux

Kali Linux

2.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which worker only handle all other event processing jobs, including receiving events from collectors or devices, and storing them into the event database, rule, inline query, real time query, and so on.

Query worker

Supervisor worker

Elastic search worker

Event worker

3.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

What are the minimum memory requirements for the FortiSIEM supervisor virtual appliance, when the elastic search database is used?

16GB RAM

24GB RAM

32GB RAM

64GB RAM

4.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

What are the minimum memory requirements for the FortiSIEM supervisor virtual appliance, when the proprietary flat file database is used?

16GB RAM

24GB

32GB RAM

64GB RAM

5.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

A FortiSIEM supervisor at headquarters is struggling to keep up with an increase of EPS (Events Per Second) being reported across the enterprise. What components should an administrator consider deploying to assist the supervisor with processing data?

Supervisor

Worker

Collector

Agents

6.

MULTIPLE SELECT QUESTION

45 sec • 2 pts

Which two FortiSIEM components are capable of performing discovery?

Worker

Collector

FortiSIEM Windows Agent

Supervisor

7.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

What is a prerequisite for a FortiSIEM supervisor with a worker deployment, using the proprietary flat file database?

The CMDB database must be on NFS

The event database must be on NFS

The event database must be on a local disk

The \archive mount must be on a local disk

8.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which database is used for storing anomaly data that is calculated for different parameters, such as traffic and device resource usage running averages and standard deviation values?

Profile DB

Event DB

CMDB

SVN DB