Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

FCSS_ADA_AR-6.7 FCSS Advanced Analytics 6.7 Architect Questions and Answers

Questions 4

Refer to the exhibit.

FCSS_ADA_AR-6.7 Question 4

This is an example of a baseline profile that is configured in the backend of FortiSIEM.

Which two Group By attributes are configured for this profile? (Choose two.)

Options:

A.

Logon Failure

B.

Reporting Device

C.

Reporting IP

D.

Distinct User

Buy Now
Questions 5

Refer to the exhibit.

FCSS_ADA_AR-6.7 Question 5

How long has the UEBA agent been operationally down?

Options:

A.

2 Hours

B.

20 Hours

C.

21 Hours

D.

9 Hours

Buy Now
Questions 6

What is the hourly bucket used in baselining?

Options:

A.

To store hourly baselines reports for every hour of the day during weekdays and weekends

B.

To store data for specific baselines during the weekend, if there is a spike in network activity

C.

To store data for specific baselines during peak business hours of weekdays

D.

To store data for specific baselines for every hour of the day during weekdays and weekends

Buy Now
Questions 7

Refer to the exhibit.

FCSS_ADA_AR-6.7 Question 7

Which three fields from the organization destination are required while registering a collector? (Choose three.)

Options:

A.

Account Number

B.

Admin Password

C.

Agent Password

D.

Organization

E.

Admin User

Buy Now
Questions 8

Refer to the exhibit.

FCSS_ADA_AR-6.7 Question 8

Within what time window is the incident auto cleared?

Options:

A.

1800 seconds

B.

Null

C.

1 day

D.

30 minutes

Buy Now
Questions 9

Which two statements about phRuleWorker are true? (Choose two.)

Options:

A.

phRuleWorker uses a 60-second bucket as an evaluation window.

B.

phRuleWorker evaluates non-aggregate conditions as defined in subpattern filters of a rule in memory.

C.

phRuleWorker exists on both the supervisor and workers.

D.

phRuleWorker exists on the worker only.

Buy Now
Questions 10

Refer to the exhibit.

FCSS_ADA_AR-6.7 Question 10

Which statement about the rule filters events shown in the exhibit is true?

Options:

A.

The rule filters events with an event type that equals Domain Account Locked and a reporting IP that equals Domain Controller applications.

B.

The rule filters events with an event type that belong to the Domain Account Locked CMDB group or a reporting IP that belong to the Domain Controller applications group.

C.

The rule filters events with an event type that belong to the Domain Account Locked CMDB group and a reporting IP that belong to the Domain Controller applications group.

D.

The rule filters events with an event type that belong to the Domain Account Locked CMDB group and a user that belongs to the Domain Controller applications group.

Buy Now
Questions 11

A service provider purchased a 500-EPS license and configured a new collector with 100 EPS for customer A, and another collector with 200 EPS for customer B.

How much is in the remaining EPS pool for future customers and for MSSP itself?

Options:

A.

30

B.

200

C.

100

D.

50

Buy Now
Questions 12

Which lookup table function can be either true or false?

Options:

A.

LookupTableHas

B.

LookupTableGet

C.

LookupTableFilter

D.

LookupTableRetriev

Buy Now
Questions 13

Refer to the exhibit.

FCSS_ADA_AR-6.7 Question 13

Why is the windows device still in the CMDB, even though the administrator uninstalled the windows agent?

Options:

A.

The device must be deleted from backend of FortiSIEM

B.

The device has performance jobs assigned

C.

The device was not installed properly

D.

The device must be deleted manually from the CMDB

Buy Now
Questions 14

Refer to the exhibit.

FCSS_ADA_AR-6.7 Question 14

Why was this incident auto cleared?

Options:

A.

Within five minutes, the packet loss percentage dropped to a level where the host IP of the original rule matches the host IP of the clear condition pattern

B.

Within five minutes the packet loss percentage dropped to a level where the reporting IP is the same as the host IP

C.

The original rule did not trigger within five minutes

D.

Within five minutes, the packet loss percentage dropped to a level where the reporting IP is same as the source IP

Buy Now
Questions 15

Refer to the exhibit.

FCSS_ADA_AR-6.7 Question 15

If the Z-score for this rule is greater than or equal to three, what does this mean?

Options:

A.

The rate of firewall connection is below historical average value.

B.

The rate of firewall connection is optimum.

C.

The rate firewall connection is above the historical average value.

D.

The rate of firewall connection is above the current average value.

Buy Now
Questions 16

How do customers connect to a shared multi-tenant instance on FortiSOAR?

Options:

A.

The customer must install a tenant node to connect to the MSSP shared multi-tenant instance.

B.

The MSSP must provide secure network connectivity between the FortiSOAR manager node and the customer devices.

C.

The MSSP must install a Secure Message Exchange node to connect to the customer’s shared multi-tenant instance.

D.

The MSSP must install an agent node on the customer’s network to connect to the customer ' s shared multi-tenant instance.

Buy Now
Questions 17

Why do collectors communicate with the Supervisor after registration? (Choose two.)

Options:

A.

To receive templates associated with agents

B.

To report the health status of the agents

C.

To upload event data if a worker down

D.

To report its own health status

Buy Now
Exam Code: FCSS_ADA_AR-6.7
Exam Name: FCSS Advanced Analytics 6.7 Architect
Last Update: May 20, 2026
Questions: 59

PDF + Testing Engine

$64.99   $185.69

Testing Engine

$49.99   $142.83

PDF (Q&A)

$54.99   $157.11