FCSS_ADA_AR-6.7 FCSS Advanced Analytics 6.7 Architect Questions and Answers
Refer to the exhibit.

This is an example of a baseline profile that is configured in the backend of FortiSIEM.
Which two Group By attributes are configured for this profile? (Choose two.)
Refer to the exhibit.

Which three fields from the organization destination are required while registering a collector? (Choose three.)
Refer to the exhibit.

Which statement about the rule filters events shown in the exhibit is true?
A service provider purchased a 500-EPS license and configured a new collector with 100 EPS for customer A, and another collector with 200 EPS for customer B.
How much is in the remaining EPS pool for future customers and for MSSP itself?
Refer to the exhibit.

Why is the windows device still in the CMDB, even though the administrator uninstalled the windows agent?
Refer to the exhibit.

If the Z-score for this rule is greater than or equal to three, what does this mean?
Why do collectors communicate with the Supervisor after registration? (Choose two.)



This means the rule will match events where the event type is classified under the Domain Account Locked category.
This means the rule is filtering for events where the reporting IP is classified under the Domain Controller applications group .
The filters are combined using AND , meaning both conditions must be met for an event to match.

If a worker node fails , the collector can temporarily store event logs and then forward them to the Supervisor.
This ensures event continuity even during infrastructure issues.
The collector sends health reports to the Supervisor , including resource usage, connectivity status, and operational logs.
This helps FortiSIEM track collector uptime and performance .