FortiSIEM is deployed in disaster recovery mode.
When disaster strikes, which two tasks must you perform manually to achieve a successful disaster recovery operation? (Choose two.)
Which FortiSIEM feature must you use to produce a report on which FortiGate devices in your environment are running which firmware version?
Refer to the exhibit.

It events are grouped by Event Type and User attributes in FortiSIEM. how many results will be displayed?
Which two FortiSIEM components work together to provide real-time event correlation?
Refer to the exhibits.


Three events are collected over a 10-minute time period from two servers: Server A and Server B.
Based on the settings tor the rule subpattern. how many incidents will the servers generate?
Consider the storage of anomaly baseline date that is calculated for different parameters. Which database is used for storing this data?
Refer to the exhibit.

What do the yellow stars listed in the Monitor column indicate?
An administrator wants to search for events received from Linux and Windows agents.
Which attribute should the administrator use in search filters, to view events received from agents only.
Refer to the exhibit.

If events are grouped by User. Source IP. and Application Category attributes in FortiSiEM. how many results will be displayed?
Where do you configure rule notifications and automated remediation on FortiSIEM?
An administrator is in the process of renewing a FortiSIEM license. Which two commands will provide the system ID? (Choose two.)
A customer is experiencing slow performance while executing long, adhoc analytic searches. Which FortiSIEM component can make the searches run faster?
In which state can a device be moved into the CMDB to prevent monitoring log collection?
In FortiSIEM enterprise licensing mode, it the link between the collector and data center FortiSlEM cluster is down, what happens?