Refer to the exhibit.

Why was this incident auto cleared?
A. Within five minutes the packet loss percentage dropped to a level where the reporting IP is the same as the host IP
B. The original rule did not trigger within five minutes
C. Within five minutes, the packet loss percentage dropped to a level where the reporting IP is same as the source IP
D. Within five minutes, the packet loss percentage dropped to a level where the host IP of the original rule matches the host IP of the clear condition pattern
What happens to UEBA events when a user is off-net?
A. The agent will upload the events to the Worker if it cannot upload them to a FortiSIEM collector
B. The agent will cache events locally if it cannot upload them to a FortiSIEM collector
C. The agent will upload the events to the Supervisor if it cannot upload them to a FortiSIEM collector
D. The agent will drop the events if it cannot upload them to a FortiSIEM collector
Which syntax will register a collector to the supervisor?
A. phProvisionCollector --add
B. phProvisionCollector --add
C. phProvisionCollector --add
D. phProvisionCollector --add
Refer to the exhibit.

The window for this rule is 30 minutes. What is this rule tracking?
A. A sudden 50% increase in WMI response times over a 30-minute time window
B. A sudden 1.50 times increase in WMI response times over a 30-minute time window
C. A sudden 75% increase in WMI response times over a 30-minute time window
D. A sudden 150% increase in WMI response times over a 30-minute time window
Refer to the exhibit.

The service provider deployed FortiSIEM without a collector and added three customers on the supervisor. What mistake did the administrator make?
A. Customer A and customer B have overlapping IP addresses.
B. Collectors must be deployed on all customer premises before they are added to organizations on the supervisor.
C. The number of workers on the FortiSIEM cluster must match the number of customers added.
D. At least one collector must be deployed to collect logs from service provider infrastructure devices.
How can you invoke an integration policy on FortiSIEM rules?
A. Through Notification Policy settings
B. Through Incident Notification settings
C. Through remediation scripts
D. Through External Authentication settings
What is Tactic in the MITRE ATTandCK framework?
A. Tactic is how an attacker plans to execute the attack
B. Tactic is what an attacker hopes to achieve
C. Tactic is the tool that the attacker uses to compromise a system
D. Tactic is a specific implementation of the technique
Refer to the exhibit.

Why is the windows device still in the CMDB, even though the administrator uninstalled the windows agent?
A. The device was not uninstalled properly
B. The device must be deleted from backend of FortiSIEM
C. The device has performance jobs assigned
D. The device must be deleted manually from the CMDB
Which statement about EPS bursting is true?
A. FortiSIEM will let you burst up to five times the licensed EPS once during a 24-hour period.
B. FortiSIEM must be provisioned with ten percent the licensed EPS to handle potential event surges.
C. FortiSIEM will let you burst up to five times the licensed EPS at any given time, provided it has accumulated enough unused EPS.
D. FortiSIEM will let you burst up to five times the licensed EPS at any given time, regardless of unused of EPS.
From where does the rule engine load the baseline data values?
A. The profile report
B. The daily database
C. The profile database
D. The memory