Which two statements about the maximum device limit on FortiSIEM are true? (Choose two.)
A. The device limit is defined per customer and every customer is assigned a fixed number of device limit by the service provider.
B. The device limit is only applicable to enterprise edition.
C. The device limit is based on the license type that was purchased from Fortinet.
D. The device limit is defined for the whole system and is shared by every customer on a service provider edition.
Refer to the exhibit.

Why was this incident auto cleared?
A. Within five minutes the packet loss percentage dropped to a level where the reporting IP is the same as the host IP
B. The original rule did not trigger within five minutes
C. Within five minutes, the packet loss percentage dropped to a level where the reporting IP is same as the source IP
D. Within five minutes, the packet loss percentage dropped to a level where the host IP of the original rule matches the host IP of the clear condition pattern
On which disk are the SQLite databases that are used for the baselining stored?
A. Disk1
B. Disk4
C. Disk2
D. Disk3
Refer to the exhibit.

An administrator deploys a new collector for the first time, and notices that all the processes except the phMonitor are down. How can the administrator bring the processes up?
A. The administrator needs to run the command phtools --start all on the collector.
B. Rebooting the collector will bring up the processes.
C. The processes will come up after the collector is registered to the supervisor.
D. The collector was not deployed properly and must be redeployed.
Refer to the exhibit.

If the Z-score for this rule is greater than or equal to three, what does this mean?
A. The rate of firewall connection is optimum.
B. The rate of firewall connection is above the historical average value.
C. The rate of firewall connection is above the current average value.
D. The rate of firewall connection is below historical average value.
Refer to the exhibit. Click on the calculator button.

Based on the information provided in the exhibit, calculate the unused events for the next three minutes for a 520 EPS license.
A. 72460
B. 73460
C. 74460
D. 71460
Which syntax will register a collector to the supervisor?
A. phProvisionCollector --add
B. phProvisionCollector --add
C. phProvisionCollector --add
D. phProvisionCollector --add
How can you empower SOC by deploying FortiSOAR? (Choose three.)
A. Aggregate logs from distributed systems
B. Collaborative knowledge sharing
C. Baseline user and traffic behavior
D. Reduce human error
E. Address analyst skills gap
Which statement about EPS bursting is true?
A. FortiSIEM will let you burst up to five times the licensed EPS once during a 24-hour period.
B. FortiSIEM must be provisioned with ten percent the licensed EPS to handle potential event surges.
C. FortiSIEM will let you burst up to five times the licensed EPS at any given time, provided it has accumulated enough unused EPS.
D. FortiSIEM will let you burst up to five times the licensed EPS at any given time, regardless of unused of EPS.
Identify the processes associated with Machine Learning/Al on FortiSIEM. (Choose two.)
A. phFortiInsightAI
B. phReportMaster
C. phRuleMaster
D. phAnomaly
E. phRuleWorker