C&D is correct answer : This is from Fortinet 6.2 Training: WMl: A Windows API that gets system information from a Windows server. The DC returns
all requested logon events. The collector agent is a WMI client and sends WMI queries for user logon events to
the DC, which, in this case, is a WMI server. The collector agent doesn't need to search security event logs on the
DC for user logon events; instead, the DC returns all requested logon events. This reduces network load between
the collector agent and DC.
, DC returns all requested logon events via WMI. This also reduces network load between CA and DC.
it means WMI decrease bandwidth usage instead of increasing it....
so B is not correct.
C & D is
3) Event log using WMI polling: WMI is a Windows API to get system information from a Windows server, CA is a WMI client and sends WMI queries for user logon events to DC, which in this case is a WMI server. Main advantage in this mode is that CA does not need to search security event logs on DC for user logon events, instead, DC returns all requested logon events via WMI. This also reduces network load between CA and DC.
https://kb.fortinet.com/kb/documentLink.do?externalID=FD47732
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
topicx
Highly Voted 5 years, 7 months agot12345
5 years, 3 months agointaqto
Highly Voted 5 years, 2 months agorkchandra
Most Recent 3 years, 1 month agoalbato239
3 years, 5 months agomeli_ssa
4 years, 4 months agoCtnroger
4 years, 4 months agoEdy_Crank
4 years, 7 months agoipam
4 years, 8 months agocarroyoc
4 years, 10 months agogeorgianp
4 years, 9 months agomontonearm
5 years, 1 month ago