Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free and Premium Fortinet NSE6_FSM_AN-7.4 Dumps Questions Answers

Fortinet NSE 6 - FortiSIEM 7.4 Analyst Questions and Answers

Question 1

Refer to the exhibit.

As shown in the exhibit, why are some of the fields highlighted in red?

Options:

A.

Unique values cannot be grouped

B.

The attribute COUNT(Matched Events) is an invalid expression.

C.

No RAW Event Log attribute information is available.

D.

The Event Receive Time attribute is not available for logs.

Buy Now
Question 2

How does FortiSIEM update the incident table if a performance rule triggers repeatedly?

Options:

A.

FortiSIEM changes the incident status to Repeated, and updates the Last Seen timestamp.

B.

FortiSIEM updates the Incident Count value and Last Seen timestamp.

C.

FortiSIEM generates a new incident based on the Rule Frequency value, and updates the First Seen and Last Seen timestamps.

D.

FortiSIEM generates a new incident each time the rule triggers, and updates the First Seen and Last Seen timestamps.

Question 3

How can you query the configuration management database (CMDB) in an analytics search?

Options:

A.

Click Value > Select from CMDB.

B.

On the CMDB tab, select an entry, and then click Create Search.

C.

On the Admin tab, click CMDB Search.

D.

Click Attribute > Select from CMDB.

Question 4

Refer to the exhibit.

If you group the events by User and Count attributes, how many results will FortiSIEM display?

Options:

A.

Two

B.

Six

C.

Three

D.

Five

E.

One

Question 5

What can you use to send data to FortiSIEM for user and entity behavior analytics (UEBA)?

Options:

A.

FortiSIEM agent

B.

SSH

C.

SNMP

D.

FortiSIEM worker

Question 6

Refer to the exhibit.

If you group the events by User , Source IP , and Count attributes, how many results will FortiSIEM display?

Options:

A.

Two

B.

Six

C.

Three

D.

Five

E.

Four

Question 7

Refer to the exhibit.

An analyst wants the rule shown in the exhibit to trigger when three failed login attempts occur within three minutes.

What should the values be for the condition time window and aggregate count?

Options:

A.

Time window 180 seconds, aggregate count 3

B.

Time window 180 seconds, aggregate count 2

C.

Time window 90 seconds, aggregate count 3

D.

Time window 90 seconds, aggregate count 2

Question 8

Which two data areas can you use for user and entity behavior analytics (EBA) machine learning models? (Choose two.)

Options:

A.

Process

B.

Location

C.

Resources

D.

Network

Question 9

Refer to the exhibit.

How was this incident cleared?

Options:

A.

The analyst manually cleared the incident from the incident table.

B.

FortiSIEM cleared the incident automatically after 24 hours.

C.

The incident was cleared automatically by the rule.

D.

The endpoint was rebooted and sent an all-clear signal to FortiSIEM.

Question 10

Refer to the exhibit.

Which two actions can you select in an automation policy to trigger an API call to block an IP address on a FortiGate? (Choose two.)

Options:

A.

Open Remedy ticket using the configuration set in Analytics.

B.

Send Email/SMS/Webhook to the target users.

C.

Invoke an Integration Policy.

D.

Run Remediation/Script.

E.

Run Playbook on Incident Trigger.

Question 11

Refer to the exhibit.

Which value would you expect the FortiSIEM parser to use to populate the Application Name field?

Options:

A.

applist

B.

Network.Service

C.

SSL

D.

wan1

Question 12

Refer to the exhibit.

An analyst is troubleshooting the rule shown in the exhibit. It is not generating any incidents, but the filter parameters are generating events on the Analytics tab.

What is wrong with the rule conditions?

Options:

A.

The Event Type refers to a CMDB lookup and should be an Event lookup.

B.

The Destination Host Name value is not fully qualified.

C.

The Group By attributes restricts which events are counted.

D.

The Aggregate attribute is too restrictive.

Question 13

Refer to the exhibit.

What will happen when a device being analyzed by the machine learning configuration shown in the exhibit has consistently high memory utilization?

Options:

A.

FortiSIEM will update the regression tables for memory utilization, and average sent and received bytes.

B.

FortiSIEM will trigger an incident for high memory utilization.

C.

FortiSIEM will lower the CPU utilization trigger requirement for CPU utilization.

D.

FortiSIEM will update the model with a higher memory utilization average value.

Question 14

Refer to the exhibit.

Which section contains the subpattern configuration that determines how many matching events are needed to trigger the rule?

Options:

A.

Aggregate

B.

Group By

C.

Actions

D.

Filters