Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Vce NSE6_FSM_AN-7.4 Questions Latest

Fortinet NSE 6 - FortiSIEM 7.4 Analyst Questions and Answers

Question 9

Refer to the exhibit.

How was this incident cleared?

Options:

A.

The analyst manually cleared the incident from the incident table.

B.

FortiSIEM cleared the incident automatically after 24 hours.

C.

The incident was cleared automatically by the rule.

D.

The endpoint was rebooted and sent an all-clear signal to FortiSIEM.

Question 10

Refer to the exhibit.

Which two actions can you select in an automation policy to trigger an API call to block an IP address on a FortiGate? (Choose two.)

Options:

A.

Open Remedy ticket using the configuration set in Analytics.

B.

Send Email/SMS/Webhook to the target users.

C.

Invoke an Integration Policy.

D.

Run Remediation/Script.

E.

Run Playbook on Incident Trigger.

Question 11

Refer to the exhibit.

Which value would you expect the FortiSIEM parser to use to populate the Application Name field?

Options:

A.

applist

B.

Network.Service

C.

SSL

D.

wan1

Question 12

Refer to the exhibit.

An analyst is troubleshooting the rule shown in the exhibit. It is not generating any incidents, but the filter parameters are generating events on the Analytics tab.

What is wrong with the rule conditions?

Options:

A.

The Event Type refers to a CMDB lookup and should be an Event lookup.

B.

The Destination Host Name value is not fully qualified.

C.

The Group By attributes restricts which events are counted.

D.

The Aggregate attribute is too restrictive.