Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Fortinet NSE5_FSM-6.3 - Fortinet NSE 5 - FortiSIEM 6.3

Page: 2 / 2
Total 64 questions

What does the Frequency field determine on a rule?

A.

How often the rule will evaluate the subpattern.

B.

How often the rule will trigger for the same condition.

C.

How often the rule will trigger.

D.

How often the rule will take a clear action.

Where must you configure rule notifications and automated remediation on FortiSIEM?

A.

Notification engine

B.

Response policies

C.

Email and scripting alerts

D.

Notification policy

Refer to the exhibit.

The FortiSIEM administrator is examining events for two devices to investigate an issue. However, the administrator is not getting any results from their search.

Based on the selected filters shown in the exhibit, why is the search returning no results?

A.

Parenthesis are missing.

B.

The wrong boolean operator is selected in the Next column.

C.

The wrong option is selected in the Operator column.

D.

An invalid IP subnet is typed in the Value column.

In the rules engine, which condition instructs FortiSIEM to summarize and count the matching evaluated data?

A.

Time Window

B.

Aggregation

C.

Group By

D.

Filters

Refer to the exhibit.

What do the yellow stars listed in the Monitor column indicate?

A.

A yellow star indicates that a metric was applied during discovery, and data has been collected successfully

B.

A yellow star indicates that a metric was applied during discovery, but data collection has not started

C.

A yellow star indicates that a metric was applied during discovery, but FortiSIEM is unable to collect data.

D.

A yellow star indicates that a metric was not applied during discovery and, therefore, FortiSEIM was unable to collect data.

Refer to the exhibit.

Which value will FortiSIEM use to populate the Event Type field?

A.

PHL_INFO

B.

phPerfJob

C.

PH_DSV_MON_SYS_DISK_UTIL

D.

diskUtil

In the CMDB page for a network device, the Configuration tab is unexpectedly empty. Which is a possible reason?

A.

The SNMP credential was a read-only credential.

B.

A Telnet/SSH credential was not configured for discovery.

C.

Configuration push is not enabled on the network device.

D.

Syslog was only being sent to a worker.

Refer to the exhibit.

A FortiSIEM is continuously receiving syslog events from a FortiGate firewall The FortiSlfcM administrator is trying to search the raw event logs for the last two hours that contain the keyword tcp . However, the administrator is getting no results from the search.

Based on the selected filters shown in the exhibit, why are there no search results?

A.

The keyword is case sensitive Instead of typing TCP in the Value field. the administrator should type tcp.

B.

In the Time section, the administrator selected the Relative Last option, and in the drop-down lists, selected 2 and Hours as the lime period The time period should be 24 hours.

C.

The administrator selected - in the Operator column That a the wrong operator.

D.

The administrator selected AND in the Next drop-down list. This is the wrong boolean operator.

Which three ports can be used to send Syslogs to FortiSIEM? (Choose three.)

A.

UDP9999

B.

UDP 162

C.

TCP 514

D.

UDP 514

E.

TCP 1470