Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Fortinet NSE6_FSM_AN-7.4 - Fortinet NSE 6 - FortiSIEM 7.4 Analyst

Page: 1 / 2
Total 48 questions

How can you query the configuration management database (CMDB) in an analytics search?

A.

Click Value > Select from CMDB.

B.

On the CMDB tab, select an entry, and then click Create Search.

C.

On the Admin tab, click CMDB Search.

D.

Click Attribute > Select from CMDB.

Refer to the exhibit.

If you group the events by Reporting Device , Reporting IP , and Application Category , how many results will FortiSIEM display?

A.

Four

B.

Five

C.

One

D.

Six

E.

Two

Refer to the exhibit.

What is the Group: FortiSIEM Analysts value referring to?

A.

FortiSIEM organization group

B.

LDAP user group

C.

CMDB user group

D.

Windows Active Directory user group

You want to create a rule with multiple subpatterns but trigger an incident only if three different subpatterns are matched over a 24-hour period.

Where must you define the time period that the rule uses to evaluate all the subpatterns? (Choose one answer)

A.

Define the time window in each individual subpattern.

B.

Define the time window under the General tab of the rule.

C.

Define the time window under the Define Condition tab of the rule.

D.

Define the time window in the Define Action section of the rule.

You need to model for predicting a target based on other fields in the dataset and then trigger an anomaly if the value does not match the prediction.

Which machine learning algorithm will build this type of model?

A.

Classification

B.

Clustering

C.

Regression

D.

Forecasting

Refer to the exhibit.

An analyst is trying to generate an incident with a title that includes the Source IP, Destination IP, User, and Destination Host Name. They are unable to add Destination Host Name as an incident attribute.

What must be changed to allow the analyst to select Destination Host Name as an attribute?

A.

The Destination Host Name must be selected as a Triggered Attribute.

B.

The Destination Host Name must be set as an aggregate item in a subpattern.

C.

The Destination Host Name must be added as an Event Type in FortiSIEM.

D.

The Destination IP event attribute must be removed.

What are two required components of a rule? (Choose two.)

A.

Exception policy

B.

Subpattern

C.

Detection Technology

D.

Clear policy

Refer to the exhibit.

If you group the events by User , Source IP , and Count attributes, how many results will FortiSIEM display?

A.

Two

B.

Six

C.

Three

D.

Five

E.

Four

An analyst wants to create a rule from a newly created analytics search.

What is the quickest method?

A.

On the Analytics tab, click Actions > Create Rule.

B.

Create a new rule under Resources > Rules and fill in the search details.

C.

On the Analytics tab, click the New button next to the Filter By box.

D.

On the upper menu bar on any tab, click the pencil icon.

When configuring anomaly detection machine learning, in which step must you select the fields to analyze?

A.

Design

B.

Schedule

C.

Prepare Data

D.

Train