Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Fortinet NSE6_FSM_AN-7.4 - Fortinet NSE 6 - FortiSIEM 7.4 Analyst

Page: 1 / 2
Total 48 questions

Refer to the exhibit.

An analyst is troubleshooting the rule shown in the exhibit. It is not generating any incidents, but the filter parameters are generating events on the Analytics tab.

What is wrong with the rule conditions?

A.

The Event Type refers to a CMDB lookup and should be an Event lookup.

B.

The Destination Host Name value is not fully qualified.

C.

The Group By attributes restricts which events are counted.

D.

The Aggregate attribute is too restrictive.

When configuring anomaly detection machine learning, in which step must you select the fields to analyze?

A.

Design

B.

Schedule

C.

Prepare Data

D.

Train

What can you use to send data to FortiSIEM for user and entity behavior analytics (UEBA)?

A.

FortiSIEM agent

B.

SSH

C.

SNMP

D.

FortiSIEM worker

Which statement about thresholds is true?

A.

FortiSIEM uses fixed, hardcoded global and device thresholds for all performance metrics.

B.

FortiSIEM uses only device thresholds for security metrics.

C.

FortiSIEM uses global and per-device thresholds for performance metrics.

D.

FortiSIEM uses only global thresholds for performance metrics.

Refer to the exhibit.

What is this rule attempting to match? (Choose one answer)

A.

Failed VPN logon attempts from three or more different outside countries.

B.

Failed VPN logon events from a source outside the home country.

C.

Failed VPN logon attempts from three or more different sources inside the home country.

D.

Excessive VPN logon failures from a source inside the home country.

Refer to the exhibit.

A FortiSIEM analyst is investigating an issue by examining events to two destination IP addresses. However, the analyst is not getting any results from the search.

Based on the selected filter shown in the exhibit, why is the search returning no results?

A.

Parentheses are missing between the two items.

B.

The wrong Boolean operator is selected in the Next column.

C.

The wrong option is selected in the Operator column.

D.

An invalid IP address is typed in the Value column.

Refer to the exhibit.

As shown in the exhibit, why are some of the fields highlighted in red?

A.

Unique values cannot be grouped

B.

The attribute COUNT(Matched Events) is an invalid expression.

C.

No RAW Event Log attribute information is available.

D.

The Event Receive Time attribute is not available for logs.

Refer to the exhibit.

What is the Group: VPN Gateway value a reference to? (Choose one answer)

A.

A configuration management database (CMDB) device group

B.

A FortiSIEM rule folder

C.

A FortiSIEM watchlist

D.

A FortiGate address group

Refer to the exhibit.

According to the automation policy configuration shown in the exhibit, what happens if an associated rule triggers?

A.

FortiSIEM runs the remediation script, because that takes precedence over all other options.

B.

FortiSIEM performs all selected actions.

C.

FortiSIEM fails to the integration policy, because no policy is defined.

D.

FortiSIEM sends an email, because that is first on the list.

Which information can FortiSIEM retrieve from FortiClient EMS through an API connection?

A.

Host software versions

B.

FortiSIEM license

C.

Host login credentials

D.

ZTNA tags