Fortinet NSE6_FSM_AN-7.4 - Fortinet NSE 6 - FortiSIEM 7.4 Analyst
How can you query the configuration management database (CMDB) in an analytics search?
Refer to the exhibit.

If you group the events by Reporting Device , Reporting IP , and Application Category , how many results will FortiSIEM display?
Refer to the exhibit.

What is the Group: FortiSIEM Analysts value referring to?
You want to create a rule with multiple subpatterns but trigger an incident only if three different subpatterns are matched over a 24-hour period.
Where must you define the time period that the rule uses to evaluate all the subpatterns? (Choose one answer)
You need to model for predicting a target based on other fields in the dataset and then trigger an anomaly if the value does not match the prediction.
Which machine learning algorithm will build this type of model?
Refer to the exhibit.

An analyst is trying to generate an incident with a title that includes the Source IP, Destination IP, User, and Destination Host Name. They are unable to add Destination Host Name as an incident attribute.
What must be changed to allow the analyst to select Destination Host Name as an attribute?
What are two required components of a rule? (Choose two.)
Refer to the exhibit.

If you group the events by User , Source IP , and Count attributes, how many results will FortiSIEM display?
An analyst wants to create a rule from a newly created analytics search.
What is the quickest method?
When configuring anomaly detection machine learning, in which step must you select the fields to analyze?
