Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Fortinet NSE6_FSM_AN-7.4 Fortinet NSE 6 - FortiSIEM 7.4 Analyst Exam Practice Test

Demo: 14 questions
Total 48 questions

Fortinet NSE 6 - FortiSIEM 7.4 Analyst Questions and Answers

Question 1

Refer to the exhibit.

An analyst is troubleshooting the rule shown in the exhibit. It is not generating any incidents, but the filter parameters are generating events on the Analytics tab.

What is wrong with the rule conditions?

Options:

A.

The Event Type refers to a CMDB lookup and should be an Event lookup.

B.

The Destination Host Name value is not fully qualified.

C.

The Group By attributes restricts which events are counted.

D.

The Aggregate attribute is too restrictive.

Question 2

When configuring machine learning (ML), in which step can you modify how the model fits the training data set?

Options:

A.

Prepare Data

B.

Train

C.

Statistics

D.

Design

Question 3

How does FortiSIEM update the incident table if a performance rule triggers repeatedly?

Options:

A.

FortiSIEM changes the incident status to Repeated, and updates the Last Seen timestamp.

B.

FortiSIEM updates the Incident Count value and Last Seen timestamp.

C.

FortiSIEM generates a new incident based on the Rule Frequency value, and updates the First Seen and Last Seen timestamps.

D.

FortiSIEM generates a new incident each time the rule triggers, and updates the First Seen and Last Seen timestamps.

Question 4

Which two settings must you configure to allow FortiSIEM to apply tags to devices in FortiClient EMS? (Choose two.)

Options:

A.

FortiEMS API credentials defined on FortiSIEM

B.

Remediation script configured

C.

ZTNA tags defined on FortiSIEM

D.

FortiSIEM API credentials defined on FortiEMS

Question 5

Which run mode takes the most time to perform machine learning tasks?

Options:

A.

Local Auto

B.

Local

C.

Forecasting

D.

Regression

Question 6

Refer to the exhibit.

If you group the events by User , Source IP , and Count attributes, how many results will FortiSIEM display?

Options:

A.

Two

B.

Six

C.

Three

D.

Five

E.

Four

Question 7

Refer to the exhibit.

Which value would you expect the FortiSIEM parser to use to populate the Application Name field?

Options:

A.

applist

B.

Network.Service

C.

SSL

D.

wan1

Question 8

When configuring anomaly detection machine learning, in which step must you select the fields to analyze?

Options:

A.

Design

B.

Schedule

C.

Prepare Data

D.

Train

Question 9

What can you use to send data to FortiSIEM for user and entity behavior analytics (UEBA)?

Options:

A.

FortiSIEM agent

B.

SSH

C.

SNMP

D.

FortiSIEM worker

Question 10

Refer to the exhibit.

What is the Group: VPN Gateway value a reference to? (Choose one answer)

Options:

A.

A configuration management database (CMDB) device group

B.

A FortiSIEM rule folder

C.

A FortiSIEM watchlist

D.

A FortiGate address group

Question 11

Refer to the exhibit.

An analyst wants to perform a KMeans machine learning (ML) job on this data. How many N clusters would be a good fit for the data? (Choose one answer)

Options:

A.

Two

B.

50

C.

100

D.

One

Question 12

Refer to the exhibit.

If you group the events by Reporting Device , Reporting IP , and Application Category , how many results will FortiSIEM display?

Options:

A.

Four

B.

Five

C.

One

D.

Six

E.

Two

Question 13

In an automation policy, which two methods can you use to notify analysts when an incident is triggered? (Choose two.)

Options:

A.

Email

B.

FortiSIEM Case

C.

Syslog

D.

Pop-up window

Question 14

Refer to the exhibit.

What is the Group: FortiSIEM Analysts value referring to?

Options:

A.

FortiSIEM organization group

B.

LDAP user group

C.

CMDB user group

D.

Windows Active Directory user group

Demo: 14 questions
Total 48 questions