Black Friday Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Fortinet NSE5_FSM-6.3 Fortinet NSE 5 - FortiSIEM 6.3 Exam Practice Test

Demo: 15 questions
Total 50 questions

Fortinet NSE 5 - FortiSIEM 6.3 Questions and Answers

Question 1

Refer to the exhibit.

An administrator is investigating a FortiSIEM license issue.

The procedure is for which offline licensing condition?

Options:

A.

The procedure is for offline license debug.

B.

The procedure is for offline license registration.

C.

The procedure is for offline license validation.

D.

The procedure is for offline license verification.

Question 2

Which statement about global thresholds and per device thresholds is true?

Options:

A.

FortiSIEM uses global and per device thresholds tor all performance metrics.

B.

FortiSIEM uses global thresholds for all performance metrics.

C.

FortiSIEM uses fixed hardcoded thresholds for all performance metrics.

D.

FortiSIEM uses global thresholds for all security metrics.

Question 3

Which FortiSIEM components can do performance availability and performance monitoring?

Options:

A.

Supervisor, worker, and collector

B.

Supervisor and workers only

C.

Supervisor only

D.

Collectors only

Question 4

Which two FortiSIEM components work together to provide real-time event correlation?

Options:

A.

Supervisor and worker

B.

Collector and Windows agent

C.

Worker and collector

D.

Supervisor and collector

Question 5

Refer to the exhibit.

How was the FortiGate device discovered by FortiSIEM?

Options:

A.

GUI log discovery

B.

Syslog discovery

C.

Pull events discovery

D.

Auto log discovery

Question 6

Consider the storage of anomaly baseline date that is calculated for different parameters. Which database is used for storing this data?

Options:

A.

Event DB

B.

Profile DB

C.

SVNDB

D.

CMDB

Question 7

What are the four categories of incidents?

Options:

A.

Devices, users, high risk, and low risk

B.

Performance, devices, high risk, and low risk

C.

Performance, availability, security, and change

D.

Security, change, high risk, and low risk

Question 8

In me FortiSIEM CLI. which command must you use to determine whether or not syslog is being received from a network device?

Options:

A.

tcpdump

B.

OphSyslogRecorder

C.

Onetcat

D.

phDeviceTest

Question 9

Refer to the exhibit.

Which section contains the sortings that determine how many incidents are created?

Options:

A.

Actions

B.

Group By

C.

Aggregate

D.

Filters

Question 10

Which database is used for storing anomaly data, that is calculated for different parameters, such as traffic and device resource usage running averages, and standard deviation values?

Options:

A.

Profile DB

B.

Event DB

C.

CMDB

D.

SVN DB

Question 11

Which discovery scan type is prone to miss a device, if the device is quiet and the entry foe that device is not present in the ARP table of adjacent devices?

Options:

A.

CMDB scan

B.

L2 scan

C.

Range scan

D.

Smart scan

Question 12

What is a prerequisite for FortiSIEM Linux agent installation?

Options:

A.

The web server must be installed on the Linux server being monitored

B.

The auditd service must be installed on the Linux server being monitored

C.

The Linux agent manager server must be installed.

D.

Both the web server and the audit service must be installed on the Linux server being monitored

Question 13

Refer to the exhibit.

A FortiSIEM administrator wants to group some attributes for a report, but is not able to do so successfully.

As shown in the exhibit, why are some of the fields highlighted in red?

Options:

A.

Unique attributes cannot be grouped.

B.

The Event Receive Time attribute is not available for logs.

C.

The attribute COUNT(Matched events) is an invalid expression.

D.

No RAW Event Log attribute is available for devices.

Question 14

Refer to the exhibit.

An administrator is trying to identify an issue using an expression bated on the Expression Builder settings shown in the exhibit however, the error message shown in the exhibit indicates that the expression is invalid.

Which is the correct expression?

Options:

A.

Matched Events COUNT()

B.

Matched Events(COUNT)

C.

COUNT(Matched Events)

D.

(COUNT) Matched Events

Question 15

How is a subpattern for a rule defined?

Options:

A.

Filters, Aggregation, Group by definitions

B.

Filters, Group By definitions, Threshold

C.

Filters, Threshold, Time Window definitions

D.

Filters, Aggregation, Time Window definitions

Demo: 15 questions
Total 50 questions