Pass the Fortinet NSE 5 Network Security Analyst NSE5_FSM-6.3 Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

If an incident’s status is Cleared, what does this mean?

Options:

A.

Two hours have passed since the incident occurred and the incident has not reoccurred.


B.

A clear condition set on a rule was satisfied.


C.

A security rule issue has been resolved.


D.

The incident was cleared by an operator.


Expert Solution
Questions # 2:

Which two FortiSIEM components work together to provide real-time event correlation?

Options:

A.

Supervisor and worker


B.

Collector and Windows agent


C.

Worker and collector


D.

Supervisor and collector


Expert Solution
Questions # 3:

What does the Frequency field determine on a rule?

Options:

A.

How often the rule will evaluate the subpattern.


B.

How often the rule will trigger for the same condition.


C.

How often the rule will trigger.


D.

How often the rule will take a clear action.


Expert Solution
Questions # 4:

In the advanced analytical rules engine in FortiSIEM, multiple subpatterms can be referenced using which three operation?(Choose three.)

Options:

A.

ELSE


B.

NOT


C.

FOLLOWED_BY


D.

OR


E.

AND


Expert Solution
Questions # 5:

Refer to the exhibit.

Question # 5

A FortiSIEM administrator wants to group some attributes for a report, but is not able to do so successfully.

As shown in the exhibit, why are some of the fields highlighted in red?

Options:

A.

Unique attributes cannot be grouped.


B.

The Event Receive Time attribute is not available for logs.


C.

The attribute COUNT(Matched events) is an invalid expression.


D.

No RAW Event Log attribute is available for devices.


Expert Solution
Questions # 6:

Refer to the exhibit.

Question # 6

Which section contains the subpattren configuration settings that determine how many matching events are needed to trigger the rule?

Options:

A.

Group By


B.

Aggregate


C.

Actions


D.

Filters


Expert Solution
Questions # 7:

Refer to the exhibit.

Question # 7

Which section contains the sortings that determine how many incidents are created?

Options:

A.

Actions


B.

Group By


C.

Aggregate


D.

Filters


Expert Solution
Questions # 8:

In the CMDB page for a network device, the Configuration tab is unexpectedly empty. Which is a possible reason?

Options:

A.

The SNMP credential was a read-only credential.


B.

A Telnet/SSH credential was not configured for discovery.


C.

Configuration push is not enabled on the network device.


D.

Syslog was only being sent to a worker.


Expert Solution
Questions # 9:

Which statement about global thresholds and per device thresholds is true?

Options:

A.

FortiSIEM uses global and per device thresholds tor all performance metrics.


B.

FortiSIEM uses global thresholds for all performance metrics.


C.

FortiSIEM uses fixed hardcoded thresholds for all performance metrics.


D.

FortiSIEM uses global thresholds for all security metrics.


Expert Solution
Questions # 10:

Refer to the exhibits.

Question # 10

Question # 10

Three events are collected over a 10-minute time period from two servers: Server A and Server B.

Based on the settings tor the rule subpattern. how many incidents will the servers generate?

Options:

A.

Server A will generate one incident and Server B will generate one incident.


B.

Server A will generate one incident and Server B will not generate any incidents.


C.

Server B will generate one incident and Server A will not generate any incidents.


D.

Server A will not generate any incidents and Server B will not generate any incidents.


Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions