Pass the Fortinet NSE 5 Network Security Analyst NSE5_FSM-6.3 Questions and answers with CertsForce

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which FortiSIEM components can do performance availability and performance monitoring?

Options:

A.

Supervisor, worker, and collector


B.

Supervisor and workers only


C.

Supervisor only


D.

Collectors only


Expert Solution
Questions # 12:

Refer to the exhibit.

Question # 12

How was the FortiGate device discovered by FortiSIEM?

Options:

A.

GUI log discovery


B.

Syslog discovery


C.

Pull events discovery


D.

Auto log discovery


Expert Solution
Questions # 13:

Refer to the exhibit.

Question # 13

An administrator is trying to identify an issue using an expression bated on the Expression Builder settings shown in the exhibit however, the error message shown in the exhibit indicates that the expression is invalid.

Which is the correct expression?

Options:

A.

Matched Events COUNT()


B.

Matched Events(COUNT)


C.

COUNT(Matched Events)


D.

(COUNT) Matched Events


Expert Solution
Questions # 14:

An administrator defines SMTP as a critical process on a Linux server.

It the SMTP process is stopped. FortiSIEM will generate a critical event with which event type?

Options:

A.

Postfix-Mail-Stop


B.

PH_DEV_MON_PROC_STOP


C.

PH_DEV_MON_SMTP_STOP


D.

Generic_SMTP_Procoss_Exit


Expert Solution
Questions # 15:

Which process converts raw log data to structured data?

Options:

A.

Data classification


B.

Data validation


C.

Data parsing


D.

Data enrichment


Expert Solution
Questions # 16:

When configuring collectors located in geographically separated sites, what ports must be open on a front end firewall?

Options:

A.

HTTPS, from the collector to the worker upload settings address only


B.

HTTPS, from the collector to the supervisor and worker upload settings addresses


C.

HTTPS, from the Internet to the collector


D.

HTTPS, from the Internet to the collector and from the collector to the FortiSIEM cluster


Expert Solution
Questions # 17:

Where do you configure rule notifications and automated remediation on FortiSIEM?

Options:

A.

Notification policy


B.

Remediation policy


C.

Notification engine


D.

Remediation engine


Expert Solution
Questions # 18:

Which FortiSIEM components are capable of performing device discovery?

Options:

A.

FortiSIEM Windows agent


B.

Worker


C.

FortiSIEM Linux agent


D.

Collector


Expert Solution
Questions # 19:

Refer to the exhibit.

Question # 19

Which value will FortiSIEM use to populate the Connection Id field?

Options:

A.

33909


B.

134


C.

The connection ID is not in the raw message.


D.

408228


Expert Solution
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions