Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Fortinet NSE 6 Network Security Specialist NSE6_FSM_AN-7.4 Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

Refer to the exhibit.

Question # 1

An analyst is troubleshooting the rule shown in the exhibit. It is not generating any incidents, but the filter parameters are generating events on the Analytics tab.

What is wrong with the rule conditions?

Options:

A.

The Event Type refers to a CMDB lookup and should be an Event lookup.


B.

The Destination Host Name value is not fully qualified.


C.

The Group By attributes restricts which events are counted.


D.

The Aggregate attribute is too restrictive.


Expert Solution
Questions # 2:

How does FortiSIEM update the incident table if a performance rule triggers repeatedly?

Options:

A.

FortiSIEM changes the incident status to Repeated, and updates the Last Seen timestamp.


B.

FortiSIEM updates the Incident Count value and Last Seen timestamp.


C.

FortiSIEM generates a new incident based on the Rule Frequency value, and updates the First Seen and Last Seen timestamps.


D.

FortiSIEM generates a new incident each time the rule triggers, and updates the First Seen and Last Seen timestamps.


Expert Solution
Questions # 3:

Refer to the exhibit.

Question # 3

If you group the events by User , Source IP , and Count attributes, how many results will FortiSIEM display?

Options:

A.

Two


B.

Six


C.

Three


D.

Five


E.

Four


Expert Solution
Questions # 4:

An analyst wants to create a rule from a newly created analytics search.

What is the quickest method?

Options:

A.

On the Analytics tab, click Actions > Create Rule.


B.

Create a new rule under Resources > Rules and fill in the search details.


C.

On the Analytics tab, click the New button next to the Filter By box.


D.

On the upper menu bar on any tab, click the pencil icon.


Expert Solution
Questions # 5:

Refer to the exhibit.

Question # 5

How was this incident cleared?

Options:

A.

The analyst manually cleared the incident from the incident table.


B.

FortiSIEM cleared the incident automatically after 24 hours.


C.

The incident was cleared automatically by the rule.


D.

The endpoint was rebooted and sent an all-clear signal to FortiSIEM.


Expert Solution
Questions # 6:

Refer to the exhibit.

Question # 6

An analyst wants to perform a KMeans machine learning (ML) job on this data. How many N clusters would be a good fit for the data? (Choose one answer)

Options:

A.

Two


B.

50


C.

100


D.

One


Expert Solution
Questions # 7:

Refer to the exhibit.

Question # 7

What happens when an analyst clears an incident generated by a rule containing the automation policy shown in the exhibit?

Options:

A.

No notification is sent.


B.

An email is sent to the SOC manager.


C.

The remediation script is run.


D.

A notification is sent to the SOC manager dashboard.


Expert Solution
Questions # 8:

Which two settings must you configure to allow FortiSIEM to apply tags to devices in FortiClient EMS? (Choose two.)

Options:

A.

FortiEMS API credentials defined on FortiSIEM


B.

Remediation script configured


C.

ZTNA tags defined on FortiSIEM


D.

FortiSIEM API credentials defined on FortiEMS


Expert Solution
Questions # 9:

Which statement about thresholds is true?

Options:

A.

FortiSIEM uses fixed, hardcoded global and device thresholds for all performance metrics.


B.

FortiSIEM uses only device thresholds for security metrics.


C.

FortiSIEM uses global and per-device thresholds for performance metrics.


D.

FortiSIEM uses only global thresholds for performance metrics.


Expert Solution
Questions # 10:

Refer to the exhibit.

Question # 10

Which value would you expect the FortiSIEM parser to use to populate the Application Name field?

Options:

A.

applist


B.

Network.Service


C.

SSL


D.

wan1


Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions