Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > Fortinet > NSE 6 Network Security Specialist > NSE6_FSM_AN-7.4

NSE6_FSM_AN-7.4 Fortinet NSE 6 - FortiSIEM 7.4 Analyst Question and Answers

Question # 4

Refer to the exhibit.

Which two actions can you select in an automation policy to trigger an API call to block an IP address on a FortiGate? (Choose two.)

A.

Open Remedy ticket using the configuration set in Analytics.

B.

Send Email/SMS/Webhook to the target users.

C.

Invoke an Integration Policy.

D.

Run Remediation/Script.

E.

Run Playbook on Incident Trigger.

Full Access
Question # 5

Refer to the exhibit.

Which two conditions will match this rule and subpatterns? (Choose two.)

A.

A user using RDP over SSL VPN fails to log in to an application five times.

B.

A user runs a brute force password cracker against an RDP server.

C.

A user fails twice to log in when connecting through RDP.

D.

A user connects to the wrong IP address for an RDP session five times.

Full Access
Question # 6

Refer to the exhibit.

An analyst is trying to identify an issue using an expression based on the Expression Builder settings shown in the exhibit; however, the error message shown in the exhibit indicates that the expression is invalid.

What is the correct syntax to create an expression that generates a total count of matched events?

A.

COUNT(Matched Events)

B.

(COUNT) Matched Events

C.

Matched Events (COUNT)

D.

Matched Events COUNT()

Full Access
Question # 7

Refer to the exhibit.

According to the automation policy configuration shown in the exhibit, what happens if an associated rule triggers?

A.

FortiSIEM runs the remediation script, because that takes precedence over all other options.

B.

FortiSIEM performs all selected actions.

C.

FortiSIEM fails to the integration policy, because no policy is defined.

D.

FortiSIEM sends an email, because that is first on the list.

Full Access
Question # 8

Refer to the exhibit.

If you group the events by User , Source IP , and Count attributes, how many results will FortiSIEM display?

A.

Two

B.

Six

C.

Three

D.

Five

E.

Four

Full Access
Question # 9

Refer to the exhibit.

If you group the events by Reporting Device , Reporting IP , and Application Category , how many results will FortiSIEM display?

A.

Four

B.

Five

C.

One

D.

Six

E.

Two

Full Access
Question # 10

Which information can FortiSIEM retrieve from FortiClient EMS through an API connection?

A.

Host software versions

B.

FortiSIEM license

C.

Host login credentials

D.

ZTNA tags

Full Access
Question # 11

What can you use to send data to FortiSIEM for user and entity behavior analytics (UEBA)?

A.

FortiSIEM agent

B.

SSH

C.

SNMP

D.

FortiSIEM worker

Full Access
Question # 12

Refer to the exhibit.

Which statement about the time range settings defined in the nested query is accurate? (Choose one answer)

A.

FortiSIEM will list source IP addresses found in the last 10 minutes of events from each day in the Approved Devices report from the last 30 days.

B.

FortiSIEM will search in real time using 10-minute blocks for a source IP address that is not in the Approved Devices report from the last 30 days.

C.

FortiSIEM will search the last 30 days of events for a source IP address that is not in the Approved Devices report.

D.

FortiSIEM will search the last 10 minutes of events for a source IP address that is not in the Approved Devices report from the last 30 days.

Full Access
Question # 13

Which statement about thresholds is true?

A.

FortiSIEM uses fixed, hardcoded global and device thresholds for all performance metrics.

B.

FortiSIEM uses only device thresholds for security metrics.

C.

FortiSIEM uses global and per-device thresholds for performance metrics.

D.

FortiSIEM uses only global thresholds for performance metrics.

Full Access
Question # 14

Refer to the exhibit.

What is the Group: VPN Gateway value a reference to? (Choose one answer)

A.

A configuration management database (CMDB) device group

B.

A FortiSIEM rule folder

C.

A FortiSIEM watchlist

D.

A FortiGate address group

Full Access