Summer Sale Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Fortinet NSE6_FSM_AN-7.4 Fortinet NSE 6 - FortiSIEM 7.4 Analyst Exam Practice Test

Fortinet NSE 6 - FortiSIEM 7.4 Analyst Questions and Answers

Question 1

When configuring machine learning (ML), in which step can you modify how the model fits the training data set?

Options:

A.

Prepare Data

B.

Train

C.

Statistics

D.

Design

Question 2

What can you use to send data to FortiSIEM for user and entity behavior analytics (UEBA)?

Options:

A.

FortiSIEM agent

B.

SSH

C.

SNMP

D.

FortiSIEM worker

Question 3

Refer to the exhibit.

Question # 3

Which two lookup types can you reference as the subquery in a nested analytics query? (Choose two.)

Options:

A.

LDAP Query

B.

CMDB Query

C.

SNMP Query

D.

Event Query

Question 4

When configuring anomaly detection machine learning, in which step must you select the fields to analyze?

Options:

A.

Design

B.

Schedule

C.

Prepare Data

D.

Train

Question 5

Refer to the exhibit.

Question # 5

An analyst is trying to generate an incident with a title that includes the Source IP, Destination IP, User, and Destination Host Name. They are unable to add Destination Host Name as an incident attribute.

What must be changed to allow the analyst to select Destination Host Name as an attribute?

Options:

A.

The Destination Host Name must be selected as a Triggered Attribute.

B.

The Destination Host Name must be set as an aggregate item in a subpattern.

C.

The Destination Host Name must be added as an Event Type in FortiSIEM.

D.

The Destination IP event attribute must be removed.

Question 6

Refer to the exhibit.

Question # 6

Which section contains the subpattern configuration that determines how many matching events are needed to trigger the rule?

Options:

A.

Aggregate

B.

Group By

C.

Actions

D.

Filters

Question 7

Refer to the exhibit.

Question # 7

What is this rule attempting to match? (Choose one answer)

Options:

A.

Failed VPN logon attempts from three or more different outside countries.

B.

Failed VPN logon events from a source outside the home country.

C.

Failed VPN logon attempts from three or more different sources inside the home country.

D.

Excessive VPN logon failures from a source inside the home country.

Question 8

Refer to the exhibit.

Question # 8

How was this incident cleared?

Options:

A.

The analyst manually cleared the incident from the incident table.

B.

FortiSIEM cleared the incident automatically after 24 hours.

C.

The incident was cleared automatically by the rule.

D.

The endpoint was rebooted and sent an all-clear signal to FortiSIEM.

Question 9

Refer to the exhibit.

Question # 9

What happens when an analyst clears an incident generated by a rule containing the automation policy shown in the exhibit?

Options:

A.

No notification is sent.

B.

An email is sent to the SOC manager.

C.

The remediation script is run.

D.

A notification is sent to the SOC manager dashboard.

Question 10

Which two settings must you configure to allow FortiSIEM to apply tags to devices in FortiClient EMS? (Choose two.)

Options:

A.

FortiEMS API credentials defined on FortiSIEM

B.

Remediation script configured

C.

ZTNA tags defined on FortiSIEM

D.

FortiSIEM API credentials defined on FortiEMS

Question 11

Refer to the exhibit.

Question # 11

What will FortiSIEM display if you apply the Group By and Display Fields configuration to a list of allowed firewall connections?

Options:

A.

A list of connections ordered by destination IP address hit count

B.

A list of connections between unique source and destination IP addresses

C.

A running count of connections, regardless of source or destination

D.

A list of connections ordered by the number of unique connections started by each source IP address

Question 12

How can you query the configuration management database (CMDB) in an analytics search?

Options:

A.

Click Value > Select from CMDB.

B.

On the CMDB tab, select an entry, and then click Create Search.

C.

On the Admin tab, click CMDB Search.

D.

Click Attribute > Select from CMDB.

Question 13

Refer to the exhibit.

Question # 13

If you group the events by User , Source IP , and Count attributes, how many results will FortiSIEM display?

Options:

A.

Two

B.

Six

C.

Three

D.

Five

E.

Four

Question 14

In an automation policy, which two methods can you use to notify analysts when an incident is triggered? (Choose two.)

Options:

A.

Email

B.

FortiSIEM Case

C.

Syslog

D.

Pop-up window