Fortinet NSE6_FSM_AN-7.4 Fortinet NSE 6 - FortiSIEM 7.4 Analyst Exam Practice Test
Fortinet NSE 6 - FortiSIEM 7.4 Analyst Questions and Answers
When configuring machine learning (ML), in which step can you modify how the model fits the training data set?
What can you use to send data to FortiSIEM for user and entity behavior analytics (UEBA)?
Refer to the exhibit.

Which two lookup types can you reference as the subquery in a nested analytics query? (Choose two.)
When configuring anomaly detection machine learning, in which step must you select the fields to analyze?
Refer to the exhibit.

An analyst is trying to generate an incident with a title that includes the Source IP, Destination IP, User, and Destination Host Name. They are unable to add Destination Host Name as an incident attribute.
What must be changed to allow the analyst to select Destination Host Name as an attribute?
Refer to the exhibit.

Which section contains the subpattern configuration that determines how many matching events are needed to trigger the rule?
Refer to the exhibit.

What is this rule attempting to match? (Choose one answer)
Refer to the exhibit.

How was this incident cleared?
Refer to the exhibit.

What happens when an analyst clears an incident generated by a rule containing the automation policy shown in the exhibit?
Which two settings must you configure to allow FortiSIEM to apply tags to devices in FortiClient EMS? (Choose two.)
Refer to the exhibit.

What will FortiSIEM display if you apply the Group By and Display Fields configuration to a list of allowed firewall connections?
How can you query the configuration management database (CMDB) in an analytics search?
Refer to the exhibit.

If you group the events by User , Source IP , and Count attributes, how many results will FortiSIEM display?
In an automation policy, which two methods can you use to notify analysts when an incident is triggered? (Choose two.)