Summer Sale Discount Flat 70% Offer - Ends in 0d 00h 00m 00s - Coupon code: 70diswrap

Fortinet NSE6_FSM_AN-7.4 Dumps

Fortinet NSE 6 - FortiSIEM 7.4 Analyst Questions and Answers

Question 1

Refer to the exhibits.

as

You are troubleshooting why the rule shown in the exhibit is generating incidents for successful Remote Desktop Protocol (RDP) connections with correct logins. It should only be triggering when a person fails to log in three or more times to the target device when connecting with RDP.

What is causing the rule to be triggered by correct login events? (Choose one answer)

Options:

A.

The subpattern relationship RDP_Connection:User = Failed_Logon:User never matches.

B.

The Boolean between the subpatterns is incorrect.

C.

The attribute types in the subpatterns do not match.

D.

The RDP login is different from the login used to access the target device.

Question 2

Refer to the exhibit.

as

Which two actions can you select in an automation policy to trigger an API call to block an IP address on a FortiGate? (Choose two.)

Options:

A.

Open Remedy ticket using the configuration set in Analytics.

B.

Send Email/SMS/Webhook to the target users.

C.

Invoke an Integration Policy.

D.

Run Remediation/Script.

E.

Run Playbook on Incident Trigger.

Question 3

Refer to the exhibit.

as

An analyst is trying to generate an incident with a title that includes the Source IP, Destination IP, User, and Destination Host Name. They are unable to add Destination Host Name as an incident attribute.

What must be changed to allow the analyst to select Destination Host Name as an attribute?

Options:

A.

The Destination Host Name must be selected as a Triggered Attribute.

B.

The Destination Host Name must be set as an aggregate item in a subpattern.

C.

The Destination Host Name must be added as an Event Type in FortiSIEM.

D.

The Destination IP event attribute must be removed.

Question 4

Refer to the exhibit.

as

If a rule containing the automation policy shown in the exhibit triggers, what will happen?

Options:

A.

Associated source IP addresses will be blocked on devices in the Aviation organization.

B.

Associated source IP addresses will be blocked on all FortiGate firewalls.

C.

Associated source IP addresses will be blocked on devices in the Network CMDB group.

D.

Associated source IP addresses will be blocked on two FortiGate firewalls.

Question 5

Refer to the exhibit.

as

If you group the events by User , Source IP , and Count attributes, how many results will FortiSIEM display?

Options:

A.

Two

B.

Six

C.

Three

D.

Five

E.

Four

Question 6

Refer to the exhibit.

as

As shown in the exhibit, why are some of the fields highlighted in red?

Options:

A.

Unique values cannot be grouped

B.

The attribute COUNT(Matched Events) is an invalid expression.

C.

No RAW Event Log attribute information is available.

D.

The Event Receive Time attribute is not available for logs.

Question 7

Refer to the exhibit.

as

What will FortiSIEM display if you apply the Group By and Display Fields configuration to a list of allowed firewall connections?

Options:

A.

A list of connections ordered by destination IP address hit count

B.

A list of connections between unique source and destination IP addresses

C.

A running count of connections, regardless of source or destination

D.

A list of connections ordered by the number of unique connections started by each source IP address

Question 8

Which run mode takes the most time to perform machine learning tasks?

Options:

A.

Local Auto

B.

Local

C.

Forecasting

D.

Regression

Question 9

Which two data areas can you use for user and entity behavior analytics (EBA) machine learning models? (Choose two.)

Options:

A.

Process

B.

Location

C.

Resources

D.

Network

Question 10

Refer to the exhibit.

as

What is the Group: FortiSIEM Analysts value referring to?

Options:

A.

FortiSIEM organization group

B.

LDAP user group

C.

CMDB user group

D.

Windows Active Directory user group

Question 11

Which analytics search can be used to apply a user and entity behavior analytics (UEBA) tag to an event for a failed login by the user JSmith?

Options:

A.

User = smith

B.

Username NOT END WITH jsmith

C.

User IS jsmith

D.

Username CONTAIN smit

Question 12

Refer to the exhibit.

as

Which statement about the time range settings defined in the nested query is accurate? (Choose one answer)

Options:

A.

FortiSIEM will list source IP addresses found in the last 10 minutes of events from each day in the Approved Devices report from the last 30 days.

B.

FortiSIEM will search in real time using 10-minute blocks for a source IP address that is not in the Approved Devices report from the last 30 days.

C.

FortiSIEM will search the last 30 days of events for a source IP address that is not in the Approved Devices report.

D.

FortiSIEM will search the last 10 minutes of events for a source IP address that is not in the Approved Devices report from the last 30 days.

Question 13

How does FortiSIEM update the incident table if a performance rule triggers repeatedly?

Options:

A.

FortiSIEM changes the incident status to Repeated, and updates the Last Seen timestamp.

B.

FortiSIEM updates the Incident Count value and Last Seen timestamp.

C.

FortiSIEM generates a new incident based on the Rule Frequency value, and updates the First Seen and Last Seen timestamps.

D.

FortiSIEM generates a new incident each time the rule triggers, and updates the First Seen and Last Seen timestamps.

Question 14

Refer to the exhibit.

as

Which two lookup types can you reference as the subquery in a nested analytics query? (Choose two.)

Options:

A.

LDAP Query

B.

CMDB Query

C.

SNMP Query

D.

Event Query

Page: 1 / 5
Total 48 questions