Black Friday Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70special

Fortinet NSE5_FSM-6.3 Fortinet NSE 5 - FortiSIEM 6.3 Exam Practice Test

Fortinet NSE 5 - FortiSIEM 6.3 Questions and Answers

Testing Engine

  • Product Type: Testing Engine
$37.5  $124.99

PDF Study Guide

  • Product Type: PDF Study Guide
$33  $109.99
Question 1

Refer to the exhibit.

It events are grouped by Event Type and User attributes in FortiSIEM. how many results will be displayed?

Options:

A.

Four results will be displayed.

B.

Eight results will be displayed.

C.

Two results will be displayed.

D.

No results will be displayed.

Question 2

What is a prerequisite for FortiSIEM Linux agent installation?

Options:

A.

The web server must be installed on the Linux server being monitored

B.

The auditd service must be installed on the Linux server being monitored

C.

The Linux agent manager server must be installed.

D.

Both the web server and the audit service must be installed on the Linux server being monitored

Question 3

Refer to the exhibit.

If events are grouped by Reporting IP, Event Type, and user attributes in FortiSIEM, how ,many results will be displayed?

Options:

A.

Seven results will be displayed.

B.

There results will be displayed.

C.

Unique attribute cannot be grouped.

D.

Five results will be displayed.

Question 4

What are the four possible incident status values?

Options:

A.

Active, dosed, cleared, open

B.

Active, cleared, cleared manually, system cleared

C.

Active, closed, manual, resolved

D.

Active, auto cleared, manual, false positive

Question 5

Which FortiSIEM components can do performance availability and performance monitoring?

Options:

A.

Supervisor, worker, and collector

B.

Supervisor and workers only

C.

Supervisor only

D.

Collectors only

Question 6

FortiSIEM is deployed in disaster recovery mode.

When disaster strikes, which two tasks must you perform manually to achieve a successful disaster recovery operation? (Choose two.)

Options:

A.

Promote the secondary workers to the primary rotes using the phSecworker2priworker command.

B.

Promote the secondary supervisor to the primary role using the phSecondary2primary command.

C.

Change the DNS configuration to ensure that users, devices, and collectors log in to the secondary FortiSIEM.

D.

Change the configuration for shared storage NFS configured for EventDB to the secondary FortiSIEM.

Question 7

In me FortiSIEM CLI. which command must you use to determine whether or not syslog is being received from a network device?

Options:

A.

tcpdump

B.

OphSyslogRecorder

C.

Onetcat

D.

phDeviceTest

Question 8

What are the four categories of incidents?

Options:

A.

Devices, users, high risk, and low risk

B.

Performance, devices, high risk, and low risk

C.

Performance, availability, security, and change

D.

Security, change, high risk, and low risk

Question 9

An administrator is using SNMP and WMI credentials to discover a Windows device. How will the WMI method handle this?

Options:

A.

WMI method will collect only traffic and IIS logs.

B.

WMI method will collect only DNS logs.

C.

WMI method will collect only DHCP logs.

D.

WMI method will collect security, application, and system events logs.

Question 10

Which two FortiSIEM components work together to provide real-time event correlation?

Options:

A.

Supervisor and worker

B.

Collector and Windows agent

C.

Worker and collector

D.

Supervisor and collector

Question 11

Which statement about global thresholds and per device thresholds is true?

Options:

A.

FortiSIEM uses global and per device thresholds tor all performance metrics.

B.

FortiSIEM uses global thresholds for all performance metrics.

C.

FortiSIEM uses fixed hardcoded thresholds for all performance metrics.

D.

FortiSIEM uses global thresholds for all security metrics.

Question 12

How is a subparttern for a rule defined?

Options:

A.

Filters Aggregation. Group By definition

B.

Filters Group By definitions. Threshold

C.

Filters Threshold Time Window definitions

D.

Filters Aggregation Time Window definitions

Question 13

Where do you configure rule notifications and automated remediation on FortiSIEM?

Options:

A.

Notification policy

B.

Remediation policy

C.

Notification engine

D.

Remediation engine

Question 14

When configuring collectors located in geographically separated sites, what ports must be open on a front end firewall?

Options:

A.

HTTPS, from the collector to the worker upload settings address only

B.

HTTPS, from the collector to the supervisor and worker upload settings addresses

C.

HTTPS, from the Internet to the collector

D.

HTTPS, from the Internet to the collector and from the collector to the FortiSIEM cluster

Question 15

Which three ports can be used to send Syslogs to FortiSIEM? (Choose three.)

Options:

A.

UDP9999

B.

UDP 162

C.

TCP 514

D.

UDP 514

E.

TCP 1470