NSE5_FSM-6.3 Exam Questions
69 real NSE5_FSM-6.3 exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1Monitoring, Reporting, and Troubleshooting
Which process converts raw log data to structured data?
log parsingraw log datastructured datadata processing - Question #2Monitoring, Reporting, and Troubleshooting
Refer to the exhibits. Three events are collected over a 10-minute time period from two servers: Server A and Server B. Based on the settings being used for the rule subpattern, ho...
rule subpatternsincident generationevent correlationtime window - Question #3Monitoring, Reporting, and Troubleshooting
In me FortiSIEM CLI. which command must you use to determine whether or not syslog is being received from a network device?
syslogtcpdumpCLI troubleshootingnetwork diagnostics - Question #4Monitoring, Reporting, and Troubleshooting
What does the Frequency field determine on a rule?
rule frequencysubpattern evaluationrule configurationanalytics engine - Question #5Monitoring, Reporting, and Troubleshooting
Consider the storage of anomaly baseline date that is calculated for different parameters. Which database is used for storing this data?
anomaly baselineProfile DBdatabase storagebehavioral analytics - Question #6Integration with Fortinet Security Fabric
Which is a requirement for implementing FortiSIEM disaster recovery?
disaster recoverysupervisor nodesDNS configurationhigh availability - Question #7Monitoring, Reporting, and Troubleshooting
How is a subpattern for a rule defined?
subpattern definitionfiltersaggregationtime window - Question #8Integration with Fortinet Security Fabric
Which FortiSIEM components are capable of performing device discovery?
device discoverycollectorFortiSIEM componentsnetwork discovery - Question #9Monitoring, Reporting, and Troubleshooting
Refer to the exhibit. An administrator is trying to identify an issue using an expression bated on the Expression Builder settings shown in the exhibit however, the error message s...
Expression BuilderCOUNT function syntaxanalytics ruleexpression validation - Question #10Monitoring, Reporting, and Troubleshooting
Which three ports can be used to send Syslogs to FortiSIEM? (Choose three.)
syslog portsUDP 514TCP 514TCP 1470 - Question #11Monitoring, Reporting, and Troubleshooting
In the advanced analytical rules engine in FortiSIEM, multiple subpatterms can be referenced using which three operation?(Choose three.)
analytical rules enginesubpattern operatorsFOLLOWED_BYlogical operators - Question #12Device and collector management
Device discovery information is stored in which database?
CMDBdevice discoverydatabase architecture - Question #13FortiSIEM deployment and configuration
Which FortiSIEM components can do performance availability and performance monitoring?
supervisorworkercollectorperformance monitoring - Question #14Device and collector management
Which command displays the Linux agent status?
Linux agentCLI commandsagent status - Question #15Device and collector management
Which discovery scan type is prone to miss a device, if the device is quiet and the entry foe that device is not present in the ARP table of adjacent devices?
L2 scandevice discoveryARP tablescan types - Question #16Incident management
What are the four possible incident status values?
incident statusincident lifecycle - Question #17Device and collector management
Refer to the exhibit. What do the yellow stars listed in the Monitor column indicate?
performance metricsmonitoring indicatorsdata collectiondiscovery - Question #18Device and collector management
Refer to the exhibit. A FortiSIEM administrator wants to collect both SIEM event logs and performance and availability metrics (PAM) events from a Microsoft Windows server. Which p...
WMIaccess protocolWindows monitoringPAM events - Question #19FortiSIEM deployment and configuration
Which database is used for storing anomaly data, that is calculated for different parameters, such as traffic and device resource usage running averages, and standard deviation val...
Profile DBanomaly detectionbaselinedatabase architecture - Question #20Device and collector management
What is a prerequisite for FortiSIEM Linux agent installation?
Linux agentauditdinstallation prerequisites - Question #21Event parsing and normalization
An administrator wants to search for events received from Linux and Windows agents. Which attribute should the administrator use in search filters, to view events received from age...
event searchagent eventssearch filtersevent attributes - Question #22FortiSIEM deployment and configuration
When configuring collectors located in geographically separated sites, what ports must be open on a front end firewall?
collector configurationfirewall portsHTTPSnetwork topology - Question #23Troubleshooting
An administrator is in the process of renewing a FortiSIEM license. Which two commands will provide the system ID? (Choose two.)
license managementsystem IDCLI commandsphgetHWID - Question #24Incident management
Refer to the exhibit. Which section contains the sortings that determine how many incidents are created?
incident creationGroup Byrule configurationaggregation - Question #25Troubleshooting
Refer to the exhibit. What does the pause icon indicate?
data collectionpause indicatormonitoring statuscredential issues - Question #26Reports and dashboards
Refer to the exhibit. A FortiSIEM administrator wants to group some attributes for a report, but is not able to do so successfully. As shown in the exhibit, why are some of the fie...
report configurationattribute groupingunique attributesreport design - Question #27Event parsing and normalization
Refer to the exhibit. Which value will FortiSIEM use to populate the Event Type field?
event typeevent parsingfield mappingperformance events - Question #28Device and collector management
An administrator defines SMTP as a critical process on a Linux server. It the SMTP process is stopped. FortiSIEM will generate a critical event with which event type?
process monitoringevent typecritical processPH_DEV_MON - Question #29Troubleshooting
Refer to the exhibit. An administrator is investigating a FortiSIEM license issue. The procedure is for which offline licensing condition?
offline licensinglicense registrationlicense management - Question #30Reports and dashboards
Which FortiSIEM feature must you use to produce a report on which FortiGate devices in your environment are running which firmware version?
inventoryCMDBfirmware reportingFortiGate devices - Question #31Device and collector management
Which statement about global thresholds and per device thresholds is true?
global thresholdsper-device thresholdsperformance metricsmonitoring configuration - Question #32Incident management
Where do you configure rule notifications and automated remediation on FortiSIEM?
rule notificationsautomated remediationnotification policyincident response - Question #33Incident management
What are the four categories of incidents?
incident categoriesperformanceavailabilitysecurity - Question #34Troubleshooting
Refer to the exhibit. The FortiSIEM administrator is examining events for two devices to investigate an issue. However, the administrator is not getting any results from their sear...
event searchboolean operatorssearch filtersquery logic - Question #35Device and collector management
An administrator is using SNMP and WMI credentials to discover a Windows device. How will the WMI method handle this?
WMI credentialsWindows device discoveryevent logsdevice monitoring - Question #36Device and collector management
Refer to the exhibit. How was the FortiGate device discovered by FortiSIEM?
auto log discoveryFortiGatedevice discoverysyslog - Question #37FortiSIEM deployment and configuration
A customer is experiencing slow performance while executing long, adhoc analytic searches Which FortiSIEM component can make the searches run faster?
query workeranalytic searchesperformance optimizationFortiSIEM components - Question #38Incident management
In the rules engine, which condition instructs FortiSIEM to summarize and count the matching evaluated data?
rules engineaggregationevent correlationrule conditions - Question #39Reports and dashboards
Refer to the exhibit. If events are grouped by Reporting IP, Event Type, and user attributes in FortiSIEM, how ,many results will be displayed?
event groupinggroup by attributessearch resultsdata aggregation - Question #40Incident management
If an incident's status is Cleared, what does this mean?
incident statuscleared statusrule clear conditionincident lifecycle - Question #41Troubleshooting
Refer to the exhibit. A FortiSIEM is continuously receiving syslog events from a FortiGate firewall. The FortiSlfcM administrator is trying to search the raw event logs for the las...
raw event searchcase sensitivitysearch filterskeyword search - Question #42Device and collector management
In FortiSIEM enterprise licensing mode, it the link between the collector and data center FortiSlEM cluster is down, what happens?
collector bufferingenterprise licensinglink failureevent collection - Question #43FortiSIEM deployment and configuration
Which two FortiSIEM components work together to provide real-time event correlation?
real-time correlationsupervisorworkerFortiSIEM architecture - Question #44FortiSIEM deployment and configuration
FortiSIEM is deployed in disaster recovery mode. When disaster strikes, which two tasks must you perform manually to achieve a successful disaster recovery operation? (Choose two.)
disaster recoverysecondary supervisorDNS configurationfailover - Question #45Reports and dashboards
IF the reported packet loss is between 50% and 98%. which status is assigned to the device in the Availability column of summary dashboard?
packet lossavailability statusdegraded statussummary dashboard - Question #46Device and collector management
An administrator is configuring FortiSIEM to discover network devices and receive syslog from network devices. Which statement is correct?
syslog configurationdevice discoverynetwork devicesmanual configuration - Question #47Reports and dashboards
Refer to the exhibit. It events are grouped by Event Type and User attributes in FortiSIEM. how many results will be displayed?
event groupinggroup by attributessearch resultsdata aggregation - Question #48Reports and dashboards
Refer to the exhibit. If events are grouped by User. Source IP. and Application Category attributes in FortiSiEM. how many results will be displayed?
event groupinggroup by attributessearch resultsunique combinations - Question #49Incident management
If a performance rule is triggered repeatedly due to high CPU use, what occurs in the incident table?
performance rulesincident countCPU utilizationincident table - Question #50
Which protocol do collectors use to communicate with a FortiSIEM cluster?