nerdexam
Fortinet

NSE5_FSM-6.3 · Question #18

Refer to the exhibit. A FortiSIEM administrator wants to collect both SIEM event logs and performance and availability metrics (PAM) events from a Microsoft Windows server. Which protocol should the…

The correct answer is B. WMI. Collecting SIEM and PAM Events: To collect both SIEM event logs and Performance and Availability Monitoring (PAM) events from a Microsoft Windows server, a suitable protocol must WMI Protocol: Windows Management Instrumentation (WMI) is the appropriate protocol for this SIEM…

Device and collector management

Question

Refer to the exhibit. A FortiSIEM administrator wants to collect both SIEM event logs and performance and availability metrics (PAM) events from a Microsoft Windows server. Which protocol should the administrator select in the Access Protocol drop-down list so that FortiSIEM will collect both SIEM and PAM events?

Exhibits

NSE5_FSM-6.3 question #18 exhibit 1
NSE5_FSM-6.3 question #18 exhibit 2

Options

  • ATELNET
  • BWMI
  • CLDAPS
  • DLDAP start TLS

How the community answered

(32 responses)
  • A
    3% (1)
  • B
    75% (24)
  • C
    13% (4)
  • D
    9% (3)

Explanation

Collecting SIEM and PAM Events: To collect both SIEM event logs and Performance and Availability Monitoring (PAM) events from a Microsoft Windows server, a suitable protocol must WMI Protocol: Windows Management Instrumentation (WMI) is the appropriate protocol for this SIEM Event Logs: WMI can collect security, application, and system logs from Windows devices. PAM Events: WMI can also gather performance metrics, such as CPU usage, memory utilization, and disk activity. Comprehensive Data Collection: Using WMI ensures that both types of data are collected efficiently from the Windows server.

Topics

#WMI#access protocol#Windows monitoring#PAM events

Community Discussion

No community discussion yet for this question.

Full NSE5_FSM-6.3 Practice