Fortinet NSE 6 - FortiSIEM 7.4 Analyst (NSE6_FSM_AN-7.4) Free Practice Test
Question 1
Refer to the exhibit.

An analyst wants the rule shown in the exhibit to trigger when three failed login attempts occur within three minutes.
What should the values be for the condition time window and aggregate count?

An analyst wants the rule shown in the exhibit to trigger when three failed login attempts occur within three minutes.
What should the values be for the condition time window and aggregate count?
Correct Answer: A
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 2
Refer to the exhibit.

FortiSIEM is receiving syslog events from a firewall.
You are trying to search raw event logs for traffic from the last two hours that contain the keyword
"UDP". However, you are getting no results from the search.
Based on the filter shown in the exhibit, why are you getting no search results?

FortiSIEM is receiving syslog events from a firewall.
You are trying to search raw event logs for traffic from the last two hours that contain the keyword
"UDP". However, you are getting no results from the search.
Based on the filter shown in the exhibit, why are you getting no search results?
Correct Answer: A
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 3
Refer to the exhibit. What is the Group: VPN Gateway value referring to?


Correct Answer: D
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 4
Refer to the exhibit. If you group these events by the Reporting IP, Event Type, and User attributes, how many results will FortiSIEM display?


Correct Answer: B
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 5
What are two required components in a rule? (Choose two.)
Correct Answer: C,D
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 6
Refer to the exhibit. When the subpattern is matched, what does the time condition of 60 seconds mean?


Correct Answer: D
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 7
Which two types of information can FortiSIEM retrieve from FortiClient EMS through an external connection? (Choose two.)
Correct Answer: B,C
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).