Summer Sale - Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70dumps

NSE6_FSM_AN-7.4 Questions and Answers

Question # 6

Refer to the exhibits.

Question # 6

Question # 6

Three events are collected over 10 minutes from two servers: Server A and Server B.

Based on the settings for the rule subpattern and a 10-minute condition window, how many incidents will the servers generate?

A.

Server A will generate one incident and Server B will generate one incident.

B.

Server A will not generate any incidents and server B will generate one incident.

C.

Server A will not generate any incidents and Server B will not generate any incidents.

D.

Server A will generate one incident and Server B will not generate any incidents.

Full Access
Question # 7

Which analytics search can be used to apply a user and entity behavior analytics (UEBA) tag to an event for a failed login by the user JSmith?

A.

User = smith

B.

Username NOT END WITH jsmith

C.

User IS jsmith

D.

Username CONTAIN smit

Full Access
Question # 8

Refer to the exhibit.

Question # 8

What will FortiSIEM display if you apply the Group By and Display Fields configuration to a list of allowed firewall connections?

A.

A list of connections ordered by destination IP address hit count

B.

A list of connections between unique source and destination IP addresses

C.

A running count of connections, regardless of source or destination

D.

A list of connections ordered by the number of unique connections started by each source IP address

Full Access
Question # 9

Refer to the exhibit.

Question # 9

The configuration shown in the exhibit is incorrect.

What must you change to allow this configuration to be successfully applied to FortiSIEM?

A.

The Train factor must be 70% or greater.

B.

Run Mode must be set to ML.

C.

Only one AVG type field must be selected under Fields to use for Prediction.

D.

The selection in Fields to use for Prediction and Field to Predict must match.

Full Access
Question # 10

Which two data areas can you use for user and entity behavior analytics (EBA) machine learning models? (Choose two.)

A.

Process

B.

Location

C.

Resources

D.

Network

Full Access
Question # 11

Refer to the exhibit.

Question # 11

An analyst is troubleshooting the rule shown in the exhibit. It is not generating any incidents, but the filter parameters are generating events on the Analytics tab.

What is wrong with the rule conditions?

A.

The Event Type refers to a CMDB lookup and should be an Event lookup.

B.

The Destination Host Name value is not fully qualified.

C.

The Group By attributes restricts which events are counted.

D.

The Aggregate attribute is too restrictive.

Full Access
Question # 12

Refer to the exhibit.

Question # 12

Which statement about the time range settings defined in the nested query is accurate? (Choose one answer)

A.

FortiSIEM will list source IP addresses found in the last 10 minutes of events from each day in the Approved Devices report from the last 30 days.

B.

FortiSIEM will search in real time using 10-minute blocks for a source IP address that is not in the Approved Devices report from the last 30 days.

C.

FortiSIEM will search the last 30 days of events for a source IP address that is not in the Approved Devices report.

D.

FortiSIEM will search the last 10 minutes of events for a source IP address that is not in the Approved Devices report from the last 30 days.

Full Access
Question # 13

Which information can FortiSIEM retrieve from FortiClient EMS through an API connection?

A.

Host software versions

B.

FortiSIEM license

C.

Host login credentials

D.

ZTNA tags

Full Access
Question # 14

Refer to the exhibit.

Question # 14

What is the Group: FortiSIEM Analysts value referring to?

A.

FortiSIEM organization group

B.

LDAP user group

C.

CMDB user group

D.

Windows Active Directory user group

Full Access