Black Friday Sale - Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70dumps

NSE5_FSM-6.3 Questions and Answers

Question # 6

Refer to the exhibit.

A FortiSIEM administrator wants to group some attributes for a report, but is not able to do so successfully.

As shown in the exhibit, why are some of the fields highlighted in red?

A.

Unique attributes cannot be grouped.

B.

The Event Receive Time attribute is not available for logs.

C.

The attribute COUNT(Matched events) is an invalid expression.

D.

No RAW Event Log attribute is available for devices.

Full Access
Question # 7

If a performance rule is triggered repeatedly due to high CPU use, what occurs in the incident table?

A.

A now incident is created each time the rule is triggered. and the First Seen and Last Seen times are updated.

B.

A new incident is created based on the Rule Frequency value, and the First Seen and Last Seen times ate updated.

C.

The Incident Count value increases, and the First Seen and Last Seen times update.

D.

The incident status changes to Repeated, and the First Seen and Last Seen times are updated.

Full Access
Question # 8

Refer to the exhibit.

Which section contains the sortings that determine how many incidents are created?

A.

Actions

B.

Group By

C.

Aggregate

D.

Filters

Full Access
Question # 9

An administrator is in the process of renewing a FortiSIEM license. Which two commands will provide the system ID? (Choose two.)

A.

phgetHWID

B.

./phLicenseTool - support

C.

phgetUUID

D.

./phLicenseTool-show

Full Access
Question # 10

Refer to the exhibits.

Three events are collected over a 10-minute time period from two servers: Server A and Server B.

Based on the settings tor the rule subpattern. how many incidents will the servers generate?

A.

Server A will generate one incident and Server B will generate one incident.

B.

Server A will generate one incident and Server B will not generate any incidents.

C.

Server B will generate one incident and Server A will not generate any incidents.

D.

Server A will not generate any incidents and Server B will not generate any incidents.

Full Access
Question # 11

In the advanced analytical rules engine in FortiSIEM, multiple subpatterms can be referenced using which three operation?(Choose three.)

A.

ELSE

B.

NOT

C.

FOLLOWED_BY

D.

OR

E.

AND

Full Access
Question # 12

IF the reported packet loss is between 50% and 98%. which status is assigned to the device in the Availability column of summary dashboard?

A.

Up status is assigned because of received packets.

B.

Critical status is assigned because of reduction in number of packets received.

C.

Degraded status is assigned because of packet loss

D.

Down status is assigned because of packet loss.

Full Access
Question # 13

Device discovery information is stored in which database?

A.

CMDB

B.

Profile DB

C.

Event DB

D.

SVN DB

Full Access
Question # 14

Refer to the exhibit.

How was the FortiGate device discovered by FortiSIEM?

A.

GUI log discovery

B.

Syslog discovery

C.

Pull events discovery

D.

Auto log discovery

Full Access
Question # 15

Which three ports can be used to send Syslogs to FortiSIEM? (Choose three.)

A.

UDP9999

B.

UDP 162

C.

TCP 514

D.

UDP 514

E.

TCP 1470

Full Access