Weekend Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = simple70

Pass the Fortinet NSE 5 Network Security Analyst NSE5_FSM-6.3 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam NSE5_FSM-6.3 Premium Access

View all detail and faqs for the NSE5_FSM-6.3 exam


503 Students Passed

96% Average Score

94% Same Questions
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

Where must you configure rule notifications and automated remediation on FortiSIEM?

Options:

A.

Notification engine

B.

Response policies

C.

Email and scripting alerts

D.

Notification policy

Questions # 2:

An administrator is configuring FortiSIEM to discover network devices and receive syslog from network devices. Which statement is correct?

Options:

A.

FortiSIEM uses privileged credentials to tog in to devices and make network configuration changes.

B.

FortiSIEM automatically configures network devices to send syslog using the auto log discovery process.

C.

FortiSIEM automatically configures network devices to send syslog using the GUI discovery process

D.

Syslog configuration must be done manually on devices by the network administrator.

Questions # 3:

How is a subpattern for a rule defined?

Options:

A.

Filters, Aggregation, Group by definitions

B.

Filters, Group By definitions, Threshold

C.

Filters, Threshold, Time Window definitions

D.

Filters, Aggregation, Time Window definitions

Questions # 4:

Which FortiSIEM components are capable of performing device discovery?

Options:

A.

FortiSIEM Windows agent

B.

Worker

C.

FortiSIEM Linux agent

D.

Collector

Questions # 5:

A customer is experiencing slow performance while executing long, adhoc analytic searches. Which FortiSIEM component can make the searches run faster?

Options:

A.

Correlation worker

B.

Event worker

C.

Storage worker

D.

Query worker

Questions # 6:

Which process converts raw log data to structured data?

Options:

A.

Data classification

B.

Data validation

C.

Data parsing

D.

Data enrichment

Questions # 7:

What are the four possible incident status values?

Options:

A.

Active, dosed, cleared, open

B.

Active, cleared, cleared manually, system cleared

C.

Active, closed, manual, resolved

D.

Active, auto cleared, manual, false positive

Questions # 8:

What are two tasks that you must do to make a secondary FortiSIEM device ready for disaster recovery? (Choose two.)

Options:

A.

Configure the replication of CMDB database.

B.

Configure the replication of license and license entitlements.

C.

Configure the replication of FortiSIEM certificates.

D.

Configure the replication of profile data.

Questions # 9:

If a performance rule is triggered repeatedly due to high CPU use, what occurs in the incident table?

Options:

A.

A now incident is created each time the rule is triggered. and the First Seen and Last Seen times are updated.

B.

A new incident is created based on the Rule Frequency value, and the First Seen and Last Seen times ate updated.

C.

The Incident Count value increases, and the First Seen and Last Seen times update.

D.

The incident status changes to Repeated, and the First Seen and Last Seen times are updated.

Questions # 10:

Which FortiSIEM feature must you use to produce a report on which FortiGate devices in your environment are running which firmware version?

Options:

A.

Run an analytic search.

B.

Run a query using the Inventory tab.

C.

Run a baseline report.

D.

Run a CMDB report

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.