Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Pass the Fortinet NSE 5 Network Security Analyst NSE5_FSM-6.3 Questions and answers with ValidTests

Exam NSE5_FSM-6.3 All Questions
Exam NSE5_FSM-6.3 Premium Access

View all detail and faqs for the NSE5_FSM-6.3 exam

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

An administrator is using SNMP credential only for discovery of a Windows device. How will FortiSIEM handle this?

Options:

A.

FortiSIEM will apply a job to collect application event logs.

B.

FortiSIEM will apply system monitor jobs to collect resources data.

C.

FortiSIEM will apply a Job to collect security event logs

D.

FortiSIEM will apply a job to collect system event logs.

Expert Solution
Questions # 2:

Device discovery information is stored in which database?

Options:

A.

CMDB

B.

Profile DB

C.

Event DB

D.

SVN DB

Expert Solution
Questions # 3:

Refer to the exhibits.

Question # 3

Question # 3

Three events are collected over a 10-minute time period from two servers: Server A and Server B.

Based on the settings tor the rule subpattern. how many incidents will the servers generate?

Options:

A.

Server A will generate one incident and Server B will generate one incident.

B.

Server A will generate one incident and Server B will not generate any incidents.

C.

Server B will generate one incident and Server A will not generate any incidents.

D.

Server A will not generate any incidents and Server B will not generate any incidents.

Expert Solution
Questions # 4:

Which three ports can be used to send Syslogs to FortiSIEM? (Choose three.)

Options:

A.

UDP9999

B.

UDP 162

C.

TCP 514

D.

UDP 514

E.

TCP 1470

Expert Solution
Questions # 5:

In the rules engine, which condition instructs FortiSIEM to summarize and count the matching evaluated data?

Options:

A.

Time Window

B.

Aggregation

C.

Group By

D.

Filters

Expert Solution
Questions # 6:

An administrator is configuring FortiSIEM to discover network devices and receive syslog from network devices. Which statement is correct?

Options:

A.

FortiSIEM uses privileged credentials to tog in to devices and make network configuration changes.

B.

FortiSIEM automatically configures network devices to send syslog using the auto log discovery process.

C.

FortiSIEM automatically configures network devices to send syslog using the GUI discovery process

D.

Syslog configuration must be done manually on devices by the network administrator.

Expert Solution
Questions # 7:

What are the four categories of incidents?

Options:

A.

Devices, users, high risk, and low risk

B.

Performance, devices, high risk, and low risk

C.

Performance, availability, security, and change

D.

Security, change, high risk, and low risk

Expert Solution
Questions # 8:

Refer to the exhibit.

Question # 8

The FortiSIEM administrator is examining events for two devices to investigate an issue. However, the administrator is not getting any results from their search.

Based on the selected filters shown in the exhibit, why is the search returning no results?

Options:

A.

Parenthesis are missing.

B.

The wrong boolean operator is selected in the Next column.

C.

The wrong option is selected in the Operator column.

D.

An invalid IP subnet is typed in the Value column.

Expert Solution
Questions # 9:

An administrator is in the process of renewing a FortiSIEM license. Which two commands will provide the system ID? (Choose two.)

Options:

A.

phgetHWID

B.

./phLicenseTool - support

C.

phgetUUID

D.

./phLicenseTool-show

Expert Solution
Questions # 10:

Refer to the exhibit.

Question # 10

How was the FortiGate device discovered by FortiSIEM?

Options:

A.

GUI log discovery

B.

Syslog discovery

C.

Pull events discovery

D.

Auto log discovery

Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions