Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the Fortinet NSE 5 Network Security Analyst NSE5_FSM-6.3 Questions and answers with ValidTests

Exam NSE5_FSM-6.3 All Questions
Exam NSE5_FSM-6.3 Premium Access

View all detail and faqs for the NSE5_FSM-6.3 exam

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

What action must you take to produce a report that indicates which OS version the Windows servers in your environment are running on?

Options:

A.

Use the Inventory tab to run a query

B.

Run a CMDB report

C.

Run an analytic search

D.

Run a baseline report

Expert Solution
Questions # 12:

In FortiSIEM enterprise licensing mode, it the link between the collector and data center FortiSlEM cluster is down, what happens?

Options:

A.

The collector drops incoming events like syslog. but stops performance collection.

B.

The collector processes stop, and events ate dropped.

C.

The collector continues performance collection of devices, but slops receiving syslog.

D.

The collector buffers events

Expert Solution
Questions # 13:

IF the reported packet loss is between 50% and 98%. which status is assigned to the device in the Availability column of summary dashboard?

Options:

A.

Up status is assigned because of received packets.

B.

Critical status is assigned because of reduction in number of packets received.

C.

Degraded status is assigned because of packet loss

D.

Down status is assigned because of packet loss.

Expert Solution
Questions # 14:

Which command displays the Linux agent status?

Options:

A.

Service fsm-linux-agent status

B.

Service Ao-linux-agent status

C.

Service fortisiem-linux-agent status

D.

Service linux-agent status

Expert Solution
Questions # 15:

Refer to the exhibit.

Question # 15

A FortiSIEM is continuously receiving syslog events from a FortiGate firewall The FortiSlfcM administrator is trying to search the raw event logs for the last two hours that contain the keyword tcp . However, the administrator is getting no results from the search.

Based on the selected filters shown in the exhibit, why are there no search results?

Options:

A.

The keyword is case sensitive Instead of typing TCP in the Value field. the administrator should type tcp.

B.

In the Time section, the administrator selected the Relative Last option, and in the drop-down lists, selected 2 and Hours as the lime period The time period should be 24 hours.

C.

The administrator selected - in the Operator column That a the wrong operator.

D.

The administrator selected AND in the Next drop-down list. This is the wrong boolean operator.

Expert Solution
Questions # 16:

A customer is experiencing slow performance while executing long, adhoc analytic searches. Which FortiSIEM component can make the searches run faster?

Options:

A.

Correlation worker

B.

Event worker

C.

Storage worker

D.

Query worker

Expert Solution
Questions # 17:

Which FortiSIEM feature must you use to produce a report on which FortiGate devices in your environment are running which firmware version?

Options:

A.

Run an analytic search.

B.

Run a query using the Inventory tab.

C.

Run a baseline report.

D.

Run a CMDB report

Expert Solution
Questions # 18:

Which discovery scan type is prone to miss a device, if the device is quiet and the entry foe that device is not present in the ARP table of adjacent devices?

Options:

A.

CMDB scan

B.

L2 scan

C.

Range scan

D.

Smart scan

Expert Solution
Questions # 19:

What can you do with rules on FortiSIEM?

Options:

A.

Only view, edit, and activate a single rule at one time

B.

Change the severity of multiple rules, and activate or de-activate multiple rules

C.

Only activate or de-activate multiple rules

D.

Only change the severity of multiple rules

Expert Solution
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions