Winter Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: v4s65

NSE5_FSM-6.3 Exam Dumps - Fortinet NSE 5 - FortiSIEM 6.3

Go to page:
Question # 9

Refer to the exhibit.

A FortiSIEM administrator wants to collect both SIEM event logs and performance and availability metrics (PAM) events from a Microsoft Windows server

Which protocol should the administrator select in the Access Protocol drop-down list so that FortiSIEM will collect both SIEM and PAM events?

A.

TELNET

B.

WMI

C.

LDAPS

D.

LDAP start TLS

Full Access
Question # 10

Refer to the exhibit.

Which section contains the sortings that determine how many incidents are created?

A.

Actions

B.

Group By

C.

Aggregate

D.

Filters

Full Access
Question # 11

Which process converts raw log data to structured data?

A.

Data classification

B.

Data validation

C.

Data parsing

D.

Data enrichment

Full Access
Question # 12

An administrator is configuring FortiSIEM to discover network devices and receive syslog from network devices. Which statement is correct?

A.

FortiSIEM uses privileged credentials to tog in to devices and make network configuration changes.

B.

FortiSIEM automatically configures network devices to send syslog using the auto log discovery process.

C.

FortiSIEM automatically configures network devices to send syslog using the GUI discovery process

D.

Syslog configuration must be done manually on devices by the network administrator.

Full Access
Question # 13

In me FortiSIEM CLI. which command must you use to determine whether or not syslog is being received from a network device?

A.

tcpdump

B.

OphSyslogRecorder

C.

Onetcat

D.

phDeviceTest

Full Access
Question # 14

Which discovery scan type is prone to miss a device, if the device is quiet and the entry foe that device is not present in the ARP table of adjacent devices?

A.

CMDB scan

B.

L2 scan

C.

Range scan

D.

Smart scan

Full Access
Question # 15

Refer to the exhibit.

What do the yellow stars listed in the Monitor column indicate?

A.

A yellow star indicates that a metric was applied during discovery, and data has been collected successfully

B.

A yellow star indicates that a metric was applied during discovery, but data collection has not started

C.

A yellow star indicates that a metric was applied during discovery, but FortiSIEM is unable to collect data.

D.

A yellow star indicates that a metric was not applied during discovery and, therefore, FortiSEIM was unable to collect data.

Full Access
Go to page: