11.11 Special Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

NSE5_FSM-6.3 Exam Dumps - Fortinet NSE 5 - FortiSIEM 6.3

Question # 4

Which FortiSIEM feature must you use to produce a report on which FortiGate devices in your environment are running which firmware version?

A.

Run an analytic search.

B.

Run a query using the Inventory tab.

C.

Run a baseline report.

D.

Run a CMDB report

Full Access
Question # 5

Consider the storage of anomaly baseline date that is calculated for different parameters. Which database is used for storing this data?

A.

Event DB

B.

Profile DB

C.

SVNDB

D.

CMDB

Full Access
Question # 6

Device discovery information is stored in which database?

A.

CMDB

B.

Profile DB

C.

Event DB

D.

SVN DB

Full Access
Question # 7

Which three ports can be used to send Syslogs to FortiSIEM? (Choose three.)

A.

UDP9999

B.

UDP 162

C.

TCP 514

D.

UDP 514

E.

TCP 1470

Full Access
Question # 8

What does the Frequency field determine on a rule?

A.

How often the rule will evaluate the subpattern.

B.

How often the rule will trigger for the same condition.

C.

How often the rule will trigger.

D.

How often the rule will take a clear action.

Full Access
Question # 9

Refer to the exhibit.

A FortiSIEM administrator wants to collect both SIEM event logs and performance and availability metrics (PAM) events from a Microsoft Windows server

Which protocol should the administrator select in the Access Protocol drop-down list so that FortiSIEM will collect both SIEM and PAM events?

A.

TELNET

B.

WMI

C.

LDAPS

D.

LDAP start TLS

Full Access
Question # 10

Refer to the exhibit.

Which section contains the sortings that determine how many incidents are created?

A.

Actions

B.

Group By

C.

Aggregate

D.

Filters

Full Access
Question # 11

Which process converts raw log data to structured data?

A.

Data classification

B.

Data validation

C.

Data parsing

D.

Data enrichment

Full Access
Question # 12

An administrator is configuring FortiSIEM to discover network devices and receive syslog from network devices. Which statement is correct?

A.

FortiSIEM uses privileged credentials to tog in to devices and make network configuration changes.

B.

FortiSIEM automatically configures network devices to send syslog using the auto log discovery process.

C.

FortiSIEM automatically configures network devices to send syslog using the GUI discovery process

D.

Syslog configuration must be done manually on devices by the network administrator.

Full Access
Question # 13

In me FortiSIEM CLI. which command must you use to determine whether or not syslog is being received from a network device?

A.

tcpdump

B.

OphSyslogRecorder

C.

Onetcat

D.

phDeviceTest

Full Access
Question # 14

Which discovery scan type is prone to miss a device, if the device is quiet and the entry foe that device is not present in the ARP table of adjacent devices?

A.

CMDB scan

B.

L2 scan

C.

Range scan

D.

Smart scan

Full Access
Question # 15

Refer to the exhibit.

What do the yellow stars listed in the Monitor column indicate?

A.

A yellow star indicates that a metric was applied during discovery, and data has been collected successfully

B.

A yellow star indicates that a metric was applied during discovery, but data collection has not started

C.

A yellow star indicates that a metric was applied during discovery, but FortiSIEM is unable to collect data.

D.

A yellow star indicates that a metric was not applied during discovery and, therefore, FortiSEIM was unable to collect data.

Full Access