
[Jun-2024] Updated and Accurate NSE5_FSM-6.3 Questions & Answers for passing the exam Quickly
Download Real NSE5_FSM-6.3 Exam Dumps for candidates. 100% Free Dump Files
NEW QUESTION # 11
Which database is used for storing anomaly data, that is calculated for different parameters, such as traffic and device resource usage running averages, and standard deviation values?
- A. Profile DB
- B. Event DB
- C. CMDB
- D. SVN DB
Answer: A
NEW QUESTION # 12
Which command displays the Linux agent status?
- A. Service fortisiem-linux-agent status
- B. Service linux-agent status
- C. Service fsm-linux-agent status
- D. Service Aa-linux-agent status
Answer: A
NEW QUESTION # 13
A FortiSIEM administrator wants to collect both SIEM event logs and performance and availability metrics (PAM) events from a Microsoft Windows server
Which protocol should the administrator select in the AccessProtocoI drop-down list so that FortiSIEM will collect both SIEM and PAM events?
- A. WMI
- B. LDAPS
- C. LDAP start TLS
- D. TELNET
Answer: A
NEW QUESTION # 14
In the advanced analytical rules engine in FortiSIEM, multiple subpatterms can be referenced using which three operation? (Choose three.)
- A. FOLLOWED_BY
- B. ELSE
- C. OR
- D. AND
- E. NOT
Answer: A,C,D
NEW QUESTION # 15
Which three ports can be used to send Syslogs to FortiSIEM? (Choose three.)
- A. UDP 9999
- B. TCP 514
- C. TCP 1470
- D. UDP 514
- E. UDP 162
Answer: B,C,D
NEW QUESTION # 16
Which item is required to register a FortiSIEM appliance license?
- A. Static IP address
- B. Static Hardware ID
- C. Static storage
- D. Static MAC address
Answer: B
NEW QUESTION # 17
What is a prerequisite for a FortiSIEM supervisor with a worker deployment, using the proprietary flat file database?
- A. The archive mount must be on a local disk
- B. The event database must be on NFS
- C. The CMDB database must be on NFS
- D. The event database must be on a local disk
Answer: B
NEW QUESTION # 18
What are the minimum memory requirements for the FortiSIEM supervisor virtual appliance, when the proprietary flat file database is used?
- A. 32GB RAM
- B. 16G8 RAM
- C. 24GB RAM
- D. 64G8 RAM
Answer: C
NEW QUESTION # 19
If an incident's status is Cleared, what does this mean?
- A. The incident was cleared by an operator.
- B. Two hours have passed since the incident occurred and the incident has not reoccurred.
- C. A security rule issue has been resolved.
- D. A clear condition set an a rule was satisfied.
Answer: D
NEW QUESTION # 20
A FortiSIEM supervisor at headquarters is struggling to keep up with an increase of EPS (Events Per Second) being reported across the enterprise.
What components should an administrator consider deploying to assist the supervisor with processing data?
- A. Agent
- B. Supervisor
- C. Worker
- D. Collector
Answer: C
NEW QUESTION # 21
An administrator defines SMTP as a critical process on a Linux server.
If the SMTP process is stopped, FortiSIEM would generate a critical event with which event type?
- A. Generic SMTP Process Exit
- B. Postfix-Mail-Slop
- C. PH_DEV_MON_PROC_STOP
- D. PH_DEV_MON_SMTP_STOP
Answer: C
NEW QUESTION # 22
What are the four categories of incidents?
- A. Performance, availability, security, and change
- B. Performance, devices, high risk, and low risk
- C. Devices, users, high risk, and low risk
- D. Security, change, high risk, and low risk
Answer: A
NEW QUESTION # 23
If a performance rule is triggered repeatedly due to high CPU use. what occurs m the incident table?
- A. A new incident is created each time the rule is triggered, and the First Seen and Last Seen times are updated.
- B. A new incident is created based an the Rule Frequency value, and the First Seen and Last Seen times are updated
- C. The Incident Count value increases, and the First Seen and Last Seen tomes update
- D. The incident status changes to Repeated and the First Seen and Last Seen times are updated
Answer: C
NEW QUESTION # 24
A FortiSIEM is continuously receiving syslog events from a FortiGate firewall. The FortiSIEM administrator is trying to search the raw event logs for the last two hours that contain the keyword tcp . However, the administrator is getting no results from the search.
Based on the selected filters shown in the exhibit, why are there no search results?
- A. The administrator selected - in the Operator column That a the wrong operator.
- B. The keyword is case sensitive Instead of typing TCP in the Value field. the administrator should type tcp.
- C. The administrator selected AND in the Next drop-down list. This is the wrong boolean operator.
- D. In the Time section, the administrator selected the Relative Last option, and in the drop-dawn lists, selected 2 and Hours as the time period. The time period should be 24 hours.
Answer: A
NEW QUESTION # 25
Which process convertsRaw log data to structured data?
- A. Data parsing
- B. Data enrichment
- C. Data classification
- D. Data validation
Answer: A
NEW QUESTION # 26
What do the yellow stars listed in the Monitor column indicate?
- A. A yellow star indicates that a metric was applied during discovery, but data collection has not started
- B. A yellow star indicates that a metric was applied during discovery, and data has been collected successfully
- C. A yellow star indicates that a metric was applied during discovery, but FortiSIEM is unable to collect data
- D. A yellow star indicates that a metric was not applied during discovery and, therefore, FortiSIEM was unable to collect data.
Answer: A
NEW QUESTION # 27
FortiSIEM administrator wants to group some attributes for a report, but is not able to do so successfully.
As shown in the exhibit, why are some of the fields highlighted in red?
- A. No RAW Event Log attribute is available far devices.
- B. Unique attributes cannot be grouped.
- C. The Event Receive Time attribute is not available for lags.
- D. The attribute COUNT(Matched event) is an invalid expression.
Answer: B
NEW QUESTION # 28
......
Prepare Important Exam with NSE5_FSM-6.3 Exam Dumps: https://validexam.pass4cram.com/NSE5_FSM-6.3-dumps-torrent.html