Questions for the NSE5-FSM-5-2 were updated on : Nov 06 ,2024
Refer to the exhibit.
A FortiSlEM administrator wants to group some attributes for a report, but is not able to do so
successfully.
As shown in the exhibit, why are some of the fields highlighted in red?
C
In the rules engine, which condition instructs FortiSIEM to summarize and count the matching
evaluated data?
B
Refer to the exhibit.
How was the FortiGate device discovered by FortiSIEM?
A
Refer to the exhibit.
If events are grouped by Reporting IP, Event Type, and user attributes in FortiSIEM, how ,many
results will be displayed?
D
Which two FortiSIEM components work together to provide real-time event correlation?
D
If an incident’s status is Cleared, what does this mean?
B
Refer to the exhibit.
A FortiSIEM is continuously receiving syslog events from a FortiGate firewall The FortiSlfcM
administrator is trying to search the raw event logs for the last two hours that contain the keyword
tcp . However, the administrator is getting no results from the search.
Based on the selected filters shown in the exhibit, why are there no search results?
C
Which FortiSIEM components are capable of performing device discovery?
D
Refer to the exhibit.
An administrator is trying to identify an issue using an expression bated on the Expression Builder
settings shown in the exhibit however, the error message shown in the exhibit indicates that the
expression is invalid.
Which is the correct expression?
C
If the reported packet loss is between 50% and 98%. which status is assigned to the device in the
Availability column of summary dashboard?
D
Which three ports can be used to send Syslogs to FortiSIEM? (Choose three.)
CDE
In the advanced analytical rules engine in FortiSIEM, multiple subpatterms can be referenced using
which three operation?(Choose three.)
ABE
Device discovery information is stored in which database?
A
An administrator defines SMTP as a critical process on a Linux server. If the SMTP process is stopped,
FortiSIEM would generate a critical event with which event type?
A
Which FortiSIEM components can do performance availability and performance monitoring?
A