Fortinet NSE 6 - FortiSIEM 7.4 Analyst Sample Questions:
1. When FortiSIEM is configured to apply ZTNA tags, what is the order of events when an analyst wants to automatically block a ZTNA tagged host?
A) FortiEMS tags host > FortiSIEM receives tag information > FortiSIEM tags host > ZTNA tags enforced on FortiGate
B) FortiEMS tags host > FortiEMS receives tag information > FortiSIEM tags host > ZTNA tags enforced on FortiGate
C) FortiSIEM tags host > FortiEMS receives tag information > FortiEMS tags host > ZTNA tags enforced on FortiGate
D) FortiEMS receives tag information > FortiEMS tags host > FortiSIEM tags host > ZTNA tags enforced on FortiGate
2. How can an administrator restrict the application of an automation policy on FortiSIEM? (Choose two.)
A) Apply the automation policy to specific Event Types
B) Apply the automation policy to a specific Incident and Incident Groups
C) Apply the automation policy to specific Rules and Rule Groups
D) Apply the automation policy to specific Organizations
3. Refer to the exhibit. What is this rule attempting to match?
A) Failed VPN logon attempts from three or more different outside countries.
B) Excessive VPN logon failures from a source inside the home country.
C) Failed VPN logon events from a source outside the home country.
D) Failed VPN logon attempts from three or more different sources inside the home country.
4. Refer to the exhibit. Which two items can be referenced in the incident details when this rule is triggered and creates an incident? (Choose two.)
A) Reporting Device
B) COUNT(Matched Events)
C) User
D) Domain Account Lockout
E) Event Type
5. Refer to the exhibit. You want to use a machine learning (ML) model to train data with the following characteristics shown in the exhibit. Which ML model is the best fit to match the data in the exhibit?
A) Forecasting
B) Elliptical envelope
C) Clustering
D) Anomaly detection
Solutions:
| Question # 1 Answer: A | Question # 2 Answer: C,D | Question # 3 Answer: C | Question # 4 Answer: A,C | Question # 5 Answer: C |
We're so confident of our products that we provide no hassle product exchange.


By Deborah

