Weekend Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: netbudy65

NSE5_FSM-6.3 Fortinet NSE 5 - FortiSIEM 6.3 Questions and Answers

Questions 4

Consider the storage of anomaly baseline date that is calculated for different parameters. Which database is used for storing this data?

Options:

A.

Event DB

B.

Profile DB

C.

SVNDB

D.

CMDB

Buy Now
Questions 5

An administrator wants to search for events received from Linux and Windows agents.

Which attribute should the administrator use in search filters, to view events received from agents only.

Options:

A.

External Event Receive Protocol

B.

Event Received Proto Agents

C.

External Event Receive Raw Logs

D.

External Event Receive Agents

Buy Now
Questions 6

In the rules engine, which condition instructs FortiSIEM to summarize and count the matching evaluated data?

Options:

A.

Time Window

B.

Aggregation

C.

Group By

D.

Filters

Buy Now
Questions 7

How is a subparttern for a rule defined?

Options:

A.

Filters Aggregation. Group By definition

B.

Filters Group By definitions. Threshold

C.

Filters Threshold Time Window definitions

D.

Filters Aggregation Time Window definitions

Buy Now
Questions 8

In the advanced analytical rules engine in FortiSIEM, multiple subpatterms can be referenced using which three operation?(Choose three.)

Options:

A.

ELSE

B.

NOT

C.

FOLLOWED_BY

D.

OR

E.

AND

Buy Now
Questions 9

Refer to the exhibit.

NSE5_FSM-6.3 Question 9

A FortiSIEM administrator wants to group some attributes for a report, but is not able to do so successfully.

As shown in the exhibit, why are some of the fields highlighted in red?

Options:

A.

Unique attributes cannot be grouped.

B.

The Event Receive Time attribute is not available for logs.

C.

The attribute COUNT(Matched events) is an invalid expression.

D.

No RAW Event Log attribute is available for devices.

Buy Now
Questions 10

Refer to the exhibit.

NSE5_FSM-6.3 Question 10

What does the pauso icon indicate?

Options:

A.

Data collection is paused after the intervals shown for metrics.

B.

Data collection has not started.

C.

Data collection execution failed because the device is not reachable.

D.

Data collection is paused duo to an issue, such as a change of password.

Buy Now
Questions 11

If an incident’s status is Cleared, what does this mean?

Options:

A.

Two hours have passed since the incident occurred and the incident has not reoccurred.

B.

A clear condition set on a rule was satisfied.

C.

A security rule issue has been resolved.

D.

The incident was cleared by an operator.

Buy Now
Questions 12

Refer to the exhibit.

NSE5_FSM-6.3 Question 12

A FortiSIEM is continuously receiving syslog events from a FortiGate firewall The FortiSlfcM administrator is trying to search the raw event logs for the last two hours that contain the keyword tcp . However, the administrator is getting no results from the search.

Based on the selected filters shown in the exhibit, why are there no search results?

Options:

A.

The keyword is case sensitive Instead of typing TCP in the Value field. the administrator should type tcp.

B.

In the Time section, the administrator selected the Relative Last option, and in the drop-down lists, selected 2 and Hours as the lime period The time period should be 24 hours.

C.

The administrator selected - in the Operator column That a the wrong operator.

D.

The administrator selected AND in the Next drop-down list. This is the wrong boolean operator.

Buy Now
Questions 13

Which command displays the Linux agent status?

Options:

A.

Service fsm-linux-agent status

B.

Service Ao-linux-agent status

C.

Service fortisiem-linux-agent status

D.

Service linux-agent status

Buy Now
Questions 14

Refer to the exhibits.

NSE5_FSM-6.3 Question 14

NSE5_FSM-6.3 Question 14

Three events are collected over a 10-minute time period from two servers: Server A and Server B.

Based on the settings tor the rule subpattern. how many incidents will the servers generate?

Options:

A.

Server A will generate one incident and Server B will generate one incident.

B.

Server A will generate one incident and Server B will not generate any incidents.

C.

Server B will generate one incident and Server A will not generate any incidents.

D.

Server A will not generate any incidents and Server B will not generate any incidents.

Buy Now
Questions 15

Which statement about global thresholds and per device thresholds is true?

Options:

A.

FortiSIEM uses global and per device thresholds tor all performance metrics.

B.

FortiSIEM uses global thresholds for all performance metrics.

C.

FortiSIEM uses fixed hardcoded thresholds for all performance metrics.

D.

FortiSIEM uses global thresholds for all security metrics.

Buy Now
Exam Code: NSE5_FSM-6.3
Exam Name: Fortinet NSE 5 - FortiSIEM 6.3
Last Update: Oct 16, 2025
Questions: 64

PDF + Testing Engine

$134.99

Testing Engine

$99.99

PDF (Q&A)

$84.99