Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: best70

NSE6_FSM_AN-7.4 Fortinet NSE 6 - FortiSIEM 7.4 Analyst Questions and Answers

Questions 4

Refer to the exhibits.

NSE6_FSM_AN-7.4 Question 4

You are troubleshooting why the rule shown in the exhibit is generating incidents for successful Remote Desktop Protocol (RDP) connections with correct logins. It should only be triggering when a person fails to log in three or more times to the target device when connecting with RDP.

What is causing the rule to be triggered by correct login events? (Choose one answer)

Options:

A.

The subpattern relationship RDP_Connection:User = Failed_Logon:User never matches.

B.

The Boolean between the subpatterns is incorrect.

C.

The attribute types in the subpatterns do not match.

D.

The RDP login is different from the login used to access the target device.

Buy Now
Questions 5

Refer to the exhibit.

NSE6_FSM_AN-7.4 Question 5

A FortiSIEM analyst is investigating an issue by examining events to two destination IP addresses. However, the analyst is not getting any results from the search.

Based on the selected filter shown in the exhibit, why is the search returning no results?

Options:

A.

Parentheses are missing between the two items.

B.

The wrong Boolean operator is selected in the Next column.

C.

The wrong option is selected in the Operator column.

D.

An invalid IP address is typed in the Value column.

Buy Now
Questions 6

You want to create a rule with multiple subpatterns but trigger an incident only if three different subpatterns are matched over a 24-hour period.

Where must you define the time period that the rule uses to evaluate all the subpatterns? (Choose one answer)

Options:

A.

Define the time window in each individual subpattern.

B.

Define the time window under the General tab of the rule.

C.

Define the time window under the Define Condition tab of the rule.

D.

Define the time window in the Define Action section of the rule.

Buy Now
Questions 7

Refer to the exhibit.

NSE6_FSM_AN-7.4 Question 7

Which two lookup types can you reference as the subquery in a nested analytics query? (Choose two.)

Options:

A.

LDAP Query

B.

CMDB Query

C.

SNMP Query

D.

Event Query

Buy Now
Questions 8

Refer to the exhibit.

NSE6_FSM_AN-7.4 Question 8

If you group the events by User , Source IP , and Count attributes, how many results will FortiSIEM display?

Options:

A.

Two

B.

Six

C.

Three

D.

Five

E.

Four

Buy Now
Questions 9

Which statement about thresholds is true?

Options:

A.

FortiSIEM uses fixed, hardcoded global and device thresholds for all performance metrics.

B.

FortiSIEM uses only device thresholds for security metrics.

C.

FortiSIEM uses global and per-device thresholds for performance metrics.

D.

FortiSIEM uses only global thresholds for performance metrics.

Buy Now
Questions 10

Refer to the exhibit.

NSE6_FSM_AN-7.4 Question 10

Which value would you expect the FortiSIEM parser to use to populate the Application Name field?

Options:

A.

applist

B.

Network.Service

C.

SSL

D.

wan1

Buy Now
Questions 11

Refer to the exhibit.

NSE6_FSM_AN-7.4 Question 11

What is the Group: FortiSIEM Analysts value referring to?

Options:

A.

FortiSIEM organization group

B.

LDAP user group

C.

CMDB user group

D.

Windows Active Directory user group

Buy Now
Questions 12

Refer to the exhibit.

NSE6_FSM_AN-7.4 Question 12

An analyst is trying to identify an issue using an expression based on the Expression Builder settings shown in the exhibit; however, the error message shown in the exhibit indicates that the expression is invalid.

What is the correct syntax to create an expression that generates a total count of matched events?

Options:

A.

COUNT(Matched Events)

B.

(COUNT) Matched Events

C.

Matched Events (COUNT)

D.

Matched Events COUNT()

Buy Now
Questions 13

Refer to the exhibit.

NSE6_FSM_AN-7.4 Question 13

How was this incident cleared?

Options:

A.

The analyst manually cleared the incident from the incident table.

B.

FortiSIEM cleared the incident automatically after 24 hours.

C.

The incident was cleared automatically by the rule.

D.

The endpoint was rebooted and sent an all-clear signal to FortiSIEM.

Buy Now
Questions 14

Refer to the exhibit.

NSE6_FSM_AN-7.4 Question 14

Which statement about the time range settings defined in the nested query is accurate? (Choose one answer)

Options:

A.

FortiSIEM will list source IP addresses found in the last 10 minutes of events from each day in the Approved Devices report from the last 30 days.

B.

FortiSIEM will search in real time using 10-minute blocks for a source IP address that is not in the Approved Devices report from the last 30 days.

C.

FortiSIEM will search the last 30 days of events for a source IP address that is not in the Approved Devices report.

D.

FortiSIEM will search the last 10 minutes of events for a source IP address that is not in the Approved Devices report from the last 30 days.

Buy Now
Exam Code: NSE6_FSM_AN-7.4
Exam Name: Fortinet NSE 6 - FortiSIEM 7.4 Analyst
Last Update: Aug 4, 2026
Questions: 48

PDF + Testing Engine

$134.99

Testing Engine

$99.99

PDF (Q&A)

$84.99