NSE6_FSM_AN-7.4 Fortinet NSE 6 - FortiSIEM 7.4 Analyst Questions and Answers
Refer to the exhibits.

You are troubleshooting why the rule shown in the exhibit is generating incidents for successful Remote Desktop Protocol (RDP) connections with correct logins. It should only be triggering when a person fails to log in three or more times to the target device when connecting with RDP.
What is causing the rule to be triggered by correct login events? (Choose one answer)
Refer to the exhibit.

A FortiSIEM analyst is investigating an issue by examining events to two destination IP addresses. However, the analyst is not getting any results from the search.
Based on the selected filter shown in the exhibit, why is the search returning no results?
You want to create a rule with multiple subpatterns but trigger an incident only if three different subpatterns are matched over a 24-hour period.
Where must you define the time period that the rule uses to evaluate all the subpatterns? (Choose one answer)
Refer to the exhibit.

Which two lookup types can you reference as the subquery in a nested analytics query? (Choose two.)
Refer to the exhibit.

If you group the events by User , Source IP , and Count attributes, how many results will FortiSIEM display?
Refer to the exhibit.

Which value would you expect the FortiSIEM parser to use to populate the Application Name field?
Refer to the exhibit.

An analyst is trying to identify an issue using an expression based on the Expression Builder settings shown in the exhibit; however, the error message shown in the exhibit indicates that the expression is invalid.
What is the correct syntax to create an expression that generates a total count of matched events?
Refer to the exhibit.

Which statement about the time range settings defined in the nested query is accurate? (Choose one answer)

