Summer Sale Limited Time 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = simple75

Pass the Fortinet NSE 6 Network Security Specialist NSE6_FSM_AN-7.4 Questions and answers with Dumpstech

Exam NSE6_FSM_AN-7.4 Premium Access

View all detail and faqs for the NSE6_FSM_AN-7.4 exam

Practice at least 50% of the questions to maximize your chances of passing.
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

Refer to the exhibit.

Question # 11

What is this rule attempting to match? (Choose one answer)

Options:

A.

Failed VPN logon attempts from three or more different outside countries.

B.

Failed VPN logon events from a source outside the home country.

C.

Failed VPN logon attempts from three or more different sources inside the home country.

D.

Excessive VPN logon failures from a source inside the home country.

Questions # 12:

In an automation policy, which two methods can you use to notify analysts when an incident is triggered? (Choose two.)

Options:

A.

Email

B.

FortiSIEM Case

C.

Syslog

D.

Pop-up window

Questions # 13:

You want to create a rule with multiple subpatterns but trigger an incident only if three different subpatterns are matched over a 24-hour period.

Where must you define the time period that the rule uses to evaluate all the subpatterns? (Choose one answer)

Options:

A.

Define the time window in each individual subpattern.

B.

Define the time window under the General tab of the rule.

C.

Define the time window under the Define Condition tab of the rule.

D.

Define the time window in the Define Action section of the rule.

Questions # 14:

Which information can FortiSIEM retrieve from FortiClient EMS through an API connection?

Options:

A.

Host software versions

B.

FortiSIEM license

C.

Host login credentials

D.

ZTNA tags

Questions # 15:

When configuring anomaly detection machine learning, in which step must you select the fields to analyze?

Options:

A.

Design

B.

Schedule

C.

Prepare Data

D.

Train

Questions # 16:

Refer to the exhibit.

Question # 16

A FortiSIEM analyst is investigating an issue by examining events to two destination IP addresses. However, the analyst is not getting any results from the search.

Based on the selected filter shown in the exhibit, why is the search returning no results?

Options:

A.

Parentheses are missing between the two items.

B.

The wrong Boolean operator is selected in the Next column.

C.

The wrong option is selected in the Operator column.

D.

An invalid IP address is typed in the Value column.

Questions # 17:

How can you query the configuration management database (CMDB) in an analytics search?

Options:

A.

Click Value > Select from CMDB.

B.

On the CMDB tab, select an entry, and then click Create Search.

C.

On the Admin tab, click CMDB Search.

D.

Click Attribute > Select from CMDB.

Questions # 18:

Refer to the exhibit.

Question # 18

What happens when an analyst clears an incident generated by a rule containing the automation policy shown in the exhibit?

Options:

A.

No notification is sent.

B.

An email is sent to the SOC manager.

C.

The remediation script is run.

D.

A notification is sent to the SOC manager dashboard.

Questions # 19:

Which analytics search can be used to apply a user and entity behavior analytics (UEBA) tag to an event for a failed login by the user JSmith?

Options:

A.

User = smith

B.

Username NOT END WITH jsmith

C.

User IS jsmith

D.

Username CONTAIN smit

Questions # 20:

Which two data areas can you use for user and entity behavior analytics (EBA) machine learning models? (Choose two.)

Options:

A.

Process

B.

Location

C.

Resources

D.

Network

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions