Fortinet
FCP_FSM_AN-7.2
Q1:
How does FortiSIEM update the incident table if a performance rule triggers repeatedly?
○
A
FortiSIEM changes the incident status to Repeated, and updates the Last Seen timestamp.○
B
FortiSIEM updates the Incident Count value and Last Seen timestamp.○
C
FortiSIEM generates a new incident based on the Rule Frequency value, and updates the First Seen and Last Seen timestamps.○
D
FortiSIEM generates a new incident each time the rule triggers, and updates the First Seen and Last Seen timestamps.
Fortinet
FCP_FSM_AN-7.2
Q2:
Refer to the exhibit.

If a rule containing the automation policy shown in the exhibit triggers, what will happen?
○
A
Associated source IP addresses will be blocked on devices in the Aviation organization.○
B
Associated source IP addresses will be blocked on all FortiGate firewalls.○
C
Associated source IP addresses will be blocked on devices in the Network CMDB group.○
D
Associated source IP addresses will be blocked on two FortiGate firewalls.
Fortinet
FCP_FSM_AN-7.2
Q3:
Which information can FortiSIEM retrieve from FortiClient EMS through an API connection?
○
A
Host software versions○
B
FortiSIEM license○
C
Host login credentials○
D
ZTNA tags
Fortinet
FCP_FSM_AN-7.2
Q4:
Which analytics search can be used to apply a user and entity behavior analytics (UEBA) tag to an event for a failed login by the user JSmith?
○
A
User = smith○
B
Username NOT END WITH jsmith○
C
User IS jsmith○
D
Username CONTAIN smit
Fortinet
FCP_FSM_AN-7.2
Q5:
What can you use to send data to FortiSIEM for user and entity behavior analytics (UEBA)?
○
A
FortiSIEM agent○
B
SSH○
C
SNMP○
D
FortiSIEM worker