Fortinet
NSE6_FSM_AN-7.4
Q1:
Refer to the exhibit.

As shown in the exhibit, why are some of the fields highlighted in red?
○
A
Unique values cannot be grouped○
B
The attribute COUNT(Matched Events) is an invalid expression.○
C
No RAW Event Log attribute information is available.○
D
The Event Receive Time attribute is not available for logs.
Fortinet
NSE6_FSM_AN-7.4
Q2:
In an automation policy, which two methods can you use to notify analysts when an incident is triggered? (Choose two.)
☐
A
Email☐
B
FortiSIEM Case☐
C
Syslog☐
D
Pop-up window
Fortinet
NSE6_FSM_AN-7.4
Q3:
Which items are used to define a subpattern?
○
A
Filters, Aggregate, Group By definitions○
B
Filters, Aggregate, Time Window definitions○
C
Filters, Group By, Threshold definitions○
D
Filters, Threshold, Time Window definitions
Fortinet
NSE6_FSM_AN-7.4
Q4:
Refer to the exhibit.

If you group the events by User and Count attributes, how many results will FortiSIEM display?
○
A
Two○
B
Six○
C
Three○
D
Five○
E
One
Fortinet
NSE6_FSM_AN-7.4
Q5:
What are two required components of a rule? (Choose two.)
☐
A
Exception policy☐
B
Subpattern☐
C
Detection Technology☐
D
Clear policy