Fortinet
NSE5_FSM-6.3
Q1:
How is a subpattern for a rule defined?
○
A
Filters, Aggregation, Group by definitions○
B
Filters, Group By definitions, Threshold○
C
Filters, Threshold, Time Window definitions○
D
Filters, Aggregation, Time Window definitions
Fortinet
NSE5_FSM-6.3
Q2:
Refer to the exhibit.

If events are grouped by Reporting IP, Event Type, and user attributes in FortiSIEM, how ,many results will be displayed?
○
A
Seven results will be displayed.○
B
There results will be displayed.○
C
Unique attribute cannot be grouped.○
D
Five results will be displayed.
Fortinet
NSE5_FSM-6.3
Q3:
Which two FortiSIEM components work together to provide real-time event correlation?
○
A
Supervisor and worker○
B
Collector and Windows agent○
C
Worker and collector○
D
Supervisor and collector
Fortinet
NSE5_FSM-6.3
Q4:
In FortiSIEM enterprise licensing mode, it the link between the collector and data center FortiSlEM cluster is down, what happens?
○
A
The collector drops incoming events like syslog. but stops performance collection.○
B
The collector processes stop, and events ate dropped.○
C
The collector continues performance collection of devices, but slops receiving syslog.○
D
The collector buffers events
Fortinet
NSE5_FSM-6.3
Q5:
Which statement about global thresholds and per device thresholds is true?
○
A
FortiSIEM uses global and per device thresholds tor all performance metrics.○
B
FortiSIEM uses global thresholds for all performance metrics.○
C
FortiSIEM uses fixed hardcoded thresholds for all performance metrics.○
D
FortiSIEM uses global thresholds for all security metrics.