Pre-Winter Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: cramtick70

NSE6_FSM_AN-7.4 Fortinet NSE 6 - FortiSIEM 7.4 Analyst Questions and Answers

Questions 4

Refer to the exhibit.

What happens when an analyst clears an incident generated by a rule containing the automation policy shown in the exhibit?

Options:

A.

No notification is sent.

B.

An email is sent to the SOC manager.

C.

The remediation script is run.

D.

A notification is sent to the SOC manager dashboard.

Buy Now
Questions 5

Which statement about thresholds is true?

Options:

A.

FortiSIEM uses fixed, hardcoded global and device thresholds for all performance metrics.

B.

FortiSIEM uses only device thresholds for security metrics.

C.

FortiSIEM uses global and per-device thresholds for performance metrics.

D.

FortiSIEM uses only global thresholds for performance metrics.

Buy Now
Questions 6

Refer to the exhibit.

An analyst wants the rule shown in the exhibit to trigger when three failed login attempts occur within three minutes.

What should the values be for the condition time window and aggregate count?

Options:

A.

Time window 180 seconds, aggregate count 3

B.

Time window 180 seconds, aggregate count 2

C.

Time window 90 seconds, aggregate count 3

D.

Time window 90 seconds, aggregate count 2

Buy Now
Questions 7

You need to model for predicting a target based on other fields in the dataset and then trigger an anomaly if the value does not match the prediction.

Which machine learning algorithm will build this type of model?

Options:

A.

Classification

B.

Clustering

C.

Regression

D.

Forecasting

Buy Now
Questions 8

Refer to the exhibit.

How was this incident cleared?

Options:

A.

The analyst manually cleared the incident from the incident table.

B.

FortiSIEM cleared the incident automatically after 24 hours.

C.

The incident was cleared automatically by the rule.

D.

The endpoint was rebooted and sent an all-clear signal to FortiSIEM.

Buy Now
Questions 9

Refer to the exhibits.

You are troubleshooting why the rule shown in the exhibit is generating incidents for successful Remote Desktop Protocol (RDP) connections with correct logins. It should only be triggering when a person fails to log in three or more times to the target device when connecting with RDP.

What is causing the rule to be triggered by correct login events? (Choose one answer)

Options:

A.

The subpattern relationship RDP_Connection:User = Failed_Logon:User never matches.

B.

The Boolean between the subpatterns is incorrect.

C.

The attribute types in the subpatterns do not match.

D.

The RDP login is different from the login used to access the target device.

Buy Now
Questions 10

Refer to the exhibit.

A FortiSIEM analyst is investigating an issue by examining events to two destination IP addresses. However, the analyst is not getting any results from the search.

Based on the selected filter shown in the exhibit, why is the search returning no results?

Options:

A.

Parentheses are missing between the two items.

B.

The wrong Boolean operator is selected in the Next column.

C.

The wrong option is selected in the Operator column.

D.

An invalid IP address is typed in the Value column.

Buy Now
Questions 11

Which run mode takes the most time to perform machine learning tasks?

Options:

A.

Local Auto

B.

Local

C.

Forecasting

D.

Regression

Buy Now
Questions 12

When selecting multiple rules at once on FortiSIEM, what actions can you perform?

Options:

A.

You can change the severity of multiple rules, and activate or deactivate them.

B.

You can only view, edit, and activate a single rule at one time.

C.

You can only change the severity of multiple rules.

D.

You can only activate or deactivate multiple rules.

Buy Now
Questions 13

In an automation policy, which two methods can you use to notify analysts when an incident is triggered? (Choose two.)

Options:

A.

Email

B.

FortiSIEM Case

C.

Syslog

D.

Pop-up window

Buy Now
Questions 14

Refer to the exhibit.

As shown in the exhibit, why are some of the fields highlighted in red?

Options:

A.

Unique values cannot be grouped

B.

The attribute COUNT(Matched Events) is an invalid expression.

C.

No RAW Event Log attribute information is available.

D.

The Event Receive Time attribute is not available for logs.

Buy Now
Exam Code: NSE6_FSM_AN-7.4
Exam Name: Fortinet NSE 6 - FortiSIEM 7.4 Analyst
Last Update: Sep 11, 2026
Questions: 48
NSE6_FSM_AN-7.4 pdf

NSE6_FSM_AN-7.4 PDF

$25.5  $84.99
NSE6_FSM_AN-7.4 Engine

NSE6_FSM_AN-7.4 Testing Engine

$30  $99.99
NSE6_FSM_AN-7.4 PDF + Engine

NSE6_FSM_AN-7.4 PDF + Testing Engine

$40.5  $134.99