최신Fortinet NSE 6 - FortiSIEM 7.4 Analyst - NSE6_FSM_AN-7.4무료샘플문제
문제1
Refer to the exhibit. Which two actions can you select in an automation policy to trigger an API call to block an IP address on a FortiGate? (Choose two.)

Refer to the exhibit. Which two actions can you select in an automation policy to trigger an API call to block an IP address on a FortiGate? (Choose two.)

정답: A,C
설명: (ExamPassdump 회원만 볼 수 있음)
문제2
Which rule logic should you use to apply a user entity and behavior analytics (UEBA) tag to an event for a failed login incident by the account JSmith?
Which rule logic should you use to apply a user entity and behavior analytics (UEBA) tag to an event for a failed login incident by the account JSmith?
정답: A
설명: (ExamPassdump 회원만 볼 수 있음)
문제3
In an automation policy, which two methods can you use to notify analysts when an incident is triggered? (Choose two.)
In an automation policy, which two methods can you use to notify analysts when an incident is triggered? (Choose two.)
정답: B,C
문제4
A critical server is sending traffic that is triggering a high severity outbound intrusion prevention system (IPS) permitted IPS exploit rule. This traffic must be allowed. Which two items must you configure to prevent this sever from triggering the incident? (Choose two.)
A critical server is sending traffic that is triggering a high severity outbound intrusion prevention system (IPS) permitted IPS exploit rule. This traffic must be allowed. Which two items must you configure to prevent this sever from triggering the incident? (Choose two.)
정답: B,E
설명: (ExamPassdump 회원만 볼 수 있음)
문제5
Which information can FortiSIEM retrieve from FortiClient EMS through an API connection?
Which information can FortiSIEM retrieve from FortiClient EMS through an API connection?
정답: D
설명: (ExamPassdump 회원만 볼 수 있음)
문제6
Which two categories can you map to the MITRE ATT&CK coverage tables on FortiSIEM?
(Choose two.)
Which two categories can you map to the MITRE ATT&CK coverage tables on FortiSIEM?
(Choose two.)
정답: A,E
설명: (ExamPassdump 회원만 볼 수 있음)
문제7
Refer to the exhibit. If you group these events by the Reporting IP, Event Type, and User attributes, how many results will FortiSIEM display?

Refer to the exhibit. If you group these events by the Reporting IP, Event Type, and User attributes, how many results will FortiSIEM display?

정답: A
설명: (ExamPassdump 회원만 볼 수 있음)
문제8
When FortiSIEM is configured to apply ZTNA tags, what is the order of events when an analyst wants to automatically block a ZTNA tagged host?
When FortiSIEM is configured to apply ZTNA tags, what is the order of events when an analyst wants to automatically block a ZTNA tagged host?
정답: C
설명: (ExamPassdump 회원만 볼 수 있음)
문제9
When configuring machine learning (ML), in which step can you modify how the model fits the training data set?
When configuring machine learning (ML), in which step can you modify how the model fits the training data set?
정답: D
문제10
Refer to the exhibit.

FortiSIEM is receiving syslog events from a firewall.
You are trying to search raw event logs for traffic from the last two hours that contain the keyword
"UDP". However, you are getting no results from the search.
Based on the filter shown in the exhibit, why are you getting no search results?
Refer to the exhibit.

FortiSIEM is receiving syslog events from a firewall.
You are trying to search raw event logs for traffic from the last two hours that contain the keyword
"UDP". However, you are getting no results from the search.
Based on the filter shown in the exhibit, why are you getting no search results?
정답: A
설명: (ExamPassdump 회원만 볼 수 있음)