Weekend Sale - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmaspas7

Easiest Solution 2 Pass Your Certification Exams

NSE5_FSM-6.3 Fortinet NSE 5 - FortiSIEM 6.3 Free Practice Exam Questions (2025 Updated)

Prepare effectively for your Fortinet NSE5_FSM-6.3 Fortinet NSE 5 - FortiSIEM 6.3 certification with our extensive collection of free, high-quality practice questions. Each question is designed to mirror the actual exam format and objectives, complete with comprehensive answers and detailed explanations. Our materials are regularly updated for 2025, ensuring you have the most current resources to build confidence and succeed on your first attempt.

Page: 1 / 1
Total 64 questions

If FortiSIEM supervisor is deployed with the worker using the proprietary flat file database, which action is required?

A.

An event database must be placed on NFS

B.

Collectors must be deployed

C.

A FortiSIEM service provider license must be obtained

D.

A separate network interface must be used for the storage network

In the CMDB page for a network device, the Configuration tab is unexpectedly empty. Which is a possible reason?

A.

The SNMP credential was a read-only credential.

B.

A Telnet/SSH credential was not configured for discovery.

C.

Configuration push is not enabled on the network device.

D.

Syslog was only being sent to a worker.

Refer to the exhibit.

An administrator is trying to identify an issue using an expression bated on the Expression Builder settings shown in the exhibit however, the error message shown in the exhibit indicates that the expression is invalid.

Which is the correct expression?

A.

Matched Events COUNT()

B.

Matched Events(COUNT)

C.

COUNT(Matched Events)

D.

(COUNT) Matched Events

Which FortiSIEM components are capable of performing device discovery?

A.

FortiSIEM Windows agent

B.

Worker

C.

FortiSIEM Linux agent

D.

Collector

Refer to the exhibit.

What do the yellow stars listed in the Monitor column indicate?

A.

A yellow star indicates that a metric was applied during discovery, and data has been collected successfully

B.

A yellow star indicates that a metric was applied during discovery, but data collection has not started

C.

A yellow star indicates that a metric was applied during discovery, but FortiSIEM is unable to collect data.

D.

A yellow star indicates that a metric was not applied during discovery and, therefore, FortiSEIM was unable to collect data.

What are two tasks that you must do to make a secondary FortiSIEM device ready for disaster recovery? (Choose two.)

A.

Configure the replication of CMDB database.

B.

Configure the replication of license and license entitlements.

C.

Configure the replication of FortiSIEM certificates.

D.

Configure the replication of profile data.

When configuring collectors located in geographically separated sites, what ports must be open on a front end firewall?

A.

HTTPS, from the collector to the worker upload settings address only

B.

HTTPS, from the collector to the supervisor and worker upload settings addresses

C.

HTTPS, from the Internet to the collector

D.

HTTPS, from the Internet to the collector and from the collector to the FortiSIEM cluster

In the advanced analytical rules engine in FortiSIEM, multiple subpatterms can be referenced using which three operation?(Choose three.)

A.

ELSE

B.

NOT

C.

FOLLOWED_BY

D.

OR

E.

AND

Which three ports can be used to send Syslogs to FortiSIEM? (Choose three.)

A.

UDP9999

B.

UDP 162

C.

TCP 514

D.

UDP 514

E.

TCP 1470

How is a subparttern for a rule defined?

A.

Filters Aggregation. Group By definition

B.

Filters Group By definitions. Threshold

C.

Filters Threshold Time Window definitions

D.

Filters Aggregation Time Window definitions

An administrator is in the process of renewing a FortiSIEM license. Which two commands will provide the system ID? (Choose two.)

A.

phgetHWID

B.

./phLicenseTool - support

C.

phgetUUID

D.

./phLicenseTool-show

Where do you configure rule notifications and automated remediation on FortiSIEM?

A.

Notification policy

B.

Remediation policy

C.

Notification engine

D.

Remediation engine

Refer to the exhibit.

How was the FortiGate device discovered by FortiSIEM?

A.

GUI log discovery

B.

Syslog discovery

C.

Pull events discovery

D.

Auto log discovery

Refer to the exhibit.

Which value will FortiSIEM use to populate the Connection Id field?

A.

33909

B.

134

C.

The connection ID is not in the raw message.

D.

408228

In FortiSIEM enterprise licensing mode, it the link between the collector and data center FortiSlEM cluster is down, what happens?

A.

The collector drops incoming events like syslog. but stops performance collection.

B.

The collector processes stop, and events ate dropped.

C.

The collector continues performance collection of devices, but slops receiving syslog.

D.

The collector buffers events

Consider the storage of anomaly baseline date that is calculated for different parameters. Which database is used for storing this data?

A.

Event DB

B.

Profile DB

C.

SVNDB

D.

CMDB

Which database is used for storing anomaly data, that is calculated for different parameters, such as traffic and device resource usage running averages, and standard deviation values?

A.

Profile DB

B.

Event DB

C.

CMDB

D.

SVN DB

Refer to the exhibit.

If events are grouped by Reporting IP, Event Type, and user attributes in FortiSIEM, how ,many results will be displayed?

A.

Seven results will be displayed.

B.

There results will be displayed.

C.

Unique attribute cannot be grouped.

D.

Five results will be displayed.

Which statement about global thresholds and per device thresholds is true?

A.

FortiSIEM uses global and per device thresholds tor all performance metrics.

B.

FortiSIEM uses global thresholds for all performance metrics.

C.

FortiSIEM uses fixed hardcoded thresholds for all performance metrics.

D.

FortiSIEM uses global thresholds for all security metrics.

Page: 1 / 1
Total 64 questions
Copyright © 2014-2025 Solution2Pass. All Rights Reserved