Fortinet NSE 6 - FortiSIEM 7.4 Analyst - NSE6_FSM_AN-7.4 模擬練習
Refer to the exhibit.

Which statement about the time range settings defined in the nested query is accurate?

Which statement about the time range settings defined in the nested query is accurate?
正解: A
解説: (PassTest メンバーにのみ表示されます)
Refer to the exhibit.
The configuration for a machine learning (ML) dataset using anomaly detection is shown.

If data for this model is generated every hour, how long must the FortiSIEM device be up before it can produce a valid training set?
The configuration for a machine learning (ML) dataset using anomaly detection is shown.

If data for this model is generated every hour, how long must the FortiSIEM device be up before it can produce a valid training set?
正解: A
解説: (PassTest メンバーにのみ表示されます)
You want to build an event query that displays only events to higher number destination ports (1024-65535). Which analytic search string is valid for this scenario?
正解: B
解説: (PassTest メンバーにのみ表示されます)
From which two sources can you import data to train FortiSIEM machine learning? (Choose two.)
正解: B,D
You need a model for predicting a target field based on other fields in a dataset and then trigger an anomaly if the value does not match the prediction. Which machine learning algorithm will build this type of model?
正解: D
解説: (PassTest メンバーにのみ表示されます)
How can an administrator restrict the application of an automation policy on FortiSIEM? (Choose two.)
正解: A,B
解説: (PassTest メンバーにのみ表示されます)
Several new internal servers are generating incidents and must be excluded from several FortiSIEM rules. How must you tune rules to exclude several undiscovered devices from rules?
正解: C
解説: (PassTest メンバーにのみ表示されます)
Refer to the exhibit. Which section contains settings that determine which attribute associations are used to trigger an incident?


正解: C
Refer to the exhibit. According to the automation policy configuration shown in the exhibit, what happens if an associated rule triggers?


正解: A
解説: (PassTest メンバーにのみ表示されます)
Refer to the exhibits.


You want the rule shown in the exhibit to trigger when three failed login attempts occur within 3 minutes.
Which condition time window and aggregate values are correct for your objective?


You want the rule shown in the exhibit to trigger when three failed login attempts occur within 3 minutes.
Which condition time window and aggregate values are correct for your objective?
正解: D
解説: (PassTest メンバーにのみ表示されます)