Fortinet NSE 5 - FortiSIEM 6.3 Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 219 questions. Use the simulator for timed and flashcard mode.

Try Simulator

NSE5-FSM-6-3 Sample Questions

  1. Question 1

    Q1

    A Managed Security Service Provider (MSSP) is designing a new FortiSIEM deployment for a large enterprise client. The client has three major data centers across different continents and an estimated event rate of 50,000 EPS. The key requirements are centralized management, high availability for the analytics and reporting engine, and local event collection and parsing at each data center to minimize WAN traffic. Which architectural design best meets these requirements?

    Show answer & explanation

    Correct answer: B

    This is the standard and most effective architecture for a large, geographically distributed environment. The Supervisor/Worker cluster at the central location provides high availability for analytics, correlation, and reporting. Deploying Collectors at the client sites ensures that events are collected and parsed locally, significantly reducing the amount of raw log data sent over the WAN, as only parsed, compressed events are forwarded.

  2. Question 2

    Q2

    A security analyst needs to create a correlation rule to detect a potential brute-force attack followed by a successful login. The logic must identify at least 10 failed login events for the same user from the same source IP within a 5-minute window, which are then immediately followed by a successful login for that same user and source IP. How must the rule be constructed in FortiSIEM to achieve this specific sequence of events?

    flowchart TD A[Start: Event Received] --> B{Login Failed?}; B -- Yes --> C[Increment Counter for User/IP]; B -- No --> D{Login Successful?}; D -- No --> E[Ignore]; C --> F{Counter >= 10 in 5min?}; F -- Yes --> D; F -- No --> E; D -- Yes --> G{Same User/IP as failed attempts?}; G -- Yes --> H[Trigger Incident]; G -- No --> E; H --> I[End];

    Show answer & explanation

    Correct answer: B

    This scenario requires detecting a specific sequence of different event types. This is achieved using ordered sub-patterns. The first sub-pattern identifies the aggregated failed logins, and the second identifies the subsequent successful login. The 'Group By' clause is critical to ensure that both sub-patterns are correlated based on the same user and source IP address.

  3. Question 3

    Q3

    A FortiSIEM administrator is investigating a performance issue where the Supervisor node's CPU utilization is consistently high. After initial investigation, the cause is determined to be an excessive number of low-value syslog events coming from a newly added group of IoT devices. The security team has confirmed these specific events are not needed for analysis. What is the most efficient method within FortiSIEM to reduce the processing load on the Supervisor without losing visibility into other critical events from the same IoT devices?

    Show answer & explanation

    Correct answer: C

    The most efficient way to reduce the load on the Supervisor is to prevent the unwanted events from ever being sent to it. By creating an event dropping filter on the Collector, the noisy events are discarded at the source, saving bandwidth and reducing the parsing and processing load on the entire FortiSIEM cluster. This is the recommended best practice for tuning data collection.

  4. Question 4

    Q4

    True or False: In a multi-tenant FortiSIEM deployment, administrators from one organization can view and manage incidents belonging to another organization if they are granted Super/Global administrator privileges.

    Show answer & explanation

    Correct answer: B

    FortiSIEM enforces strict data segregation between organizations (tenants). Even a Super/Global administrator cannot view the specific incident or event data of another organization. They can manage system-level settings and organizations, but the data within each tenant is kept isolated to users assigned to that specific organization.

  5. Question 5

    Q5Multiple answers

    A financial institution is using FortiSIEM to monitor access to its critical database servers. A compliance requirement mandates a monthly report that shows a summary of distinct users who accessed each database server, along with the total number of connections per user. Which components of the FortiSIEM Analytics tab are required to create this specific report? (Select TWO)

    Show answer & explanation

    Correct answers: A, C

  6. Question 6

    Q6

    An administrator at a retail company is deploying a new FortiSIEM Collector in a branch store. After deployment, the Collector appears online in the FortiSIEM GUI, but no events from the store's devices are appearing in the central analytics console. The administrator has verified that devices are successfully sending syslog messages to the Collector's IP address. Which of the following is the most likely cause of this issue?

    Show answer & explanation

    Correct answer: C

    Collectors communicate their health status and parsed events to the Worker nodes via HTTPS (TCP/443). The Collector can appear online because initial registration with the Supervisor might have succeeded, but if the ongoing communication to the Workers is blocked, parsed events will not be uploaded. This is a common deployment issue in segmented networks.

  7. Question 7

    Q7

    A security team wants to create an incident that triggers when any user is added to a privileged group in Active Directory, such as 'Domain Admins'. However, they want to prevent an incident from being created if the change was performed by an approved administrator account (e.g., 'svc-ad-admin'). Which rule component should be used to achieve this?

    Show answer & explanation

    Correct answer: C

    The Filters section of a rule defines the primary conditions for an event to be considered a match. To create an exception, you define the broad condition (user added to 'Domain Admins') and then add an exception to the filter (e.g., 'Reporting User' NOT EQUAL 'svc-ad-admin'). This ensures the rule only triggers for unauthorized changes.

  8. Question 8

    Q8

    What is the primary purpose of the 'Define Condition' time field within a FortiSIEM rule?

    Show answer & explanation

    Correct answer: B

    The 'Define Condition' time field sets the evaluation window for the rule. For example, a value of '5m' means the rule will look for matching events within a 5-minute sliding window. This is crucial for time-based correlations, such as detecting multiple failed logins within a short period.

  9. Question 9

    Q9

    A systems administrator is tasked with deploying the FortiSIEM Windows Agent to 500 workstations across the enterprise. Which deployment method offers the most efficient and scalable solution for this task?

    Show answer & explanation

    Correct answer: C

    For a large number of endpoints, manual installation is not feasible. Using enterprise software deployment tools like GPO or SCCM allows for silent, automated, and centralized installation of the agent MSI package across hundreds or thousands of machines, ensuring consistency and efficiency.

  10. Question 10

    Q10Multiple answers

    An organization has configured a rule that generates a 'Malware Detected' incident. The security policy requires that when this incident is triggered, the infected endpoint's IP address is automatically added to a blocklist on the network's FortiGate firewall. Which two FortiSIEM components are primarily involved in this automated remediation process? (Select TWO)

    Show answer & explanation

    Correct answers: A, C

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the NSE5-FSM-6-3 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 219 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon