Fortinet NSE6_FSM_AN-7.4 Exam Overview:
| Certification Vendor: | Fortinet |
| Exam Name: | Fortinet NSE 6 - FortiSIEM 7.4 Analyst |
| Exam Number: | NSE6_FSM_AN-7.4 |
| Real Exam Qty: | 35-40 |
| Related Certifications: | FortiSIEM 7.4 Analyst (FCSS Security Operations track) |
| Certificate Validity Period: | 2 years |
| Exam Duration: | 70 minutes |
| Passing Score: | Pass/Fail |
| Available Languages: | English |
| Exam Price: | $200 USD |
| Exam Format: | Multiple choice, Scenario-based questions |
| Recommended Training: | Fortinet Certified Security Operations Practice Tests FortiSIEM 7.4 Analyst Training |
| Exam Registration: | Fortinet Certification Registration Pearson VUE Fortinet Exams |
| Sample Questions: | Fortinet NSE6_FSM_AN-7.4 Sample Questions |
| Exam Way: | Online or onsite via Pearson VUE testing centers |
| Pre Condition: | Recommended experience with FortiSIEM operations and Security Operations workflows; prior Fortinet NSE 5 or equivalent knowledge is beneficial. |
| Official Syllabus URL: | https://training.fortinet.com/local/staticpage/view.php?page=fortisiem_analyst_exam |
Fortinet NSE6_FSM_AN-7.4 Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| Machine Learning, UEBA, and ZTNA | - Advanced analytics integration
|
| Analytics | - Query and event analysis
|
| Incidents, Notifications, and Remediation | - Incident management
|
| Rules and Subpatterns | - Analytics rules configuration
|
| FortiEDR Security Settings and Policies | - Security configuration
|
Fortinet NSE 6 - FortiSIEM 7.4 Analyst Sample Questions:
1. In an automation policy, which two methods can you use to notify analysts when an incident is triggered? (Choose two.)
A) Pop-up window
B) Syslog
C) Email
D) FortiSIEM Case
2. Refer to the exhibit.
FortiSIEM is receiving syslog events from a firewall.
You are trying to search raw event logs for traffic from the last two hours that contain the keyword
"UDP". However, you are getting no results from the search.
Based on the filter shown in the exhibit, why are you getting no search results?
A) You are using udp in the Value field, but you must use UDP.
B) The AND operator in the Next column is the wrong operator for this type of search.
C) The = operator in the Operator column is the wrong operator for this type of search.
D) You can perform raw event log searches using only an Event Keyword search.
3. When using user and entity behavior analytics (UEBA) on FortiSIEM, what must you use to dynamically supply a list of IP addresses to a FortiGate device for blocking purposes?
A) Lookup tables
B) API Connection
C) Watchlists
D) SCP
4. You need a model that predicts a target field based on other fields in a dataset and then triggers an anomaly if the value does not match the prediction. Which machine learning (ML) algorithm will you use to build this type of model?
A) Forecasting
B) Anomaly detection
C) Classification
D) Regression
5. Refer to the exhibit. What is this rule attempting to match?
A) Failed VPN logon events from a source outside the home country.
B) Failed VPN logon attempts from three or more different sources inside the home country.
C) Failed VPN logon attempts from three or more different outside countries.
D) Excessive VPN logon failures from a source inside the home country.
Solutions:
| Question # 1 Answer: C,D | Question # 2 Answer: C | Question # 3 Answer: C | Question # 4 Answer: D | Question # 5 Answer: A |

We're so confident of our products that we provide no hassle product exchange.


By Kay


