Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Fortinet FCP_FSM_AN-7.2 Practice Exam with Questions & Answers

Questions 1

When configuring anomaly detection machine learning, in which step must you select the fields to analyze?

Options:
A.

Design

B.

Schedule

C.

Prepare Data

D.

Train

Questions 2

What can you use to send data to FortiSIEM for user and entity behavior analytics (UEBA)?

Options:
A.

FortiSIEM agent

B.

SSH

C.

SNMP

D.

FortiSIEM worker

Questions 3

Refer to the exhibit.

FCP_FSM_AN-7.2 Question 3

A FortiSIEM device is receiving syslog events from a FortiGate firewall. The FortiSIEM analyst is trying to search the raw event logs for the last two hours that contain the keyword "udp". However, they are getting no results from the search, which they know should be available. Based on the filter shown in the exhibit, why are there no search results?

Options:
A.

The analyst selected AND in the Next column. This is the wrong Boolean operator.

B.

The Time Range value should be set to Real-Time.

C.

The keyword is case sensitive. Instead of typing udp in the Value field, the analyst should type UDP.

D.

The analyst selected = in the Operator column. That is the wrong operator.

Questions 4

Refer to the exhibit.

FCP_FSM_AN-7.2 Question 4

An analyst is troubleshooting the rule shown in the exhibit. It is not generating any incidents, but the filter parameters are generating events on the Analytics tab.

What is wrong with the rule conditions?

Options:
A.

The Event Type refers to a CMDB lookup and should be an Event lookup.

B.

The Destination Host Name value is not fully qualified.

C.

The Group By attributes restricts which events are counted.

D.

The Aggregate attribute is too restrictive.

Questions 5

Refer to the exhibit.

FCP_FSM_AN-7.2 Question 5

Which two lookup types can you reference as the subquery in a nested analytics query? (Choose two.)

Options:
A.

LDAP Query

B.

CMDB Query

C.

SNMP Query

D.

Event Query

Questions 6

Refer to the exhibit.

FCP_FSM_AN-7.2 Question 6

What will happen when a device being analyzed by the machine learning configuration shown in the exhibit has a consistently high memory utilization?

Options:
A.

FortiSIEM will update the regression tables for memory utilization, and average sent and received bytes.

B.

FortiSIEM will trigger an incident for high memory utilization.

C.

FortiSIEM will lower the CPU utilization trigger requirement for CPU utilization.

D.

FortiSIEM will update the model with a higher memory utilization average value.

Questions 7

Which items are used to define a subpattern?

Options:
A.

Filters, Aggregate, Group By definitions

B.

Filters, Aggregate, Time Window definitions

C.

Filters, Group By, Threshold definitions

D.

Filters, Threshold, Time Window definitions

Questions 8

Refer to the exhibit.

FCP_FSM_AN-7.2 Question 8

If you group the events by User and Count attributes, how many results will FortiSIEM display?

Options:
A.

Two

B.

Six

C.

Three

D.

Five

E.

One

Questions 9

Refer to the exhibit.

FCP_FSM_AN-7.2 Question 9

According to the automation policy configuration shown in the exhibit, what happens if an associated rule triggers?

Options:
A.

FortiSIEM runs the remediation script, because that takes precedence over all other options.

B.

FortiSIEM performs all selected actions.

C.

FortiSIEM fails to the integration policy, because no policy is defined.

D.

FortiSIEM sends an email, because that is first on the list.