Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Fortinet NSE5_FSM-6.3 Practice Exam with Questions & Answers

Questions 1

What does the Frequency field determine on a rule?

Options:
A.

How often the rule will evaluate the subpattern.

B.

How often the rule will trigger for the same condition.

C.

How often the rule will trigger.

D.

How often the rule will take a clear action.

Fortinet NSE5_FSM-6.3 Premium Access
Questions 2

What are the four possible incident status values?

Options:
A.

Active, dosed, cleared, open

B.

Active, cleared, cleared manually, system cleared

C.

Active, closed, manual, resolved

D.

Active, auto cleared, manual, false positive

Questions 3

Which two FortiSIEM components work together to provide real-time event correlation?

Options:
A.

Supervisor and worker

B.

Collector and Windows agent

C.

Worker and collector

D.

Supervisor and collector

Questions 4

Which discovery scan type is prone to miss a device, if the device is quiet and the entry foe that device is not present in the ARP table of adjacent devices?

Options:
A.

CMDB scan

B.

L2 scan

C.

Range scan

D.

Smart scan

Questions 5

An administrator defines SMTP as a critical process on a Linux server.

It the SMTP process is stopped. FortiSIEM will generate a critical event with which event type?

Options:
A.

Postfix-Mail-Stop

B.

PH_DEV_MON_PROC_STOP

C.

PH_DEV_MON_SMTP_STOP

D.

Generic_SMTP_Procoss_Exit

Questions 6

In FortiSIEM enterprise licensing mode, it the link between the collector and data center FortiSlEM cluster is down, what happens?

Options:
A.

The collector drops incoming events like syslog. but stops performance collection.

B.

The collector processes stop, and events ate dropped.

C.

The collector continues performance collection of devices, but slops receiving syslog.

D.

The collector buffers events

Questions 7

In me FortiSIEM CLI. which command must you use to determine whether or not syslog is being received from a network device?

Options:
A.

tcpdump

B.

OphSyslogRecorder

C.

Onetcat

D.

phDeviceTest

Questions 8

Refer to the exhibit.

NSE5_FSM-6.3 Question 8

What do the yellow stars listed in the Monitor column indicate?

Options:
A.

A yellow star indicates that a metric was applied during discovery, and data has been collected successfully

B.

A yellow star indicates that a metric was applied during discovery, but data collection has not started

C.

A yellow star indicates that a metric was applied during discovery, but FortiSIEM is unable to collect data.

D.

A yellow star indicates that a metric was not applied during discovery and, therefore, FortiSEIM was unable to collect data.

Questions 9

When configuring collectors located in geographically separated sites, what ports must be open on a front end firewall?

Options:
A.

HTTPS, from the collector to the worker upload settings address only

B.

HTTPS, from the collector to the supervisor and worker upload settings addresses

C.

HTTPS, from the Internet to the collector

D.

HTTPS, from the Internet to the collector and from the collector to the FortiSIEM cluster

Questions 10

FortiSIEM is deployed in disaster recovery mode.

When disaster strikes, which two tasks must you perform manually to achieve a successful disaster recovery operation? (Choose two.)

Options:
A.

Promote the secondary workers to the primary rotes using the phSecworker2priworker command.

B.

Promote the secondary supervisor to the primary role using the phSecondary2primary command.

C.

Change the DNS configuration to ensure that users, devices, and collectors log in to the secondary FortiSIEM.

D.

Change the configuration for shared storage NFS configured for EventDB to the secondary FortiSIEM.

Exam Code: NSE5_FSM-6.3
Certification Provider: Fortinet
Exam Name: Fortinet NSE 5 - FortiSIEM 6.3
Last Update: Jul 9, 2025
Questions: 64
PDF + Testing Engine
$164.99
$66
Testing Engine
$124.99
$50
PDF (Q&A)
$104.99
$42