Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

NSE5_FSM-6.3 Fortinet NSE 5 - FortiSIEM 6.3 Questions and Answers

Questions 4

Which FortiSIEM components are capable of performing device discovery?

Options:

A.

FortiSIEM Windows agent

B.

Worker

C.

FortiSIEM Linux agent

D.

Collector

Buy Now
Questions 5

FortiSIEM is deployed in disaster recovery mode.

When disaster strikes, which two tasks must you perform manually to achieve a successful disaster recovery operation? (Choose two.)

Options:

A.

Promote the secondary workers to the primary roles using the phSecworker2priworker command.

B.

Promote the secondary supervisor to the primary role using the phSecondary2primary command.

C.

Change the DNS configuration to ensure that users, devices, and collectors log in to the secondary FortiSIEM.

D.

Change the configuration for shared storage NFS configured for EventDB to the secondary FortiSIEM.

Buy Now
Questions 6

Which FortiSIEM feature must you use to produce a report on which FortiGate devices in your environment are running which firmware version?

Options:

A.

Run an analytic search.

B.

Run a query using the Inventory tab.

C.

Run a baseline report.

D.

Run a CMDB report

Buy Now
Questions 7

Refer to the exhibit.

NSE5_FSM-6.3 Question 7

It events are grouped by Event Type and User attributes in FortiSIEM. how many results will be displayed?

Options:

A.

Four results will be displayed.

B.

Eight results will be displayed.

C.

Two results will be displayed.

D.

No results will be displayed.

Buy Now
Questions 8

Which protocol do collectors use to communicate with a FortiSIEM cluster?

Options:

A.

Syslog

B.

SNMP

C.

HTTPS

D.

SMTP

Buy Now
Questions 9

Which two FortiSIEM components work together to provide real-time event correlation?

Options:

A.

Supervisor and worker

B.

Collector and Windows agent

C.

Worker and collector

D.

Supervisor and collector

Buy Now
Questions 10

Refer to the exhibits.

NSE5_FSM-6.3 Question 10

NSE5_FSM-6.3 Question 10

Three events are collected over a 10-minute time period from two servers: Server A and Server B.

Based on the settings tor the rule subpattern. how many incidents will the servers generate?

Options:

A.

Server A will generate one incident and Server B will generate one incident.

B.

Server A will generate one incident and Server B will not generate any incidents.

C.

Server B will generate one incident and Server A will not generate any incidents.

D.

Server A will not generate any incidents and Server B will not generate any incidents.

Buy Now
Questions 11

Consider the storage of anomaly baseline date that is calculated for different parameters. Which database is used for storing this data?

Options:

A.

Event DB

B.

Profile DB

C.

SVNDB

D.

CMDB

Buy Now
Questions 12

Refer to the exhibit.

NSE5_FSM-6.3 Question 12

What do the yellow stars listed in the Monitor column indicate?

Options:

A.

A yellow star indicates that a metric was applied during discovery, and data has been collected successfully

B.

A yellow star indicates that a metric was applied during discovery, but data collection has not started

C.

A yellow star indicates that a metric was applied during discovery, but FortiSIEM is unable to collect data.

D.

A yellow star indicates that a metric was not applied during discovery and, therefore, FortiSEIM was unable to collect data.

Buy Now
Questions 13

An administrator wants to search for events received from Linux and Windows agents.

Which attribute should the administrator use in search filters, to view events received from agents only.

Options:

A.

External Event Receive Protocol

B.

Event Received Proto Agents

C.

External Event Receive Raw Logs

D.

External Event Receive Agents

Buy Now
Questions 14

Refer to the exhibit.

NSE5_FSM-6.3 Question 14

If events are grouped by User. Source IP. and Application Category attributes in FortiSiEM. how many results will be displayed?

Options:

A.

Three results will be displayed.

B.

Five results will be displayed.

C.

No results will be displayed.

D.

Seven results will be displayed.

Buy Now
Questions 15

Where do you configure rule notifications and automated remediation on FortiSIEM?

Options:

A.

Notification policy

B.

Remediation policy

C.

Notification engine

D.

Remediation engine

Buy Now
Questions 16

An administrator is in the process of renewing a FortiSIEM license. Which two commands will provide the system ID? (Choose two.)

Options:

A.

phgetHWID

B.

./phLicenseTool - support

C.

phgetUUID

D.

./phLicenseTool-show

Buy Now
Questions 17

A customer is experiencing slow performance while executing long, adhoc analytic searches. Which FortiSIEM component can make the searches run faster?

Options:

A.

Correlation worker

B.

Event worker

C.

Storage worker

D.

Query worker

Buy Now
Questions 18

In which state can a device be moved into the CMDB to prevent monitoring log collection?

Options:

A.

Unmanaged

B.

Unapproved

C.

Pending

D.

Void

Buy Now
Questions 19

In FortiSIEM enterprise licensing mode, it the link between the collector and data center FortiSlEM cluster is down, what happens?

Options:

A.

The collector drops incoming events like syslog. but stops performance collection.

B.

The collector processes stop, and events ate dropped.

C.

The collector continues performance collection of devices, but slops receiving syslog.

D.

The collector buffers events

Buy Now
Exam Code: NSE5_FSM-6.3
Exam Name: Fortinet NSE 5 - FortiSIEM 6.3
Last Update: Apr 30, 2026
Questions: 64

PDF + Testing Engine

$63.52  $181.49

Testing Engine

$50.57  $144.49
buy now NSE5_FSM-6.3 testing engine

PDF (Q&A)

$43.57  $124.49
buy now NSE5_FSM-6.3 pdf