Fortinet FCP_FSM_AN-7.2 - FCP - FortiSIEM 7.2 Analyst Exam

Question #11 (Topic: Exam A)
Refer to the exhibit.

What happens when an analyst clears an incident generated by a rule containing the automation policy shown in the exhibit?
A. No notification is sent. B. An email is sent to the SOC manager. C. The remediation script is run. D. A notification is sent to the SOC manager dashboard.
Answer: B
Question #12 (Topic: Exam A)
Refer to the exhibit.

Which value would you expect the FortiSIEM parser to use to populate the Application Name field?
A. applist B. Network.Service C. SSL D. wan1
Answer: C
Question #13 (Topic: Exam A)
Refer to the exhibit.

An analyst is troubleshooting the rule shown in the exhibit. It is not generating any incidents, but the filter parameters are generating events on the Analytics tab.
What is wrong with the rule conditions?
A. The Event Type refers to a CMDB lookup and should be an Event lookup. B. The Destination Host Name value is not fully qualified. C. The Group By attributes restricts which events are counted. D. The Aggregate attribute is too restrictive.
Answer: C
Question #14 (Topic: Exam A)
Refer to the exhibit.

What is the Group: FortiSIEM Analysts value referring to?
A. FortiSIEM organization group B. LDAP user group C. CMDB user group D. Windows Active Directory user group
Answer: C
Question #15 (Topic: Exam A)
Refer to the exhibit.

Which section contains the subpattern configuration that determines how many matching events are needed to trigger the rule?
A. Aggregate B. Group By C. Actions D. Filters
Answer: A
Download Exam
Page: 3 / 11
Total 51 questions