[2025年11月]更新のNSE5_FSM-6.3試験問題集合格させるのは2025年最新のFortinet NSE 5 - FortiSIEM 6.3
無料で使えるNSE5_FSM-6.3試験問題集で合格させるお手軽に試験合格
Fortinet NSE5_FSM-6.3(Fortinet NSE 5 - FortiSIEM 6.3)試験は、FortiSIEM 6.3を実装および管理するセキュリティプロフェッショナルの知識とスキルを検証するための認定試験です。この試験は、候補者にセキュリティイベントを監視および分析し、脅威を検出し、リアルタイムでセキュリティインシデントに対応するために必要な技術的な専門知識を提供することを目的としています。
質問 # 22
A FortiSIEM supervisor at headquarters is struggling to keep up with an increase of EPS (Events Per Second) being reported across the enterprise.
What components should an administrator consider deploying to assist the supervisor with processing data?
- A. Supervisor
- B. Worker
- C. Collector
- D. Agent
正解:B
質問 # 23
Refer to the exhibits.

Three events are collected over a 10-minute time period from two servers: Server A and Server B.
Based on thesettings tor the rule subpattern. how many incidents will the servers generate?
- A. Server A will generate one incident and Server B will not generate any incidents.
- B. Server B will generate one incident and Server A will not generate any incidents.
- C. Server A will generate one incident and Server B will generate one incident.
- D. Server A will not generate any incidents and Server B will not generate any incidents.
正解:A
解説:
Event Collection Overview: The exhibits show three events collected over a 10-minute period from two servers, Server A and Server B.
Rule Subpattern Settings: The rule subpattern specifies two conditions:
* AVG(CPU Util) > DeviceToCMDBAttr(Host IP : Server CPU Util Critical Threshold): This checks if the average CPU utilization exceeds the critical threshold defined for each server.
* COUNT(Matched Events) >= 2: This requires at least two matching events within the specified period.
Server A Analysis:
* Events: Three events (CPU=90, CPU=90, CPU=95).
* Average CPU Utilization: (90+90+95)/3 = 91.67, which exceeds the critical threshold of 90.
* Matched Events Count: 3, which meets the condition of being greater than or equal to 2.
* Incident Generation: Server A meets both conditions, so it generates one incident.
Server B Analysis:
* Events: Three events (CPU=70, CPU=50, CPU=60).
* Average CPU Utilization: (70+50+60)/3 = 60, which does not exceed the critical threshold of 90.
* Matched Events Count: 3, but since the average CPU utilization condition is not met, no incident is generated.
Conclusion: Based on the rule subpattern, Server A will generate one incident, and Server B will not generate any incidents.
References: FortiSIEM 6.3 User Guide, Event Correlation Rules and Incident Management sections, which explain how incidents are generated based on rule subpatterns and event conditions.
質問 # 24
When configuring collectors located in geographically separated sites, what ports must be open on a front end firewall?
- A. HTTPS, from the Internet to the collector and from the collector to the FortiSIEM cluster
- B. HTTPS, from the Internet to the collector
- C. HTTPS, from the collector to the supervisor and worker upload settings addresses
- D. HTTPS, from the collector to the worker upload settings address only
正解:C
解説:
FortiSIEM Architecture: In FortiSIEM, collectors gather data from various sources and send this data to supervisors and workers within the FortiSIEM architecture.
Communication Requirements: For collectors to effectively send data to the FortiSIEM system, specific communication channels must be open.
Port Usage: The primary port used for secure communication between the collectors and the FortiSIEM infrastructure is HTTPS (port 443).
Network Configuration: When configuring collectors in geographically separated sites, the HTTPS port must be open for the collectors to communicate with both the supervisor and the worker upload settings addresses. This ensures that the collected data can be securely transmitted to the appropriate processing and analysis components.
References: FortiSIEM 6.3 Administration Guide, Network Ports section details the necessary ports for communication within the FortiSIEM architecture.
質問 # 25
Which FortiSIEM components can do performance availability and performance monitoring?
- A. Collectors only
- B. Supervisor and workers only
- C. Supervisor, worker, and collector
- D. Supervisor only
正解:C
質問 # 26
What are the four possible incident status values?
- A. Active, cleared, cleared manually, system cleared
- B. Active, closed, manual, resolved
- C. Active, dosed, cleared, open
- D. Active, auto cleared, manual, false positive
正解:C
解説:
Incident Status Values: Incident statuses in FortiSIEM help administrators track and manage the lifecycle of incidents from detection to resolution.
Four Possible Status Values:
* Active: Indicates that the incident is currently ongoing and needs attention.
* Closed: Indicates that the incident has been resolved or addressed.
* Cleared: Indicates that the incident has been resolved automatically based on predefined conditions.
* Open: Indicates that the incident is acknowledged and under investigation but not yet resolved.
Usage: These statuses help in prioritizing and tracking incidents effectively, ensuring that all incidents are appropriately managed.
References: FortiSIEM 6.3 User Guide, Incident Management section, which details the different status values and their meanings.
質問 # 27
Which FortiSIEM feature must you use to produce a report on which FortiGate devices in your environment are running which firmware version?
- A. Run a CMDB report
- B. Run a baseline report.
- C. Run a query using the Inventory tab.
- D. Run an analytic search.
正解:C
解説:
* Feature Overview: FortiSIEM provides several tools for querying and reporting on device information within an environment.
* Inventory Tab: The Inventory tab is specifically designed to display detailed information about devices, including their firmware versions.
* Query Functionality: Within the Inventory tab, you can run queries to filter and display devices based on specific attributes, such as the firmware version for FortiGate devices.
* Report Generation: By running a query in the Inventory tab, you can produce a report that lists the FortiGate devices and their corresponding firmware versions.
* Reference: FortiSIEM 6.3 User Guide, Inventory Management section, explains how to use the Inventory tab to query and report on device attributes.
質問 # 28
Which three ports can be used to send Syslogs to FortiSIEM? (Choose three.)
- A. UDP 514
- B. UDP 162
- C. TCP 1470
- D. TCP 514
- E. UDP9999
正解:A、C、D
解説:
Syslog Ports: Syslog messages can be sent over different ports using TCP or UDP protocols.
Common Ports for Syslog:
* UDP 514: This is the default port for sending syslog messages over UDP.
* TCP 514: This is the default port for sending syslog messages over TCP, providing a more reliable transmission.
* TCP 1470: This port is often used for secure or alternative syslog transmission.
Usage in FortiSIEM: FortiSIEM can be configured to receive syslog messages on these ports to ensure the logs are collected from various network devices.
References: FortiSIEM 6.3 User Guide, Syslog Integration section, which details the supported ports for syslog transmission.
質問 # 29
When configuring collectors located in geographically separated sites, what ports must be open on a front end firewall?
- A. HTTPS, from the Internet to the collector and from the collector to the FortiSIEM cluster
- B. HTTPS,from the Internet to the collector
- C. HTTPS, from the collector to the supervisor and worker upload settings addresses
- D. HTTPS, from the collector to the worker upload settings address only
正解:C
解説:
FortiSIEM Architecture: In FortiSIEM, collectors gather data from various sources and send this data to supervisors and workers within the FortiSIEM architecture.
Communication Requirements: For collectors to effectively send data to the FortiSIEM system, specific communication channels must be open.
Port Usage: The primary port used for secure communication between the collectors and the FortiSIEM infrastructure is HTTPS (port 443).
Network Configuration: When configuring collectors in geographically separated sites, the HTTPS port must be open for the collectors to communicate with both the supervisor and the worker upload settings addresses.
This ensures that the collected data can be securely transmitted to the appropriate processing and analysis components.
References: FortiSIEM 6.3 Administration Guide, Network Ports section details the necessary ports for communication within the FortiSIEM architecture.
質問 # 30
Which statement about global thresholds and per device thresholds is true?
- A. FortiSIEM uses fixed hardcoded thresholds for all performance metrics.
- B. FortiSIEM uses global and per device thresholds tor all performance metrics.
- C. FortiSIEM uses global thresholds for all performance metrics.
- D. FortiSIEM uses global thresholds for all security metrics.
正解:B
解説:
Threshold Management: FortiSIEM uses thresholds to generate alerts and incidents based on performance and security metrics.
Global Thresholds: These are default thresholds applied to all devices and metrics across the system, providing a baseline for alerts.
Per Device Thresholds: These thresholds can be customized for individual devices, allowing for more granular control and tailored monitoring based on specific device characteristics and requirements.
Usage in Performance Metrics: Both global and per device thresholds are used for performance metrics to ensure comprehensive and precise monitoring.
References: FortiSIEM 6.3 User Guide, Thresholds and Alerts section, details the application of global and per device thresholds for performance and security metrics.
質問 # 31
Refer to the exhibit.
A FortiSIEM is continuously receiving syslog events from a FortiGate firewall The FortiSlfcM administrator is trying to search the raw event logs for the last two hours that contain the keyword tcp . However, the administrator is getting no results from the search.
Based on the selected filters shown in the exhibit, why are there no search results?
- A. The administrator selected AND in the Next drop-down list. This is the wrong boolean operator.
- B. In the Time section, the administrator selected the Relative Last option, and in the drop-down lists, selected 2 and Hours as the lime period The time period should be 24 hours.
- C. The administrator selected - in the Operator column That a the wrong operator.
- D. The keyword is case sensitive Instead of typing TCP in the Value field. the administrator should type tcp.
正解:D
解説:
Case Sensitivity in Searches: In FortiSIEM, search queries, including those for raw event logs, are case sensitive. This means that keywords must be entered exactly as they appear in the logs.
Keyword Mismatch: The exhibit shows the keyword "TCP" in the Value field. If the actual events use "tcp" (lowercase), the search will return no results because of the case mismatch.
Correct Keyword: To match the keyword correctly, the administrator should enter "tcp" in the Value field.
References: FortiSIEM 6.3 User Guide, Search and Filtering section, which discusses the importance of case sensitivity in search queries.
質問 # 32
An administrator is using SNMP credential only for discovery of a Windows device. How will FortiSIEM handle this?
- A. FortiSIEM will apply a job to collect application event logs.
- B. FortiSIEM will apply system monitor jobs to collect resources data.
- C. FortiSIEM will apply a job to collect system event logs.
- D. FortiSIEM will apply a Job to collect security event logs
正解:B
質問 # 33
In FortiSIEM enterprise licensing mode, it the link between the collector and data center FortiSlEM cluster is down, what happens?
- A. The collector buffers events
- B. The collector continues performance collection of devices, but slops receiving syslog.
- C. The collector processes stop, and events ate dropped.
- D. The collector drops incoming events like syslog. but stops performance collection.
正解:B
解説:
* Enterprise Licensing Mode: In FortiSIEM enterprise licensing mode, collectors are deployed in remote sites to gather and forward data to the central FortiSIEM cluster located in the data center.
* Collector Functionality: Collectors are responsible for receiving logs, events (e.g., syslog), and performance metrics from devices.
* Link Down Scenario: When the link between the collector and the FortiSIEM cluster is down, the collector needs a mechanism to ensure no data is lost during the disconnection.
* Event Buffering: The collector buffers the events locally until the connection is restored, ensuring that no incoming events are lost. This buffered data is then forwarded to the FortiSIEM cluster once the link is re-established.
* Reference: FortiSIEM 6.3 User Guide, Data Collection and Buffering section, explains the behavior of collectors during network disruptions.
質問 # 34
An administrator is trying to identify an issue using an expression bated on the Expression Builder settings shown in the exhibit however, the error message shown in the exhibit indicates that the expression is invalid.
Which is the correct expression?
- A. Matched Events(COUNT)
- B. COUNT(Matched Events)
- C. (COUNT) Matched Events
- D. Matched Events COUNT()
正解:B
質問 # 35
Refer to the exhibit.
Which section contains the sortings that determine how many incidents are created?
- A. Actions
- B. Aggregate
- C. Group By
- D. Filters
正解:C
解説:
Incident Creation in FortiSIEM: Incidents in FortiSIEM are created based on specific patterns and conditions defined within the system.
Group By Function: The "Group By" section in the "Edit SubPattern" window specifies how the data should be grouped for analysis and incident creation.
Impact of Grouping: The way data is grouped affects the number of incidents generated. Each unique combination of the grouped attributes results in a separate incident.
Exhibit Analysis: In the provided exhibit, the "Group By" section lists "Reporting Device," "Reporting IP," and "User." This means incidents will be created for each unique combination of these attributes.
References: FortiSIEM 6.3 User Guide, Rule and Pattern Creation section, which details how grouping impacts incident generation.
質問 # 36
What does the Frequency field determine on a rule?
- A. How often the rule will trigger.
- B. How often the rule will evaluate the subpattern.
- C. How often the rule will trigger for the same condition.
- D. How often the rule will take a clear action.
正解:C
解説:
Rule Evaluation in FortiSIEM: Rules in FortiSIEM are evaluated periodically to check if the defined conditions or subpatterns are met.
Frequency Field: The Frequency field in a rule determines the interval at which the rule's subpattern will be evaluated.
* Evaluation Interval: This defines how often the system will check the incoming events against the rule's subpattern to determine if an incident should be triggered.
* Impact on Performance: Setting an appropriate frequency is crucial to balance between timely detection of incidents and system performance.
Examples:
* If the Frequency is set to 5 minutes, the rule will evaluate the subpattern every 5 minutes.
* This means that every 5 minutes, the system will check if the conditions defined in the subpattern are met by the incoming events.
References: FortiSIEM 6.3 User Guide, Rules and Incidents section, which explains the Frequency field and how it impacts the evaluation of subpatterns in rules.
質問 # 37
Refer to the exhibit.
If events are grouped by User. Source IP. and Application Category attributes in FortiSiEM. how many results will be displayed?
- A. Seven results will be displayed.
- B. Three results will be displayed.
- C. No results will be displayed.
- D. Five results will be displayed.
正解:D
解説:
Grouping Events in FortiSIEM: Grouping events by specific attributes allows for the aggregation of similar events, providing clearer insights and reducing clutter.
Grouping Criteria: For this question, events are grouped by "User," "Source IP," and "Application Category." Unique Combinations Analysis:
* Ryan, 1.1.1.1, Web App(appears multiple times but is one unique combination)
* John, 5.5.5.5, DB
* Paul, 3.3.2.1, Web App
* Ryan, 1.1.1.15, DB
* Wendy, 1.1.1.6, DB
Result Calculation: There are five unique combinations in the provided data based on the specified grouping attributes.
References: FortiSIEM 6.3 User Guide, Event Management and Reporting sections, which explain how to group events by various attributes for analysis and reporting purposes.
質問 # 38
An administrator is in the process ofrenewing a FortiSIEM license. Which two commands will provide thesystem ID? (Choose two.)
- A. ./phLicenseTool-show
- B. ./phLicenseTool - support
- C. phgetUUID
- D. phgetHWID
正解:C、D
解説:
License Renewal Process: When renewing a FortiSIEM license, it is essential to provide the system ID, which uniquely identifies the FortiSIEM instance.
Commands to Retrieve System ID:
* phgetHWID: This command retrieves the hardware ID of the FortiSIEM appliance.
* Usage: Run the commandphgetHWIDin the CLI to obtain the hardware ID.
* phgetUUID: This command retrieves the universally unique identifier (UUID) for the FortiSIEM system.
* Usage: Run the commandphgetUUIDin the CLI to obtain the UUID.
Verification: BothphgetHWIDandphgetUUIDare valid commands for retrieving the necessary system IDs required for license renewal.
References: FortiSIEM 6.3 Administration Guide, Licensing section details the commands and procedures for obtaining system identification information necessary for license renewal.
質問 # 39
Where must you configure rule notifications and automated remediation on FortiSIEM?
- A. Notification engine
- B. Response policies
- C. Email and scripting alerts
- D. Notification policy
正解:B
質問 # 40
Refer to the exhibit.
The FortiSIEM administrator is examining events for two devices to investigate an issue. However, the administrator is not getting any results from their search.
Based on the selected filters shown in the exhibit, why is the search returning no results?
- A. An invalid IP subnet is typed in the Value column.
- B. The wrong boolean operator is selected in the Next column.
- C. Parenthesis are missing.
- D. The wrong option is selected in the Operator column.
正解:B
解説:
* Search Filters in FortiSIEM: When searching for events, the correct use of filters and logical operators is crucial to obtain accurate results.
* Issue Analysis:
Selected Filters: The exhibit shows filters for two different Reporting IP addresses.
Logical Operators: The use of "AND" between the two Reporting IP addresses implies that an event must match both IP addresses simultaneously, which is not possible for a single event.
* Correct Usage: To search for events from either of the two IP addresses, parentheses should be used to group conditions logically.
Corrected Filter: (Reporting IP = 192.168.1.1 OR Reporting IP = 172.16.10.3) would return events from either IP address.
* Reference: FortiSIEM 6.3 User Guide, Search and Filters section, which explains the use of logical operators and the importance of parentheses in constructing effective search queries.
質問 # 41
An administrator defines SMTP as a critical process on a Linux server.
It the SMTP process is stopped. FortiSIEM will generate a critical event with which event type?
- A. PH_DEV_MON_SMTP_STOP
- B. Postfix-Mail-Stop
- C. PH_DEV_MON_PROC_STOP
- D. Generic_SMTP_Procoss_Exit
正解:C
解説:
Process Monitoring in FortiSIEM: FortiSIEM can monitor critical processes on managed devices, such as an SMTP process on a Linux server.
Event Generation: When a critical process stops, FortiSIEM generates an event to alert administrators.
Event Types: Specific event types correspond to different monitored conditions. For a stopped process, the event typePH_DEV_MON_PROC_STOPis used.
Reasoning: The namePH_DEV_MON_PROC_STOP(Device Monitoring Process Stop) is a generic event type used by FortiSIEM to indicate that any monitored process, including SMTP, has stopped.
References: FortiSIEM 6.3 User Guide, Event Types section, explains the predefined event types and their usage in different monitoring scenarios.
質問 # 42
In the advanced analytical rules engine in FortiSIEM, multiple subpatterms can be referenced using which three operation?(Choose three.)
- A. FOLLOWED_BY
- B. AND
- C. NOT
- D. OR
- E. ELSE
正解:A、B、D
解説:
* Advanced Analytical Rules Engine: FortiSIEM's rules engine allows for complex event correlation using multiple subpatterns.
* Operations for Referencing Subpatterns:
FOLLOWED_BY: This operation is used to indicate that one event follows another within a specified time window.
OR: This logical operation allows for the inclusion of multiple subpatterns, where the rule triggers if any of the subpatterns match.
AND: This logical operation requires all referenced subpatterns to match for the rule to trigger.
* Usage: These operations allow for detailed and precise event correlation, helping to detect complex patterns and incidents.
* Reference: FortiSIEM 6.3 User Guide, Advanced Analytics Rules Engine section, which explains the use of different operations to reference subpatterns in rules.
質問 # 43
......
Fortinet NSE5_FSM-6.3(Fortinet NSE 5 - FortiSIEM 6.3)認定試験は、Fortinetから提供される高度なセキュリティ情報およびイベント管理(SIEM)ソリューションであるFortiSIEMを展開および管理するために必要な知識とスキルを検証するためのプロフェッショナルレベルの認定です。この認定試験は、SIEM展開および管理の専門知識を強化したいセキュリティプロフェッショナルや、複雑かつ動的な環境でFortiSIEMを管理する能力を証明したい人々を対象としています。
NSE5_FSM-6.3試験問題集、NSE5_FSM-6.3練習テスト問題:https://jp.fast2test.com/NSE5_FSM-6.3-premium-file.html