Free NSE5_FSM-5.2 Exam Braindumps (page: 2)

Page 1 of 11

Refer to the exhibit.


A FortiSlEM administrator wants to group some attributes for a report, but is not able to do so successfully. As shown in the exhibit, why are some of the fields highlighted in red?

  1. The Event Receive Time attribute is not available for logs.
  2. The attribute COUNT(Matched event) is an invalid expression.
  3. Unique attributes cannot be grouped.
  4. No RAW Event Log attribute is available for devices.

Answer(s): C



In the rules engine, which condition instructs FortiSIEM to summarize and count the matching evaluated data?

  1. Time Window
  2. Aggregation
  3. Group By
  4. Filters

Answer(s): C



Refer to the exhibit.


How was the FortiGate device discovered by FortiSIEM?

  1. Through GUI log discovery
  2. Through syslog discovery
  3. Using the pull events method
  4. Through auto log discovery

Answer(s): A



Refer to the exhibit.


If events are grouped by Reporting IP, Event Type, and user attributes in FortiSIEM, how ,many results will be displayed?

  1. Seven results will be displayed.
  2. There results will be displayed.
  3. Unique attribute cannot be grouped.
  4. Five results will be displayed.

Answer(s): D






Post your Comments and Discuss Fortinet NSE5_FSM-5.2 exam with other Community members:

NSE5_FSM-5.2 Discussions & Posts