Skip to content

NSE5-FSM-6-3 Fortinet NSE 5 - FortiSIEM 6.3 Practice Questions

Prepare for NSE5-FSM-6-3 with more than an answer.

219 questions in the full set20 sample questionsUpdated Dec 7, 2025
Exam fee
$200 USD
Level
Professional
Valid for
2 years
Domains covered on the exam 4
  1. SIEM Concepts25%
  2. FortiSIEM Operations35%
  3. FortiSIEM Analytics20%
  4. Rules and Incidents20%
  1. 1

    True or False: The FortiSIEM Supervisor node is responsible for receiving parsed events directly from Collectors and performing real-time correlation.

    Show answer details

    Correct answer: B

    This statement is false. The Worker nodes are responsible for receiving parsed events from Collectors and performing real-time correlation. The Supervisor node's primary role is to manage the cluster, provide the user interface, and coordinate the tasks performed by the Worker nodes. It does not handle the high-volume event stream directly.

  2. 2

    An administrator is attempting to discover a custom Linux application server using SNMP. The discovery process fails repeatedly. The administrator has verified that there is network connectivity between the FortiSIEM Collector and the server on UDP port 161, and the SNMP community string is correct. What is a common reason for SNMP discovery to fail in this scenario?

    Show answer details

    Correct answer: A

    A common security practice for SNMP daemons on Linux systems is to restrict access to a specific list of IP addresses or subnets. Even with the correct community string and network connectivity, if the Collector's IP is not explicitly allowed in the snmpd.conf file, the daemon will ignore the discovery requests.

  3. 3

    A new administrator is tasked with backing up the FortiSIEM configuration. Which database contains the system configuration, rules, reports, and CMDB information?

    Show answer details

    Correct answer: C

    The PostgreSQL database on the Supervisor node is the central repository for all FortiSIEM configuration data. This includes rules, reports, users, system settings, and the entire CMDB. Backing up this database is critical for disaster recovery of the system's configuration.

  4. 4

    A SOC manager wants to create a dashboard widget that displays the top 10 users by the volume of outbound traffic over the last 24 hours. Which FortiSIEM analytics feature should be used as the data source for this widget?

    Show answer details

    Correct answer: B

    Dashboard widgets are powered by underlying queries. To display specific, summarized data like 'top 10 users by traffic', the administrator must first create a historical search query that filters for outbound traffic, groups the results by username, aggregates by the sum of bytes sent, and sorts in descending order. This saved query can then be selected as the data source for the dashboard widget.

  5. 5

    What is the function of the 'Group By' section in a FortiSIEM correlation rule?

    Show answer details

    Correct answer: D

    The 'Group By' clause is fundamental to how incidents are triggered. It specifies the key attributes for correlation. For example, if a rule groups by 'srcIpAddr', all matching events from the same source IP are treated as a single instance. If a new event arrives with the same source IP, it updates the existing incident; if it has a different source IP, a new incident is created.

  6. 6

    A Managed Security Service Provider (MSSP) is designing a new FortiSIEM deployment for a large enterprise client. The client has three major data centers across different continents and an estimated event rate of 50,000 EPS. The key requirements are centralized management, high availability for the analytics and reporting engine, and local event collection and parsing at each data center to minimize WAN traffic. Which architectural design best meets these requirements?

    Show answer details

    Correct answer: B

    This is the standard and most effective architecture for a large, geographically distributed environment. The Supervisor/Worker cluster at the central location provides high availability for analytics, correlation, and reporting. Deploying Collectors at the client sites ensures that events are collected and parsed locally, significantly reducing the amount of raw log data sent over the WAN, as only parsed, compressed events are forwarded.

  7. 7

    A security analyst needs to create a correlation rule to detect a potential brute-force attack followed by a successful login. The logic must identify at least 10 failed login events for the same user from the same source IP within a 5-minute window, which are then immediately followed by a successful login for that same user and source IP. How must the rule be constructed in FortiSIEM to achieve this specific sequence of events?

    flowchart TD A[Start: Event Received] --> B{Login Failed?}; B -- Yes --> C[Increment Counter for User/IP]; B -- No --> D{Login Successful?}; D -- No --> E[Ignore]; C --> F{Counter >= 10 in 5min?}; F -- Yes --> D; F -- No --> E; D -- Yes --> G{Same User/IP as failed attempts?}; G -- Yes --> H[Trigger Incident]; G -- No --> E; H --> I[End];

    Show answer details

    Correct answer: B

    This scenario requires detecting a specific sequence of different event types. This is achieved using ordered sub-patterns. The first sub-pattern identifies the aggregated failed logins, and the second identifies the subsequent successful login. The 'Group By' clause is critical to ensure that both sub-patterns are correlated based on the same user and source IP address.

  8. 8

    A FortiSIEM administrator is investigating a performance issue where the Supervisor node's CPU utilization is consistently high. After initial investigation, the cause is determined to be an excessive number of low-value syslog events coming from a newly added group of IoT devices. The security team has confirmed these specific events are not needed for analysis. What is the most efficient method within FortiSIEM to reduce the processing load on the Supervisor without losing visibility into other critical events from the same IoT devices?

    Show answer details

    Correct answer: C

    The most efficient way to reduce the load on the Supervisor is to prevent the unwanted events from ever being sent to it. By creating an event dropping filter on the Collector, the noisy events are discarded at the source, saving bandwidth and reducing the parsing and processing load on the entire FortiSIEM cluster. This is the recommended best practice for tuning data collection.

  9. 9

    True or False: In a multi-tenant FortiSIEM deployment, administrators from one organization can view and manage incidents belonging to another organization if they are granted Super/Global administrator privileges.

    Show answer details

    Correct answer: B

    FortiSIEM enforces strict data segregation between organizations (tenants). Even a Super/Global administrator cannot view the specific incident or event data of another organization. They can manage system-level settings and organizations, but the data within each tenant is kept isolated to users assigned to that specific organization.

  10. 10

    A financial institution is using FortiSIEM to monitor access to its critical database servers. A compliance requirement mandates a monthly report that shows a summary of distinct users who accessed each database server, along with the total number of connections per user. Which components of the FortiSIEM Analytics tab are required to create this specific report? (Select TWO)

    Show answer details

    Correct answer: A, C

Create an account to continue.