NSE5-FSM-6-3 Sample Questions & Answers
Device discovery, query building, and tuning data collection carry the most weight, built on FortiSIEM architecture and event-type classification, aggregating data for reporting analytics purposes, plus configuring rules and managing incidents.
Launch the full NSE5-FSM-6-3 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
SIEM Concepts · Troubleshoot system configuration and deployment related issues
An administrator at a retail company is deploying a new FortiSIEM Collector in a branch store. After deployment, the Collector appears online in the FortiSIEM GUI, but no events from the store's devices are appearing in the central analytics console. The administrator has verified that devices are successfully sending syslog messages to the Collector's IP address. Which of the following is the most likely cause of this issue?
Show answer & explanation
Correct answer: C
Collectors communicate their health status and parsed events to the Worker nodes via HTTPS (TCP/443). The Collector can appear online because initial registration with the Supervisor might have succeeded, but if the ongoing communication to the Workers is blocked, parsed events will not be uploaded. This is a common deployment issue in segmented networks.
- Question 2Intermediate
Rules and Incidents · Identify various rule components
A security team wants to create an incident that triggers when any user is added to a privileged group in Active Directory, such as 'Domain Admins'. However, they want to prevent an incident from being created if the change was performed by an approved administrator account (e.g., 'svc-ad-admin'). Which rule component should be used to achieve this?
Show answer & explanation
Correct answer: C
The Filters section of a rule defines the primary conditions for an event to be considered a match. To create an exception, you define the broad condition (user added to 'Domain Admins') and then add an exception to the filter (e.g., 'Reporting User' NOT EQUAL 'svc-ad-admin'). This ensures the rule only triggers for unauthorized changes.
- Question 3Beginner
Rules and Incidents · Identify various rule components
What is the primary purpose of the 'Define Condition' time field within a FortiSIEM rule?
Show answer & explanation
Correct answer: B
The 'Define Condition' time field sets the evaluation window for the rule. For example, a value of '5m' means the rule will look for matching events within a 5-minute sliding window. This is crucial for time-based correlations, such as detecting multiple failed logins within a short period.
- Question 4Beginner
FortiSIEM Operations · Deploy FortiSIEM agents
A systems administrator is tasked with deploying the FortiSIEM Windows Agent to 500 workstations across the enterprise. Which deployment method offers the most efficient and scalable solution for this task?
Show answer & explanation
Correct answer: C
For a large number of endpoints, manual installation is not feasible. Using enterprise software deployment tools like GPO or SCCM allows for silent, automated, and centralized installation of the agent MSI package across hundreds or thousands of machines, ensuring consistency and efficiency.
- Question 5AdvancedSelect 2
Rules and Incidents · Configure notification policies
An organization has configured a rule that generates a 'Malware Detected' incident. The security policy requires that when this incident is triggered, the infected endpoint's IP address is automatically added to a blocklist on the network's FortiGate firewall. Which two FortiSIEM components are primarily involved in this automated remediation process? (Select TWO)
Show answer & explanation
Correct answers: A, C
- Question 6Advanced
FortiSIEM Analytics · Apply group by and data aggregation on search results
A security analyst is building a query to investigate suspicious network traffic. The goal is to see the raw log for every event associated with a specific destination IP address. However, when the analyst includes both
Raw Event LoganddestIpAddrin the 'Display Fields' of an aggregated query, an error occurs. Why does this happen?Show answer & explanation
Correct answer: C
FortiSIEM's analytics engine treats
Raw Event Logas unstructured text. Aggregated queries require grouping and displaying structured, parsed attributes. BecauseRaw Event Logis not structured, it cannot be combined with parsed fields likedestIpAddrorsrcIpAddrin the 'Display Fields' of a query that uses 'Group By'. To see the raw log, one must run a non-aggregated search. - Question 7Beginner
SIEM Concepts · Identify FortiSIEM architecture components
A FortiSIEM administrator is reviewing the system architecture and notices three main component types: Supervisor, Worker, and Collector. What is the specific function of the Worker nodes in this architecture?
graph TD subgraph Central_Datacenter Supervisor[Supervisor] Worker1[Worker 1] Worker2[Worker 2] EventDB[(Event DB)] CMDB[(CMDB)] end subgraph Remote_Site_A Collector_A[Collector A] end subgraph Remote_Site_B Collector_B[Collector B] end Collector_A -->|Parsed Events| Worker1 Collector_B -->|Parsed Events| Worker2 Worker1 Supervisor Worker2 Supervisor Worker1 --> EventDB Worker2 --> EventDB Worker1 --> CMDB Worker2 --> CMDB Supervisor -->|Manages| Worker1 Supervisor -->|Manages| Worker2Show answer & explanation
Correct answer: C
The Worker nodes are the data processing engines of the FortiSIEM cluster. They receive parsed events from Collectors, run the real-time correlation rules, handle user-initiated queries for analytics and reporting, and are responsible for writing the final event data into the EventDB. The Supervisor manages and coordinates the Workers.
- Question 8Beginner
FortiSIEM Operations · Discover devices on FortiSIEM
A new FortiGate firewall has been deployed and is sending syslog messages to FortiSIEM. An administrator observes that the device was automatically discovered and added to the CMDB. Which discovery method was used in this scenario?
Show answer & explanation
Correct answer: B
FortiSIEM has the capability to discover devices automatically as it receives logs from them. When a log from an unknown IP address arrives, FortiSIEM parses it, identifies the device type from the log content, and creates a new entry in the CMDB. This is known as real-time or log-based auto-discovery.
- Question 9Intermediate
Rules and Incidents · Configure clear conditions for incidents
After creating a new incident rule, a FortiSIEM operator notices that some incidents are not being cleared automatically even though the threat has been resolved. The operator needs to configure the rule to automatically clear the incident after 24 hours if no new matching events are seen. Where is this configured?
Show answer & explanation
Correct answer: B
The logic for automatically clearing an incident is defined within the rule that creates it. The 'Clear Condition' section allows an administrator to specify conditions under which the incident should be considered resolved, such as when a specific clearing event is seen or, in this case, when no new triggering events have been detected for a defined period (e.g., 24 hours).
- Question 10Intermediate
FortiSIEM Analytics · Use various reporting functions available on FortiSIEM
A hospital is preparing for a compliance audit. The auditor has requested a detailed report of all user accounts that were created, modified, or deleted across all Windows servers in the last 90 days. The FortiSIEM administrator needs to provide this report. Which of the following describes the most direct way to generate this information?
Show answer & explanation
Correct answer: B
FortiSIEM includes many out-of-the-box report templates designed for common security and compliance use cases. For Windows user account changes, there are predefined reports that already contain the necessary filters for the relevant event IDs. The administrator simply needs to select the appropriate template, specify the target devices and the 90-day time range, and run it.
Ready for the real thing?
The full NSE5-FSM-6-3 simulator has every exam-style question, timed mode, and instant scoring.