Join the discussion
Question 38/52
Refer to the exhibit. Which two lookup types can you reference as the subquery in a nested analytics query? (Choose two.)


Correct Answer: A,C
FortiSIEM nested analytics queries support CMDB queries and Event queries as subqueries.
These lookup types allow the main query to reference results returned from event data or CMDB- based datasets.
These lookup types allow the main query to reference results returned from event data or CMDB- based datasets.
Add Comments
- Other Question (52q)
- Q1. Refer to the exhibit. (Exhibit) You are attempting to tune an anomaly detection machine le...
- Q2. Which two elements can you use to define how an automation policy activates? (Choose two.)...
- Q3. Which two categories can you map to the MITRE ATT&CK coverage tables on FortiSIEM? (Ch...
- Q4. You want to reference the first source IP address from an incident in a playbook. Which op...
- Q5. A rule that detects network connections to an SSH server is triggering constantly in respo...
- Q6. Refer to the exhibit. (Exhibit) You are investigating an issue with two destination IP add...
- Q7. Refer to the exhibit. Which section contains settings that determine which attribute assoc...
- Q8. Which two types of information can FortiSIEM retrieve from FortiClient EMS through an exte...
- Q9. Which run mode takes the most time to perform machine learning tasks?...
- Q10. You want to build an event query that displays only events to higher number destination po...
- Q11. Refer to the exhibit. What does the Group: Windows value refer to? (Exhibit)...
- Q12. Refer to the exhibit. Which two items can be referenced in the incident details when this ...
- Q13. Refer to the exhibit. (Exhibit) Which statement about the nested query shown in the exhibi...
- Q14. What must match when referencing an inner query from an outer query?...
- Q15. Refer to the exhibit. (Exhibit) An analyst is trying to generate an incident with a title ...
- Q16. Refer to the exhibit. You want to use a machine learning (ML) model to train data with the...
- Q17. Refer to the exhibit. The configuration for a machine learning (ML) dataset using anomaly ...
- Q18. Which analytics search can be used to apply a user and entity behavior analytics (UEBA) ta...
- Q19. Which information can FortiSIEM retrieve from FortiClient EMS through an API connection?...
- Q20. From which two sources can you import data to train FortiSIEM machine learning? (Choose tw...
- Q21. What can you use to send data to FortiSIEM for user and entity behavior analytics (UEBA)?...
- Q22. Refer to the exhibit. (Exhibit) Which section contains the subpattern configuration that d...
- Q23. Refer to the exhibits. (Exhibit) You want the rule shown in the exhibit to trigger when th...
- Q24. Refer to the exhibit. (Exhibit) An incorrect configuration is shown. Which setting must yo...
- Q25. Rules on FortiSIEM are usually processed as events are collected (streaming). How can you ...
- Q26. Refer to the exhibit. What will FortiSIEM display if you apply the Group By and Display Fi...
- Q27. Refer to the exhibit. (Exhibit) If you apply this Group By and Display Fields configuratio...
- Q28. In an automation policy, which two methods can you use to notify analysts when an incident...
- Q29. Which two attributes can you not select together in the Group By and Display Fields? (Choo...
- Q30. An analyst wants to create a rule from a new analytic search they just performed. Which me...
- Q31. How can you query the configuration management database (CMDB) in an analytics search?...
- Q32. Refer to the exhibits. Which information will this analytics search display? (Exhibit)...
- Q33. What are the four incident status values on FortiSIEM?...
- Q34. Several new internal servers are generating incidents and must be excluded from several Fo...
- Q35. Refer to the exhibit. (Exhibit) Which statement about the time range settings defined in t...
- Q36. What are two required components of a rule? (Choose two.)...
- Q37. Refer to the exhibit. Which two things that happen when this automation policy triggers? (...
- Q38. Refer to the exhibit. Which two lookup types can you reference as the subquery in a nested...
- Q39. Refer to the exhibit. What will happen when a device being analyzed by the machine learnin...
- Q40. Refer to the exhibit. (Exhibit) If a rule containing the automation policy shown in the ex...
- Q41. Refer to the exhibit. (Exhibit) A FortiSIEM analyst is investigating an issue by examining...
- Q42. Which two ways are rule tags used on FortiSIEM? (Choose two.)...
- Q43. Where must you define and assign a custom python script as a remediation action?...
- Q44. Refer to the exhibit. (Exhibit) What will FortiSIEM display if you apply the Group By and ...
- Q45. How can you query the configuration management database (CMDB) in an analytics search?...
- Q46. Which two data areas can you use for user and entity behavior analytics (EBA) machine lear...
- Q47. What are four incident status options on FortiSIEM?...
- Q48. Refer to the exhibit. (Exhibit) What is this rule attempting to match? (Choose one answer)...
- Q49. Refer to the exhibit. Which value will the FortiSIEM parser use to populate the Applicatio...
- Q50. Refer to the exhibit. (Exhibit) A FortiSIEM analyst is investigating an issue by examining...
- Q51. Refer to the exhibit. (Exhibit) An analyst is troubleshooting the rule shown in the exhibi...
- Q52. Refer to the exhibit. (Exhibit) If you group the events by User , Source IP , and Count at...
[×]
Download PDF File
Enter your email address to download Fortinet.NSE6_FSM_AN-7.4.v2026-07-15.q52.pdf
