Join the discussion
Question 47/52
What are four incident status options on FortiSIEM?
Correct Answer: D
FortiSIEM incidents can use status values that track the incident lifecycle, including active investigation, closure, clearing, and resolution. These statuses help analysts manage whether an incident is still open, has been cleared by conditions, has been closed, or has been resolved.
Add Comments
- Other Question (52q)
- Q1. Refer to the exhibit. (Exhibit) You are attempting to tune an anomaly detection machine le...
- Q2. Which two elements can you use to define how an automation policy activates? (Choose two.)...
- Q3. Which two categories can you map to the MITRE ATT&CK coverage tables on FortiSIEM? (Ch...
- Q4. You want to reference the first source IP address from an incident in a playbook. Which op...
- Q5. A rule that detects network connections to an SSH server is triggering constantly in respo...
- Q6. Refer to the exhibit. (Exhibit) You are investigating an issue with two destination IP add...
- Q7. Refer to the exhibit. Which section contains settings that determine which attribute assoc...
- Q8. Which two types of information can FortiSIEM retrieve from FortiClient EMS through an exte...
- Q9. Which run mode takes the most time to perform machine learning tasks?...
- Q10. You want to build an event query that displays only events to higher number destination po...
- Q11. Refer to the exhibit. What does the Group: Windows value refer to? (Exhibit)...
- Q12. Refer to the exhibit. Which two items can be referenced in the incident details when this ...
- Q13. Refer to the exhibit. (Exhibit) Which statement about the nested query shown in the exhibi...
- Q14. What must match when referencing an inner query from an outer query?...
- Q15. Refer to the exhibit. (Exhibit) An analyst is trying to generate an incident with a title ...
- Q16. Refer to the exhibit. You want to use a machine learning (ML) model to train data with the...
- Q17. Refer to the exhibit. The configuration for a machine learning (ML) dataset using anomaly ...
- Q18. Which analytics search can be used to apply a user and entity behavior analytics (UEBA) ta...
- Q19. Which information can FortiSIEM retrieve from FortiClient EMS through an API connection?...
- Q20. From which two sources can you import data to train FortiSIEM machine learning? (Choose tw...
- Q21. What can you use to send data to FortiSIEM for user and entity behavior analytics (UEBA)?...
- Q22. Refer to the exhibit. (Exhibit) Which section contains the subpattern configuration that d...
- Q23. Refer to the exhibits. (Exhibit) You want the rule shown in the exhibit to trigger when th...
- Q24. Refer to the exhibit. (Exhibit) An incorrect configuration is shown. Which setting must yo...
- Q25. Rules on FortiSIEM are usually processed as events are collected (streaming). How can you ...
- Q26. Refer to the exhibit. What will FortiSIEM display if you apply the Group By and Display Fi...
- Q27. Refer to the exhibit. (Exhibit) If you apply this Group By and Display Fields configuratio...
- Q28. In an automation policy, which two methods can you use to notify analysts when an incident...
- Q29. Which two attributes can you not select together in the Group By and Display Fields? (Choo...
- Q30. An analyst wants to create a rule from a new analytic search they just performed. Which me...
- Q31. How can you query the configuration management database (CMDB) in an analytics search?...
- Q32. Refer to the exhibits. Which information will this analytics search display? (Exhibit)...
- Q33. What are the four incident status values on FortiSIEM?...
- Q34. Several new internal servers are generating incidents and must be excluded from several Fo...
- Q35. Refer to the exhibit. (Exhibit) Which statement about the time range settings defined in t...
- Q36. What are two required components of a rule? (Choose two.)...
- Q37. Refer to the exhibit. Which two things that happen when this automation policy triggers? (...
- Q38. Refer to the exhibit. Which two lookup types can you reference as the subquery in a nested...
- Q39. Refer to the exhibit. What will happen when a device being analyzed by the machine learnin...
- Q40. Refer to the exhibit. (Exhibit) If a rule containing the automation policy shown in the ex...
- Q41. Refer to the exhibit. (Exhibit) A FortiSIEM analyst is investigating an issue by examining...
- Q42. Which two ways are rule tags used on FortiSIEM? (Choose two.)...
- Q43. Where must you define and assign a custom python script as a remediation action?...
- Q44. Refer to the exhibit. (Exhibit) What will FortiSIEM display if you apply the Group By and ...
- Q45. How can you query the configuration management database (CMDB) in an analytics search?...
- Q46. Which two data areas can you use for user and entity behavior analytics (EBA) machine lear...
- Q47. What are four incident status options on FortiSIEM?...
- Q48. Refer to the exhibit. (Exhibit) What is this rule attempting to match? (Choose one answer)...
- Q49. Refer to the exhibit. Which value will the FortiSIEM parser use to populate the Applicatio...
- Q50. Refer to the exhibit. (Exhibit) A FortiSIEM analyst is investigating an issue by examining...
- Q51. Refer to the exhibit. (Exhibit) An analyst is troubleshooting the rule shown in the exhibi...
- Q52. Refer to the exhibit. (Exhibit) If you group the events by User , Source IP , and Count at...
[×]
Download PDF File
Enter your email address to download Fortinet.NSE6_FSM_AN-7.4.v2026-07-15.q52.pdf
