10 free sample questions from a bank of 49, with the correct answers and explanations. No signup required — start practising right now.
1Which two data areas can you use for user and entity behavior analytics (UEBA) machine learning models? (Choose two.)
location
resources
process
network
Answer: A, D
The short version
A and D — UEBA models learn from location and network behavior. Where plus how-connected.
Key concepts in this question
Location tracks impossible-travel and unusual-place logins.
Network captures connection patterns per entity.
Why A and D are correct
Location (A) plus network (D) are the documented UEBA ML data areas.
Why the others are wrong
B. Resources are inventory, not behavior signals.
C. Processes are EDR telemetry, not UEBA model areas.
FortiSIEM exam tip
UEBA learns where + how-connected.
2When configuring machine learning (ML), in which step can you modify how the model fits the training data set?
Prepare Data
Train
Statistics
Design
Answer: C
The short version
C — model fit is tuned in the Statistics step. Distributions and fit review live there.
Key concepts in this question
Statistics shows how the model fits training data for adjustment.
Prepare/Train/Design handle data, execution, and structure.
Why C is correct
Fit-tuning is the documented Statistics-step activity.
Why the others are wrong
A. Prepare Data cleans; it does not tune fit.
B. Train executes; fit review follows.
D. Design structures; it does not adjust fit.
FortiSIEM exam tip
Fit the model = Statistics step.
3Refer to the exhibits.You want the rule shown in the exhibit to trigger when three failed login attempts occur within 3 minutes.Which condition time window and aggregate values are correct for your objective?
Time window 180 seconds, aggregate value 3
Time window 180 seconds, aggregate value 2
Time window 540 seconds, aggregate value 3
Time window 60 seconds, aggregate value 3
Answer: B
The short version
The banked answer B is kept because the reconstructed rule exhibit uses a 180 second window with aggregate value 2 to fire on three failed logins in 3 minutes, so exhibit missing is resolved by reconstruction.
Key concepts in this question
This question tests FortiSIEM rule aggregation and time window semantics and how aggregate count relates to the number of matching events.
Why B is correct
The reconstructed exhibit shows an aggregate rule where the count threshold is expressed as aggregate value plus one, so a 180 second window with aggregate value 2 fires when three failed logins arrive within 3 minutes, which makes B consistent with the stem options and banked answer.
Why the others are wrong
Aggregate value 3 in 180 seconds would need four events, 540 seconds is nine minutes rather than three minutes, and 60 seconds is only one minute, so A and C and D do not meet the three in three minutes objective.
NSE6_FSM_AN-7.4 exam tip
Remember that FortiSIEM aggregate value is zero based in this pattern and map event count to aggregate plus one before choosing the window.
4Which information can FortiSIEM retrieve from FortiClient EMS through an API connection?
Host software versions
FortiSIEM license
Host login credentials
ZTNA tags
Answer: D
The short version
D — FortiSIEM pulls ZTNA tags from EMS over the API. Posture tags flow to analytics.
Key concepts in this question
ZTNA tags originate on EMS-managed endpoints.
The API connection carries them into FortiSIEM.
Why D is correct
ZTNA-tag retrieval is the documented EMS API data.
Why the others are wrong
A. Software versions come from inventory sync, not this API fact.
B. Licensing never transfers over the EMS API.
C. Credentials are never exposed via API.
FortiSIEM exam tip
EMS API to SIEM = ZTNA tags.
5From which two sources can you import data to train FortiSIEM machine learning? (Choose two.)
Syslog archives
SQL database
CSV files
FortiSIEM reports
Answer: C, D
The short version
C and D — ML training imports from CSV files and FortiSIEM reports. Flat files plus analytic output.
Key concepts in this question
CSV import feeds labeled external datasets.
Reports recycle analytic results as training input.
Why C and D are correct
The two documented ML-training import sources.
Why the others are wrong
A. Syslog archives stream events; they are not training imports.
B. SQL databases are queried live, not imported for training.
FortiSIEM exam tip
ML training in = CSV + reports.
6Refer to the exhibit.An analyst wants the rule shown in the exhibit to trigger when three failed login attempts occur within three minutes.What should the values be for the condition time window and aggregate count?
Time window 180 seconds, aggregate count 3
Time window 180 seconds, aggregate count 2
Time window 90 seconds, aggregate count 3
Time window 90 seconds, aggregate count 2
Answer: A
The short version
A — approved. Three minutes equals 180 seconds and three events need an aggregate count of 3.
Key concepts in this question
Time window: FortiSIEM subpattern windows are in seconds, so 3 minutes is 180 seconds.
Aggregate condition: COUNT(Matched Events) threshold fires when that many matching events aggregate.
Failed-login rule: threshold count equals the number of occurrences to detect.
Why A is correct
FortiSIEM rule docs define aggregate conditions such as COUNT(Matched Events) >= N, so 3 logins in 3 minutes is a 180-second window with aggregate value 3.
Why the others are wrong
B. 180 seconds is right but aggregate 2 detects two events, not three.
C. 90 seconds is only 1.5 minutes, too short for a 3-minute objective.
D. 90 seconds is too short and aggregate 2 is too low for three attempts.
NSE6_FSM_AN-7.4 exam tip
3 events in 3 minutes = 180 seconds + COUNT 3.
7Refer to the exhibit. If a user account is locked after five failed login attempts, how many times will this rule be triggered if three individual users all fail their login 10 times?
Five
One
Fifteen
Three
Answer: D
The short version
The banked answer D is kept because the reconstructed Group-By exhibit groups by user so three users failing ten times each produces three rule triggers, so exhibit missing is resolved by reconstruction.
Key concepts in this question
This question tests FortiSIEM Group-By behavior and per group trigger counting when one rule watches failed logins across multiple users.
Why D is correct
The reconstructed exhibit shows the rule grouped by user account with a five failure threshold, so each of the three users independently crosses the threshold once and the rule fires three times total, which makes D consistent with the stem options and banked answer.
Why the others are wrong
Five would confuse attempts with triggers, one would ignore Group-By, and fifteen would count every failure as a trigger, so A and B and C are inconsistent with the reconstructed grouped rule.
NSE6_FSM_AN-7.4 exam tip
Remember that Group-By creates one trigger per group and count users rather than total events for grouped login rules.
8When FortiSIEM is configured to apply ZTNA tags, what is the order of events when an analyst wants to automatically block a ZTNA tagged host?
FortiEMS tags host > FortiSIEM receives tag information > FortiSIEM tags host > ZTNA tags enforced on FortiGate
FortiEMS tags host > FortiEMS receives tag information > FortiSIEM tags host > ZTNA tags enforced on FortiGate
FortiSIEM tags host > FortiEMS receives tag information > FortiEMS tags host > ZTNA tags enforced on FortiGate
FortiEMS receives tag information > FortiEMS tags host > FortiSIEM tags host > ZTNA tags enforced on FortiGate
Answer: A
The short version
A — EMS tags, SIEM ingests, SIEM tags, FortiGate enforces. The four-hop ZTNA blocking chain.
Key concepts in this question
FortiEMS originates host tags.
FortiSIEM receives, applies, and pushes enforcement to FortiGate.
Why A is correct
Tag-origin through enforcement in exact order.
Why the others are wrong
B. EMS never receives its own tags back mid-chain.
C. SIEM cannot originate endpoint tags.
D. Receiving precedes tagging on EMS, reversing the true order.
9A rule that detects network connections to an SSH server is triggering constantly in response to background internet traffic and must be tuned. Which method is used to tune this rule and solve the issue?
Update the Group By attribute to include only allowed host IP addresses.
Increase the COUNT (Matched Events)value in the subpattern.
Block connections from unauthorized networks before they reach the server.
Increase the time window on the FortiSIEM rule.
Answer: B
The short version
B — noisy SSH rules calm down by raising the subpattern COUNT. Fewer incidents, same visibility.
Key concepts in this question
COUNT (Matched Events) thresholds how many hits fire the rule.
Background internet noise needs volume-tolerance, not rewiring.
Why B is correct
Raising the match count is the documented noisy-rule tuning method.
Why the others are wrong
A. Group-By host scoping hides the broader pattern.
C. Upstream blocking is firewall work, not rule tuning.
D. Wider windows admit more noise, not less.
FortiSIEM exam tip
Noisy rule = raise the COUNT.
10Refer to the exhibit.A FortiSIEM analyst is investigating an issue by examining events related to two destination IP addresses. However, the analyst is not getting any results from the search.Based on the selected filters shown in the exhibit, why is the search returning no results?
Parentheses are missing between the two items.
An invalid IP address is typed in the Value column.
The wrong boolean operator is selected in the Next column.
The wrong option is selected in the Operator column.
Answer: C
The short version
C — empty results with two values means the Next-column boolean is wrong. AND where OR belongs.
Key concepts in this question
Two destination IPs need OR logic; AND demands the impossible.
Operator/value/parentheses faults produce different symptoms.
Why C is correct
Wrong Next-column boolean is the documented empty-search cause (Q24 confirms the identical pattern).
Why the others are wrong
A. Parentheses group; they do not empty simple two-value searches.
B. Invalid IPs error differently than silent emptiness.
D. Operator-column faults filter differently than boolean faults.