About the Exam

This retired Fortinet exam assessed practical use of FortiSIEM to search, enrich, and analyze security events. It was intended for security professionals responsible for detecting, analyzing, and remediating incidents using FortiSIEM in security operations environments. Passing demonstrated applied knowledge of queries, event analysis, and incident handling. Fortinet lists the 7.2 version as discontinued, with a last delivery date of June 15, 2026.

Exam Topics

  • Collect and analyze event data25%
  • Perform searches and investigations30%
  • Configure reports and visualizations20%
  • Configure incidents and automation25%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated July 13, 2026 at 7:42 PM

Topic filter
Retired questions
Question sort

QuestionQ1

Collect and analyze event data

Refer to the exhibit.

Question Image

What occurs when a device analyzed by the machine-learning configuration shown has consistently high memory utilization?

  • A FortiSIEM will update the regression tables for memory utilization, and average sent and received bytes.
  • B FortiSIEM will trigger an incident for high memory utilization.
  • C FortiSIEM will lower the CPU utilization trigger requirement for CPU utilization.
  • D FortiSIEM will update the model with a higher memory utilization average value.
Explanation

A regression model uses average memory utilization as a feature and average CPU utilization as its target. Sustained memory-utilization values become part of the model’s learned input pattern and raise its learned memory-utilization baseline; high memory utilization itself is not the target condition for an incident. FortiSIEM documents regression as predicting a target field from other feature fields.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Configure incidents and automation

Refer to the exhibit.

Question Image

An analyst needs the displayed rule to trigger when three failed login attempts take place within three minutes. What values should be set for the condition time window and the aggregate count?

  • A Time window 180 seconds, aggregate count 3
  • B Time window 180 seconds, aggregate count 2
  • C Time window 90 seconds, aggregate count 3
  • D Time window 90 seconds, aggregate count 2
Explanation

Three minutes is 180 seconds. Because the aggregate condition uses a strict greater-than operator (COUNT(Matched Events) > value), a value of 2 causes the rule to trigger at a matched-event count of 3.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Collect and analyze event data

Refer to the exhibit.

Question Image

If events are grouped by Reporting Device, Reporting IP, and Application Category, how many results will FortiSIEM display?

  • A Four
  • B Five
  • C One
  • D Six
  • E Two
Explanation

Grouping by multiple attributes produces one result for each distinct combination of their values. Five distinct Reporting Device, Reporting IP, and Application Category combinations are present because the two DB events reported by FW01 at 10.1.1.1 belong to the same group. FortiSIEM documentation describes Group By attributes as the attributes used to group events before aggregation.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Configure incidents and automation

Refer to the exhibits.

Question Image

Three events are gathered over 10 minutes from two servers: Server A and Server B.

Based on the rule subpattern settings and a 10-minute condition window, how many incidents will the servers generate?

  • A Server A will not generate any incidents and Server B will not generate any incidents.
  • B Server A will generate one incident and Server B will generate one incident.
  • C Server A will not generate any incidents and server B will generate one incident.
  • D Server A will generate one incident and Server B will not generate any incidents.
Explanation

The grouped rule requires a minimum of two events and an average CPU utilization strictly greater than each server's CPU-utilization critical threshold within the 10-minute window. Server A's CPU values average approximately 91.7, exceeding its threshold of 90, so it generates one incident. Server B does not exceed its threshold of 70 on average and generates no incident.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Collect and analyze event data

Refer to the exhibit.

Question Image

What does the Group: FortiSIEM Analysts value refer to?

  • A FortiSIEM organization group
  • B LDAP user group
  • C CMDB user group
  • D Windows Active Directory user group
Explanation

FortiSIEM Analysts is a user group in the CMDB. Fortinet defines it as the group containing the subset of FortiSIEM users who can be assigned to work on cases; analyst teams are created beneath this CMDB group.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

That's the end of the preview

It's free

100% of the questions are free for all users.
No strings attached.

Topics covered
Collect and analyze event dataPerform searches and investigationsConfigure reports and visualizationsConfigure incidents and automation
Know a question that should be here? Contribute to this exam
Back home