FCP FCP FortiSIEM & Security Monitoring 2 — Questions and Answers
Question 1: What is the purpose of FortiSIEM's 'Watch List' feature?
- Tracking specific users, IPs, or devices for heightened monitoring and alerting (Correct answer)
- Blocking malicious IP addresses at the perimeter firewall
- Scheduling compliance reports for auditors
- Syncing user accounts from Active Directory
Correct answer: Tracking specific users, IPs, or devices for heightened monitoring and alerting
Watch Lists in FortiSIEM allow analysts to tag specific identities or assets for elevated scrutiny, ensuring any associated events receive higher priority.
Question 2: Which FortiSIEM feature maps detected incidents to MITRE ATT&CK tactics and techniques?
- MITRE ATT&CK mapping in incident details (Correct answer)
- FortiSIEM Rule Library tagging
- CMDB classification engine
- Compliance dashboard framework view
Correct answer: MITRE ATT&CK mapping in incident details
FortiSIEM can tag incidents with corresponding MITRE ATT&CK tactics and techniques, helping analysts understand attacker behavior within a structured framework.
Question 3: In a multi-tenant FortiSIEM deployment, how are different customer environments kept isolated?
- Organizations (orgs) provide logical separation of devices, events, and policies per tenant (Correct answer)
- Separate physical FortiSIEM appliances per customer
- VLAN tagging on the management network
- Individual database schemas per customer in MySQL
Correct answer: Organizations (orgs) provide logical separation of devices, events, and policies per tenant
FortiSIEM uses Organizations (orgs) to logically isolate each tenant's devices, events, rules, and dashboards within a single shared deployment.
Question 4: What is the function of FortiSIEM's 'Real-Time Search'?
- Querying incoming events live as they arrive without needing a stored log index (Correct answer)
- Running pre-scheduled reports on historical data
- Scanning the network for new devices in real time
- Synchronizing FortiSIEM rules with FortiGuard
Correct answer: Querying incoming events live as they arrive without needing a stored log index
Real-Time Search in FortiSIEM lets analysts filter and examine events as they stream in, enabling immediate threat hunting without waiting for indexing.
Question 5: Which FortiSIEM protocol integration is commonly used to pull performance and availability metrics from network devices?
- SNMP (Correct answer)
- SMTP
- LDAP
- RADIUS
Correct answer: SNMP
FortiSIEM uses SNMP to poll network devices for performance counters, interface statistics, and availability data for infrastructure monitoring.
Question 6: What does FortiSIEM's 'Incident Notification' feature enable?
- Sending automated alerts via email, SMS, or ticketing system when incidents are triggered (Correct answer)
- Pushing firewall rule updates to FortiGate upon detection
- Generating weekly PDF reports for management
- Restarting compromised endpoints automatically
Correct answer: Sending automated alerts via email, SMS, or ticketing system when incidents are triggered
Incident Notifications allow FortiSIEM to automatically contact analysts via email, SMS, or integrate with ticketing systems like ServiceNow when a new incident fires.
What is the purpose of FortiSIEM's 'Watch List' feature?