FCP FCP FortiSIEM & Security Monitoring 1 — Questions and Answers
Question 1: What is the primary function of FortiSIEM in a security operations environment?
- Unified security information and event management combining log correlation, analytics, and compliance (Correct answer)
- Endpoint antivirus scanning and remediation
- WAN optimization and traffic acceleration
- Firewall policy deployment across branches
Correct answer: Unified security information and event management combining log correlation, analytics, and compliance
FortiSIEM provides a unified SIEM platform that ingests, correlates, and analyzes logs and events from diverse IT and security sources for threat detection and compliance.
Question 2: In FortiSIEM, what is a 'Rule' used for?
- Defining correlation logic that triggers incidents when event patterns are matched (Correct answer)
- Configuring firewall access policies
- Scheduling vulnerability scans
- Creating network diagrams
Correct answer: Defining correlation logic that triggers incidents when event patterns are matched
Rules in FortiSIEM define event correlation conditions — when logs match the specified pattern, FortiSIEM automatically generates an incident.
Question 3: Which FortiSIEM component is responsible for parsing raw log data into structured event attributes?
- Event parser (Correct answer)
- Collector agent
- Incident engine
- CMDB scanner
Correct answer: Event parser
The event parser in FortiSIEM processes raw log strings and extracts structured fields such as source IP, user, and action for downstream correlation.
Question 4: What is the role of the FortiSIEM CMDB?
- Maintaining an inventory of discovered devices, their attributes, and relationships (Correct answer)
- Storing encrypted credentials for LDAP authentication
- Caching DNS resolutions for faster event lookup
- Managing SSL VPN user sessions
Correct answer: Maintaining an inventory of discovered devices, their attributes, and relationships
The FortiSIEM CMDB (Configuration Management Database) automatically discovers and catalogs network assets, enabling context-aware event correlation.
Question 5: Which FortiSIEM deployment component is typically placed in remote sites to collect and forward logs to the supervisor?
- FortiSIEM Collector (Correct answer)
- FortiSIEM Worker
- FortiSIEM Supervisor
- FortiSIEM Agent
Correct answer: FortiSIEM Collector
The FortiSIEM Collector is deployed at remote locations to aggregate logs from local devices and forward them to the central Supervisor for analysis.
Question 6: In FortiSIEM, what does 'baseline deviation' detection help identify?
- Anomalous user or device behavior that differs significantly from established normal patterns (Correct answer)
- Devices that are missing security patches
- Firewall rules that overlap or conflict
- SSL certificates nearing expiration
Correct answer: Anomalous user or device behavior that differs significantly from established normal patterns
Baseline deviation detection compares current activity against learned normal behavior to flag anomalies that may indicate insider threats or compromised accounts.
What is the primary function of FortiSIEM in a security operations environment?