FCP_FSM_AN-7.2 Exam Questions & Answers
FCP - FortiSIEM 7.2 Analyst • Fortinet
100% money-back guarantee
Sample FCP_FSM_AN-7.2 Questions
Practice with real exam-style questions, each with the verified correct answer and explanation.
Refer to the exhibit.

If a rule containing the automation policy shown in the exhibit triggers, what will happen?
The automation policy is configured to run a remediation script named 'Fortinet FortiOS - Block Source IP FortiOS via API'. It specifies enforcement on two FortiGate devices: FortiGate508 and FortiGate90D. Therefore, associated source IP addresses will be blocked on those two FortiGate firewalls only.
Refer to the exhibit.

If you group the events by User, Source IP, and Count attributes, how many results will FortiSIEM display?
Grouping by User, Source IP, and Count means that each unique combination of those three attributes will be treated as a separate result. In the table, all six rows have distinct combinations of User, Source IP, and Count - so FortiSIEM will display 6 results.
Refer to the exhibit.

An analyst is trying to generate an incident with a title that includes the Source IP, Destination IP, User, and Destination Host Name. They are unable to add a Destination Host Name as an incident attribute.
What must be changed to allow the analyst to select Destination Host Name as an attribute?
For an attribute like Destination Host Name to be used in the incident title, it must first be included in the Triggered Attributes list. Only attributes listed there are available for substitution in the title template (e.g., $destIpAddr, $srcIpAddr).
Refer to the exhibit.

Which two conditions will match this rule and subpatterns? (Choose two.)
The user initiates an RDP session (Subpattern 1) and then fails to log in multiple times (Subpattern 2 with COUNT(Matched Events) >= 3) - both from the same Source IP and User within 300 seconds.
The brute force attempts typically involve a successful RDP connection followed by multiple failed logins, satisfying the sequence and grouping conditions in the rule.
Refer to the exhibit.

What happens when an analyst clears an incident generated by a rule containing the automation policy shown in the exhibit?
The automation policy has the option 'Do not notify when an incident is cleared manually' enabled. Therefore, when an analyst manually clears an incident, no notification or automation action is triggered.
Get access to all 32 verified questions with detailed answers.
Unlock All FCP_FSM_AN-7.2 Questions