Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Fortinet logo

FortinetNSE 6 - FortiSIEM Analyst

Domain 1Objective 2

Apply Group by and Data Aggregation on Search Results NSE6-FORTISIEM-ANALYST Practice Questions (Page 1)

Part of the Analytics domain, which makes up ~18% of our current practice bank. Fortinet does not publish an official question count, but from its 70-minute exam (~30–45 total, ~5–8 in this domain), expect 1–2 from this objective — we provide 16 practice questions to prepare you well beyond it. (estimate)

16questions here
4free pages
2concepts

Questions 1–5

  1. 1expert · hard

    An analyst needs to produce a report of the total bytes transferred per department, but the `department` field is sometimes empty or contains variations like 'Sales', 'sales ', and 'SALES'. The analyst wants to ensure all these variations are counted as one department. Which approach should be taken?

    Select an answer first
  2. 2foundation · easy

    A FortiSIEM analyst needs to find the average duration of VPN sessions per user. Which aggregation function should be used on the duration field?

    Select an answer first
  3. 3application · medium

    An analyst needs to see the number of malware detection events per endpoint, but only for endpoints that have generated more than 10 detections in the last 30 days. The events contain `endpointName` and `detectionType`. Which query component is required to filter the aggregated results?

    Select an answer first
  4. 4expert · hard

    A security analyst is building a query to identify anomalous behavior. They need to find users whose average session duration in the last 30 days is significantly higher than their own 90-day average. The events contain `user`, `sessionDuration`, and `eventTime`. Which approach correctly computes this comparison?

    Select an answer first
  5. 5application · easy

    A compliance officer requests a list of all unique user accounts that have accessed a sensitive file share in the past 90 days. The events have fields `user` and `filePath`. The analyst wants to produce a single row per user. Which aggregation function should be applied to the `user` field?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Fortinet. “NSE6-FORTISIEM-ANALYST” is a trademark of its owner, used for identification only.