
FortinetNSE 6 - FortiSIEM Analyst
Domain 1Objective 2
Apply Group by and Data Aggregation on Search Results NSE6-FORTISIEM-ANALYST Practice Questions (Page 3)
Part of the Analytics domain, which makes up ~18% of our current practice bank. Fortinet does not publish an official question count, but from its 70-minute exam (~30–45 total, ~5–8 in this domain), expect 1–2 from this objective — we provide 16 practice questions to prepare you well beyond it. (estimate)
16questions here
4free pages
2concepts
Questions 11–15
- 11
A SOC analyst needs to report the average severity score of security alerts per asset. The events contain `assetName` and `severityScore`. Which aggregation should be applied to `severityScore`?
Select an answer first - 12
In FortiSIEM, which clause is used in a search query to combine events into groups based on the values of one or more fields?
Select an answer first - 13
A SOC analyst is investigating a potential slow data exfiltration. They need to find the average bytes transferred per session, but some sessions have extremely large transfers that skew the average. The analyst wants a measure that is robust to outliers. Which aggregation should be used?
Select an answer first - 14
A network engineer wants to identify the server with the highest peak CPU usage. The events contain `serverName` and `cpuUsagePercent`. Which aggregation should be used to find the peak value per server?
Select an answer first - 15
A network analyst needs to report the highest and lowest latency values observed for each application server over the past day. The events contain `serverName` and `latencyMs`. Which aggregation functions should be applied to `latencyMs`?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Fortinet. “NSE6-FORTISIEM-ANALYST” is a trademark of its owner, used for identification only.