ExamGecko
Question list
Search
Search

Question 47 - NSE5_FSM-6.3 discussion

Report
Export

Refer to the exhibit.

A FortiSIEM administrator wants to collect both SIEM event logs and performance and availability metrics (PAM) events from a Microsoft Windows server

Which protocol should the administrator select in the Access Protocol drop-down list so that FortiSIEM will collect both SIEM and PAM events?

A.
TELNET
Answers
A.
TELNET
B.
WMI
Answers
B.
WMI
C.
LDAPS
Answers
C.
LDAPS
D.
LDAP start TLS
Answers
D.
LDAP start TLS
Suggested answer: B

Explanation:

Collecting SIEM and PAM Events: To collect both SIEM event logs and Performance and Availability Monitoring (PAM) events from a Microsoft Windows server, a suitable protocol must be selected.

WMI Protocol: Windows Management Instrumentation (WMI) is the appropriate protocol for this task.

SIEM Event Logs: WMI can collect security, application, and system logs from Windows devices.

PAM Events: WMI can also gather performance metrics, such as CPU usage, memory utilization, and disk activity.

Comprehensive Data Collection: Using WMI ensures that both types of data are collected efficiently from the Windows server.

Reference: FortiSIEM 6.3 User Guide, Data Collection Methods section, which details the use of WMI for collecting various types of logs and performance metrics.

asked 18/09/2024
Reed G Porter
28 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first