Exam NSE6_FSM_AN-7.4 Topic 1 Question 73 Discussion
Actual exam question for Fortinet's NSE6_FSM_AN-7.4 exam
Question #: 73
Topic #: 1
Question #: 73
Topic #: 1
Refer to the exhibit.

Which value would you expect the FortiSIEM parser to use to populate the Application Name field?

Which value would you expect the FortiSIEM parser to use to populate the Application Name field?
Suggested Answer: C Vote an answer
The correct answer is C. SSL . FortiSIEM receives raw logs, processes them through parsers, normalizes the extracted fields, classifies the event, and stores the structured data. The Study Guide explains the FortiSIEM process flow: data is collected, processed by the parsing engine, normalized, classified, and then stored. It further states that normalization extracts individual fields from raw events and maps those fields to a common schema. The FortiSIEM 7.4 User Guide describes a parser as a file containing instructions for the parser module to convert a raw log into event attributes. In the exhibit, the raw FortiGate log includes values such as profiletype= " applist " , appcat= " Network.Service " , and app= " SSL " . The field that directly represents the application value is app= " SSL " . Therefore, the parser would use SSL to populate the normalized Application Name field. applist describes the profile type, Network.Service is the application category, and wan1 is the interface, not the application name.
by Lawrence at Aug 16, 2026, 01:44 PM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).