Fortinet NSE 5 - FortiSIEM 6.3 NSE5_FSM-6.3 exam will be retired on September 30, 2025. To support professionals working with the latest capabilities in FortiSIEM 7.2, Fortinet has introduced a new assessment - the FCP_FSM_AN-7.2 FortiSIEM Analyst exam. This upgraded test reflects the platform's enhanced analytics, automation, and machine-learning features, helping security analysts validate skills that are aligned with modern SIEM operations.

The NSE5_FSM-6.3 exam is designed for IT and security practitioners who work with FortiSIEM 6.3 and need to demonstrate skills in configuration, operations, analytics, and incident management. The exam consists of 33 multiple-choice questions, and candidates have 60 minutes to complete it. A pass/fail score report is available through Pearson VUE.
Its content is divided into four main knowledge domains:
SIEM Concepts – Covers FortiSIEM architecture components, deployment requirements, event type classification, system configuration, and troubleshooting related to system setup.
FortiSIEM Operations – Focuses on discovering devices, building queries from events, tuning data collection processes, deploying FortiSIEM agents, and resolving discovery-related issues.
FortiSIEM Analytics – Tests your ability to use group-by and data aggregation tools on search results and leverage reporting features.
Rules and Incidents – Assesses your skills in configuring rule sub-patterns, managing incidents, setting clear conditions, and configuring notification policies.
This exam has been a popular choice for professionals aiming to validate their expertise in SIEM (Security Information and Event Management) solutions from Fortinet. However, with newer versions of FortiSIEM offering advanced analytics and machine learning features, the certification is being phased out.
The FCP – FortiSIEM 7.2 Analyst FCP_FSM_AN-7.2 exam is the designated upgrade for candidates seeking to validate their skills on the most recent version of FortiSIEM. It reflects changes in technology and best practices, ensuring certified professionals can operate effectively in today’s dynamic threat landscape.
Key details of the new exam include:
Format and Timing: 32 multiple-choice questions, 60 minutes, with a pass/fail score report through Pearson VUE.
Product Version: FortiSIEM 7.2, featuring enhanced analytics, automation, and behavior-based security functions.
The updated domains highlight the evolution of SIEM technologies:
Analytics – Building complex queries, applying group-by and data aggregation, performing CMDB and lookup table queries, and executing nested query lookups.
Rules and Subpatterns – Understanding rule components, subpatterns, and aggregation to create effective analytics rules.
Incidents, Notifications, and Remediation – Managing incidents, configuring notification policies, and using remediation features for faster response.
Machine Learning, UEBA, and ZTNA – Configuring machine learning capabilities, integrating User and Entity Behavior Analytics (UEBA) into rules and dashboards, and implementing Zero Trust Network Access (ZTNA) within FortiSIEM operations.
The release of FortiSIEM 7.2 introduces significant advancements that go beyond the core SIEM functionalities tested in NSE5_FSM-6.3. Key enhancements include:
Machine Learning and UEBA: Automating anomaly detection and correlating events using AI-driven insights.
ZTNA Integration: Enabling security teams to incorporate Zero Trust principles into FortiSIEM operations, improving visibility and access control.
Improved Analytics and Dashboards: Delivering deeper insights into network and user behavior through more powerful search, reporting, and aggregation tools.
By earning the FCP_FSM_AN-7.2 certification, professionals can demonstrate their ability to leverage these advanced capabilities, making them valuable assets for organizations focused on robust security monitoring and threat detection.
If you are currently preparing for the NSE5_FSM-6.3 exam, consider your timeline carefully:
●Complete the exam before September 30, 2025 if you wish to earn the certification on FortiSIEM 6.3.
●If you want to future-proof your skills, focus on the FCP_FSM_AN-7.2 exam instead.
To prepare effectively:
Study the Exam Objectives: Review the domains for both exams and note the differences, especially in areas like machine learning, UEBA, and ZTNA.
Hands-On Practice: Set up a lab environment with FortiSIEM 7.2. Practice building queries, configuring rules, and testing notification and remediation workflows.
Explore Advanced Features: Learn how machine learning models and UEBA enrich security analytics. Experiment with integrating ZTNA into your operations.
Leverage Training Resources: Fortinet's official courses, documentation, and community forums provide valuable guidance. Practice exams can also help you gauge readiness.
The retirement of the NSE5_FSM-6.3 exam marks an important milestone in Fortinet's effort to keep its certifications aligned with cutting-edge technology. By adopting the FCP_FSM_AN-7.2 exam, candidates will stay ahead of industry trends, mastering the analytics-driven and AI-enhanced capabilities of FortiSIEM 7.2.
Whether you are a current NSE5 certified professional or new to FortiSIEM, planning your certification path now ensures you remain competitive in an ever-evolving cybersecurity landscape. Don't miss the opportunity to validate your expertise with the most up-to-date SIEM skills - start preparing for FCP_FSM_AN-7.2 today.