Fortinet NSE5_FSM-5.2 Exam Questions (Updated 2021) 100% Real Question Answers
Pass Fortinet NSE5_FSM-5.2 Exam Quickly With Exams4sures
NEW QUESTION 18
Refer to the exhibit.
How was the FortiGate device discovered by FortiSIEM?
- A. Through auto log discovery
- B. Through syslog discovery
- C. Using the pull events method
- D. Through GUI log discovery
Answer: D
NEW QUESTION 19
If an incident's status is Cleared, what does this mean?
- A. A security rule issue has been resolved.
- B. The incident was cleared by an operator.
- C. A clear condition set on a rule was satisfied.
- D. Two hours have passed since the incident occurred and the incident has not reoccurred.
Answer: D
NEW QUESTION 20
What is the best discovery scan option for a network environment where ping is disabled on all network devices?
- A. L2 scan
- B. Smart scan
- C. CMDB scan
- D. Range scan
Answer: B
NEW QUESTION 21
An administrator defines SMTP as a critical process on a Linux server. If the SMTP process is stopped, FortiSIEM would generate a critical event with which event type?
- A. Postfix-Mail-Slop
- B. Generic_SMTP_Process_Exit
- C. PH_DEV_MON_PROC_STOP
- D. PH_DEV_MON_SMTP_STOP
Answer: D
NEW QUESTION 22
What is a prerequisite for FortiSIEM Linux agent installation?
- A. The auditd service must be installed on the Linux server being monitored
- B. The web server must be installed on the Linux server being monitored
- C. The Linux agent manager server must be installed.
- D. Both the web server and the audit service must be installed on the Linux server being monitored
Answer: D
NEW QUESTION 23
Refer to the exhibit.
An administrator is trying to identify an issue using an expression bated on the Expression Builder settings shown in the exhibit however, the error message shown in the exhibit indicates that the expression is invalid.
Which is the correct expression?
- A. COUNT(Matched Events)
- B. Matched Events(COUNT)
- C. (COUNT) Matched Events
- D. Matched Events COUNT()
Answer: A
NEW QUESTION 24
What are the minimum memory requirements for the FortiSIEM supervisor virtual appliance, when the proprietary flat file database is used?
- A. 16GB RAM
- B. 32GB RAM
- C. 64GB RAM
- D. 24GB RAM
Answer: D
NEW QUESTION 25
Refer to the exhibit.
The FortiSIEM administrator is examining events for two devices to investigate an issue However, the administrator is not getting any results from their search.
Based on the selected fillers shown in the exhibit, why is the search returning no results?
- A. The wrong option is selected in the Operator column
- B. An invalid IP subnet is typed in the Value column
- C. Parenthesis are missing
- D. The wrong boolean operator is selected in the Next column
Answer: D
NEW QUESTION 26
What are the four possible incident status values?
- A. Active, auto cleared, manual, false positive
- B. Active, dosed, cleared, open
- C. Active, cleared, cleared manually, system cleared
- D. Active, closed, manual, resolved
Answer: D
NEW QUESTION 27
To determine whether or not syslog is being received from a network device, which is the best command from the backend?
- A. phDeviceTest
- B. phSyslogRecorder
- C. netcat
- D. tcpdump
Answer: D
NEW QUESTION 28
Refer to the exhibit.
A FortiSIEM administrator wants to collect both SIEM event logs and performance and availability metrics (PAM) events from a Microsoft Windows server Which protocol should the administrator select in the Access Protocol drop-down list so that FortiSIEM will collect both SIEM and PAM events?
- A. TELNET
- B. LDAP start TLS
- C. WMI
- D. LDAPS
Answer: A
NEW QUESTION 29
Which process converts Raw log data to structured data?
- A. Data enrichment
- B. Data validation
- C. Data parsing
- D. Data classification
Answer: C
NEW QUESTION 30
What operating system is FortiSIEM based on?
- A. Cent OS
- B. Ubuntu
- C. RedHat
- D. Microsoft Windows
Answer: A
NEW QUESTION 31
Refer to the exhibit.
A FortiSlEM administrator wants to group some attributes for a report, but is not able to do so successfully.
As shown in the exhibit, why are some of the fields highlighted in red?
- A. Unique attributes cannot be grouped.
- B. The attribute COUNT(Matched event) is an invalid expression.
- C. The Event Receive Time attribute is not available for logs.
- D. No RAW Event Log attribute is available for devices.
Answer: A
NEW QUESTION 32
In the advanced analytical rules engine in FortiSIEM, multiple subpatterms can be referenced using which three operation?(Choose three.)
- A. ELSE
- B. AND
- C. OR
- D. FOLLOWED_BY
- E. NOT
Answer: A,B,E
NEW QUESTION 33
Refer to the exhibit.
If events are grouped by Reporting IP, Event Type, and user attributes in FortiSIEM, how ,many results will be displayed?
- A. Five results will be displayed.
- B. Unique attribute cannot be grouped.
- C. Seven results will be displayed.
- D. There results will be displayed.
Answer: A
NEW QUESTION 34
An administrator wants to search for events received from Linux and Windows agents.
Which attribute should the administrator use in search filters, to view events received from agents only.
- A. External Event Receive Protocol
- B. External Event Receive Raw Logs
- C. External Event Receive Agents
- D. Event Received Proto Agents
Answer: B
NEW QUESTION 35
......
Real Fortinet NSE5_FSM-5.2 Exam Questions [Updated 2021]: https://www.exams4sures.com/Fortinet/NSE5_FSM-5.2-practice-exam-dumps.html
Prepare NSE5_FSM-5.2 Question Answers - NSE5_FSM-5.2 Exam Dumps: https://drive.google.com/open?id=1shbNud7magF4V24uG5O3ICNG6LAWR7Lc