Download Free Fortinet NSE5_FSM-5.2 Real Exam Questions Download [Q16-Q39]

Share

Download Free Fortinet NSE5_FSM-5.2 Real Exam Questions Download

Latest Fortinet NSE5_FSM-5.2 Real Exam Dumps PDF

NEW QUESTION # 16
Refer to the exhibit.

If events are grouped by Reporting IP, Event Type, and user attributes in FortiSIEM, how ,many results will be displayed?

  • A. There results will be displayed.
  • B. Unique attribute cannot be grouped.
  • C. Seven results will be displayed.
  • D. Five results will be displayed.

Answer: D


NEW QUESTION # 17
In the advanced analytical rules engine in FortiSIEM, multiple subpatterms can be referenced using which three operation?(Choose three.)

  • A. FOLLOWED_BY
  • B. AND
  • C. NOT
  • D. ELSE
  • E. OR

Answer: B,C,D


NEW QUESTION # 18
Which three ports can be used to send Syslogs to FortiSIEM? (Choose three.)

  • A. UDP 162
  • B. TCP 1470
  • C. UDP9999
  • D. TCP 514
  • E. UDP 514

Answer: B,D,E


NEW QUESTION # 19
Refer to the exhibit.

The FortiSIEM administrator is examining events for two devices to investigate an issue However, the administrator is not getting any results from their search.
Based on the selected fillers shown in the exhibit, why is the search returning no results?

  • A. The wrong option is selected in the Operator column
  • B. Parenthesis are missing
  • C. An invalid IP subnet is typed in the Value column
  • D. The wrong boolean operator is selected in the Next column

Answer: C


NEW QUESTION # 20
If an incident's status is Cleared, what does this mean?

  • A. A clear condition set on a rule was satisfied.
  • B. Two hours have passed since the incident occurred and the incident has not reoccurred.
  • C. The incident was cleared by an operator.
  • D. A security rule issue has been resolved.

Answer: A


NEW QUESTION # 21
A FortiSIEM administrator wants to restrict a network administrator to running searches for only firewall devices. Under role management, which option does the FortiSIEM administrator need to configure to achieve this scenario?

  • A. CMDB Report Conditions
  • B. UI Access
  • C. Data Conditions

Answer: C


NEW QUESTION # 22
Which process converts Raw log data to structured data?

  • A. Data enrichment
  • B. Data validation
  • C. Data classification
  • D. Data parsing

Answer: B


NEW QUESTION # 23
Which database is used for storing anomaly data, that is calculated for different parameters, such as traffic and device resource usage running averages, and standard deviation values?

  • A. Profile DB
  • B. Event DB
  • C. SVN DB
  • D. CMDB

Answer: B


NEW QUESTION # 24
Device discovery information is stored in which database?

  • A. Profile DB
  • B. SVN DB
  • C. Event DB
  • D. CMDB

Answer: D


NEW QUESTION # 25
What are the four possible incident status values?

  • A. Active, cleared, cleared manually, system cleared
  • B. Active, closed, manual, resolved
  • C. Active, auto cleared, manual, false positive
  • D. Active, dosed, cleared, open

Answer: B


NEW QUESTION # 26
Refer to the exhibit.

A FortiSIEM administrator wants to collect both SIEM event logs and performance and availability metrics (PAM) events from a Microsoft Windows server Which protocol should the administrator select in the Access Protocol drop-down list so that FortiSIEM will collect both SIEM and PAM events?

  • A. TELNET
  • B. LDAPS
  • C. LDAP start TLS
  • D. WMI

Answer: A


NEW QUESTION # 27
Refer to the exhibit.

What do the yellow stars listed in the Monitor column indicate?

  • A. A yellow star indicates that a metric was not applied during discovery and, therefore, FortiSEIM was unable to collect data.
  • B. A yellow star indicates that a metric was applied during discovery, but data collection has not started
  • C. A yellow star indicates that a metric was applied during discovery, and data has been collected successfully
  • D. A yellow star indicates that a metric was applied during discovery, but FortiSIEM is unable to collect data.

Answer: B


NEW QUESTION # 28
Refer to the exhibit.

An administrator is trying to identify an issue using an expression bated on the Expression Builder settings shown in the exhibit however, the error message shown in the exhibit indicates that the expression is invalid.
Which is the correct expression?

  • A. Matched Events(COUNT)
  • B. COUNT(Matched Events)
  • C. (COUNT) Matched Events
  • D. Matched Events COUNT()

Answer: B


NEW QUESTION # 29
To determine SNMP discovery issues, which is the best command from the backend?

  • A. snmptest
  • B. ssh
  • C. phSNMPTest
  • D. snmpwalk

Answer: D


NEW QUESTION # 30
Refer to the exhibit.

The FortiSIEM administrator is examining events for two devices to investigate an issue However, the administrator is not getting any results from their search.
Based on the selected fillers shown in the exhibit, why is the search returning no results?

  • A. An invalid IP subnet is typed in the Value column
  • B. The wrong option is selected in the Operator column
  • C. Parenthesis are missing
  • D. The wrong boolean operator is selected in the Next column

Answer: D


NEW QUESTION # 31
Which database is used for storing anomaly data, that is calculated for different parameters, such as traffic and device resource usage running averages, and standard deviation values?

  • A. Profile DB
  • B. SVN DB
  • C. Event DB
  • D. CMDB

Answer: A


NEW QUESTION # 32
Refer to the exhibit.

If events are grouped by Reporting IP, Event Type, and user attributes in FortiSIEM, how ,many results will be displayed?

  • A. There results will be displayed.
  • B. Unique attribute cannot be grouped.
  • C. Seven results will be displayed.
  • D. Five results will be displayed.

Answer: D


NEW QUESTION # 33
Which process converts Raw log data to structured data?

  • A. Data enrichment
  • B. Data parsing
  • C. Data classification
  • D. Data validation

Answer: B


NEW QUESTION # 34
Which FortiSIEM components can do performance availability and performance monitoring?

  • A. Supervisor, worker, and collector
  • B. Supervisor only
  • C. Collectors only
  • D. Supervisor and workers only

Answer: A


NEW QUESTION # 35
Refer to the exhibit.

Three events are collected over a 10-minutc time period from two servers Server A and Server B.
Based on the settings being used for the rule subpattern. how many incidents will the servers generate?

  • A. Server A will not generate any incidents and Server B will not generate any incidents
  • B. Server B will generate one incident and Server A will not generate any incidents
  • C. Server A will generate one incident and Server B wifl generate one incident
  • D. Server A will generate one incident and Server B will not generate any incidents

Answer: A


NEW QUESTION # 36
Which two export methods are available for FortiSIEM analytics results? (Choose two.)

  • A. CSV
  • B. PDF
  • C. PNG
  • D. HTML

Answer: A,B


NEW QUESTION # 37
Refer to the exhibit.

A FortiSIEM administrator wants to collect both SIEM event logs and performance and availability metrics (PAM) events from a Microsoft Windows server Which protocol should the administrator select in the Access Protocol drop-down list so that FortiSIEM will collect both SIEM and PAM events?

  • A. TELNET
  • B. LDAPS
  • C. LDAP start TLS
  • D. WMI

Answer: A


NEW QUESTION # 38
A FortiSIEM supervisor at headquarters is struggling to keep up with an increase of EPS (Events Per Second) being reported across the enterprise. What components should an administrator consider deploying to assist the supervisor with processing data?

  • A. Collector
  • B. Agent
  • C. Worker
  • D. Supervisor

Answer: C


NEW QUESTION # 39
......

PDF (New 2023) Actual Fortinet NSE5_FSM-5.2 Exam Questions: https://www.test4engine.com/NSE5_FSM-5.2_exam-latest-braindumps.html

NSE5_FSM-5.2 Exam Dumps, NSE5_FSM-5.2 Practice Test Questions: https://drive.google.com/open?id=1bC0MtQzgWDPqzEnPCNi_4xwv2g3WRUtr