Download Free Fortinet NSE5_FSM-5.2 Real Exam Questions Download
Latest Fortinet NSE5_FSM-5.2 Real Exam Dumps PDF
NEW QUESTION # 16
Refer to the exhibit.
If events are grouped by Reporting IP, Event Type, and user attributes in FortiSIEM, how ,many results will be displayed?
- A. There results will be displayed.
- B. Unique attribute cannot be grouped.
- C. Seven results will be displayed.
- D. Five results will be displayed.
Answer: D
NEW QUESTION # 17
In the advanced analytical rules engine in FortiSIEM, multiple subpatterms can be referenced using which three operation?(Choose three.)
- A. FOLLOWED_BY
- B. AND
- C. NOT
- D. ELSE
- E. OR
Answer: B,C,D
NEW QUESTION # 18
Which three ports can be used to send Syslogs to FortiSIEM? (Choose three.)
- A. UDP 162
- B. TCP 1470
- C. UDP9999
- D. TCP 514
- E. UDP 514
Answer: B,D,E
NEW QUESTION # 19
Refer to the exhibit.
The FortiSIEM administrator is examining events for two devices to investigate an issue However, the administrator is not getting any results from their search.
Based on the selected fillers shown in the exhibit, why is the search returning no results?
- A. The wrong option is selected in the Operator column
- B. Parenthesis are missing
- C. An invalid IP subnet is typed in the Value column
- D. The wrong boolean operator is selected in the Next column
Answer: C
NEW QUESTION # 20
If an incident's status is Cleared, what does this mean?
- A. A clear condition set on a rule was satisfied.
- B. Two hours have passed since the incident occurred and the incident has not reoccurred.
- C. The incident was cleared by an operator.
- D. A security rule issue has been resolved.
Answer: A
NEW QUESTION # 21
A FortiSIEM administrator wants to restrict a network administrator to running searches for only firewall devices. Under role management, which option does the FortiSIEM administrator need to configure to achieve this scenario?
- A. CMDB Report Conditions
- B. UI Access
- C. Data Conditions
Answer: C
NEW QUESTION # 22
Which process converts Raw log data to structured data?
- A. Data enrichment
- B. Data validation
- C. Data classification
- D. Data parsing
Answer: B
NEW QUESTION # 23
Which database is used for storing anomaly data, that is calculated for different parameters, such as traffic and device resource usage running averages, and standard deviation values?
- A. Profile DB
- B. Event DB
- C. SVN DB
- D. CMDB
Answer: B
NEW QUESTION # 24
Device discovery information is stored in which database?
- A. Profile DB
- B. SVN DB
- C. Event DB
- D. CMDB
Answer: D
NEW QUESTION # 25
What are the four possible incident status values?
- A. Active, cleared, cleared manually, system cleared
- B. Active, closed, manual, resolved
- C. Active, auto cleared, manual, false positive
- D. Active, dosed, cleared, open
Answer: B
NEW QUESTION # 26
Refer to the exhibit.
A FortiSIEM administrator wants to collect both SIEM event logs and performance and availability metrics (PAM) events from a Microsoft Windows server Which protocol should the administrator select in the Access Protocol drop-down list so that FortiSIEM will collect both SIEM and PAM events?
- A. TELNET
- B. LDAPS
- C. LDAP start TLS
- D. WMI
Answer: A
NEW QUESTION # 27
Refer to the exhibit.
What do the yellow stars listed in the Monitor column indicate?
- A. A yellow star indicates that a metric was not applied during discovery and, therefore, FortiSEIM was unable to collect data.
- B. A yellow star indicates that a metric was applied during discovery, but data collection has not started
- C. A yellow star indicates that a metric was applied during discovery, and data has been collected successfully
- D. A yellow star indicates that a metric was applied during discovery, but FortiSIEM is unable to collect data.
Answer: B
NEW QUESTION # 28
Refer to the exhibit.
An administrator is trying to identify an issue using an expression bated on the Expression Builder settings shown in the exhibit however, the error message shown in the exhibit indicates that the expression is invalid.
Which is the correct expression?
- A. Matched Events(COUNT)
- B. COUNT(Matched Events)
- C. (COUNT) Matched Events
- D. Matched Events COUNT()
Answer: B
NEW QUESTION # 29
To determine SNMP discovery issues, which is the best command from the backend?
- A. snmptest
- B. ssh
- C. phSNMPTest
- D. snmpwalk
Answer: D
NEW QUESTION # 30
Refer to the exhibit.
The FortiSIEM administrator is examining events for two devices to investigate an issue However, the administrator is not getting any results from their search.
Based on the selected fillers shown in the exhibit, why is the search returning no results?
- A. An invalid IP subnet is typed in the Value column
- B. The wrong option is selected in the Operator column
- C. Parenthesis are missing
- D. The wrong boolean operator is selected in the Next column
Answer: D
NEW QUESTION # 31
Which database is used for storing anomaly data, that is calculated for different parameters, such as traffic and device resource usage running averages, and standard deviation values?
- A. Profile DB
- B. SVN DB
- C. Event DB
- D. CMDB
Answer: A
NEW QUESTION # 32
Refer to the exhibit.
If events are grouped by Reporting IP, Event Type, and user attributes in FortiSIEM, how ,many results will be displayed?
- A. There results will be displayed.
- B. Unique attribute cannot be grouped.
- C. Seven results will be displayed.
- D. Five results will be displayed.
Answer: D
NEW QUESTION # 33
Which process converts Raw log data to structured data?
- A. Data enrichment
- B. Data parsing
- C. Data classification
- D. Data validation
Answer: B
NEW QUESTION # 34
Which FortiSIEM components can do performance availability and performance monitoring?
- A. Supervisor, worker, and collector
- B. Supervisor only
- C. Collectors only
- D. Supervisor and workers only
Answer: A
NEW QUESTION # 35
Refer to the exhibit.
Three events are collected over a 10-minutc time period from two servers Server A and Server B.
Based on the settings being used for the rule subpattern. how many incidents will the servers generate?
- A. Server A will not generate any incidents and Server B will not generate any incidents
- B. Server B will generate one incident and Server A will not generate any incidents
- C. Server A will generate one incident and Server B wifl generate one incident
- D. Server A will generate one incident and Server B will not generate any incidents
Answer: A
NEW QUESTION # 36
Which two export methods are available for FortiSIEM analytics results? (Choose two.)
- A. CSV
- B. PDF
- C. PNG
- D. HTML
Answer: A,B
NEW QUESTION # 37
Refer to the exhibit.
A FortiSIEM administrator wants to collect both SIEM event logs and performance and availability metrics (PAM) events from a Microsoft Windows server Which protocol should the administrator select in the Access Protocol drop-down list so that FortiSIEM will collect both SIEM and PAM events?
- A. TELNET
- B. LDAPS
- C. LDAP start TLS
- D. WMI
Answer: A
NEW QUESTION # 38
A FortiSIEM supervisor at headquarters is struggling to keep up with an increase of EPS (Events Per Second) being reported across the enterprise. What components should an administrator consider deploying to assist the supervisor with processing data?
- A. Collector
- B. Agent
- C. Worker
- D. Supervisor
Answer: C
NEW QUESTION # 39
......
PDF (New 2023) Actual Fortinet NSE5_FSM-5.2 Exam Questions: https://www.test4engine.com/NSE5_FSM-5.2_exam-latest-braindumps.html
NSE5_FSM-5.2 Exam Dumps, NSE5_FSM-5.2 Practice Test Questions: https://drive.google.com/open?id=1bC0MtQzgWDPqzEnPCNi_4xwv2g3WRUtr