Pass Your NSE5_FSM-5.2 Dumps as PDF Updated on 2021 With 43 Questions [Q11-Q32]

Share

Pass Your NSE5_FSM-5.2 Dumps as PDF Updated on 2021 With 43 Questions

Fortinet NSE5_FSM-5.2 Real Exam Questions and Answers FREE

NEW QUESTION 11
To determine whether or not syslog is being received from a network device, which is the best command from the backend?

  • A. phDeviceTest
  • B. phSyslogRecorder
  • C. netcat
  • D. tcpdump

Answer: D

 

NEW QUESTION 12
What is a prerequisite for FortiSIEM Linux agent installation?

  • A. The auditd service must be installed on the Linux server being monitored
  • B. The web server must be installed on the Linux server being monitored
  • C. The Linux agent manager server must be installed.
  • D. Both the web server and the audit service must be installed on the Linux server being monitored

Answer: D

 

NEW QUESTION 13
In the rules engine, which condition instructs FortiSIEM to summarize and count the matching evaluated data?

  • A. Filters
  • B. Time Window
  • C. Group By
  • D. Aggregation

Answer: D

 

NEW QUESTION 14
Refer to the exhibit.

A FortiSlEM administrator wants to group some attributes for a report, but is not able to do so successfully.
As shown in the exhibit, why are some of the fields highlighted in red?

  • A. Unique attributes cannot be grouped.
  • B. The attribute COUNT(Matched event) is an invalid expression.
  • C. The Event Receive Time attribute is not available for logs.
  • D. No RAW Event Log attribute is available for devices.

Answer: A

 

NEW QUESTION 15
Which database is used for storing anomaly data, that is calculated for different parameters, such as traffic and device resource usage running averages, and standard deviation values?

  • A. SVN DB
  • B. Event DB
  • C. Profile DB
  • D. CMDB

Answer: B

 

NEW QUESTION 16
In the advanced analytical rules engine in FortiSIEM, multiple subpatterms can be referenced using which three operation?(Choose three.)

  • A. ELSE
  • B. AND
  • C. OR
  • D. FOLLOWED_BY
  • E. NOT

Answer: A,B,E

 

NEW QUESTION 17
An administrator wants to search for events received from Linux and Windows agents.
Which attribute should the administrator use in search filters, to view events received from agents only.

  • A. External Event Receive Protocol
  • B. External Event Receive Raw Logs
  • C. External Event Receive Agents
  • D. Event Received Proto Agents

Answer: B

 

NEW QUESTION 18
Which command displays the Linux agent status?

  • A. Service fortisiem-linux-agent status
  • B. Service fsm-linux-agent status
  • C. Service linux-agent status
  • D. Service Ao-linux-agent status

Answer: A

 

NEW QUESTION 19
If an incident's status is Cleared, what does this mean?

  • A. A security rule issue has been resolved.
  • B. A clear condition set on a rule was satisfied.
  • C. The incident was cleared by an operator.
  • D. Two hours have passed since the incident occurred and the incident has not reoccurred.

Answer: B

 

NEW QUESTION 20
Which three ports can be used to send Syslogs to FortiSIEM? (Choose three.)

  • A. TCP 514
  • B. UDP 514
  • C. UDP 162
  • D. UDP9999
  • E. TCP 1470

Answer: A,B,E

 

NEW QUESTION 21
Which discovery scan type is prone to miss a device, if the device is quiet and the entry foe that device is not present in the ARP table of adjacent devices?

  • A. L2 scan
  • B. Smart scan
  • C. CMDB scan
  • D. Range scan

Answer: B

 

NEW QUESTION 22
What protocol can be used to collect Windows event logs in an agentless method?

  • A. SSH
  • B. SMTP
  • C. SNMP
  • D. WMI

Answer: D

 

NEW QUESTION 23
Refer to the exhibit.

The FortiSIEM administrator is examining events for two devices to investigate an issue However, the administrator is not getting any results from their search.
Based on the selected fillers shown in the exhibit, why is the search returning no results?

  • A. The wrong option is selected in the Operator column
  • B. An invalid IP subnet is typed in the Value column
  • C. Parenthesis are missing
  • D. The wrong boolean operator is selected in the Next column

Answer: D

 

NEW QUESTION 24
Refer to the exhibit.

A FortiSIEM is continuously receiving syslog events from a FortiGate firewall The FortiSlfcM administrator is trying to search the raw event logs for the last two hours that contain the keyword tcp . However, the administrator is getting no results from the search.
Based on the selected filters shown in the exhibit, why are there no search results?

  • A. The administrator selected AND in the Next drop-down list. This is the wrong boolean operator.
  • B. In the Time section, the administrator selected the Relative Last option, and in the drop-down lists, selected 2 and Hours as the lime period The time period should be 24 hours.
  • C. The keyword is case sensitive Instead of typing TCP in the Value field. the administrator should type tcp.
  • D. The administrator selected - in the Operator column That a the wrong operator.

Answer: D

 

NEW QUESTION 25
Refer to the exhibit.

An administrator is trying to identify an issue using an expression bated on the Expression Builder settings shown in the exhibit however, the error message shown in the exhibit indicates that the expression is invalid.
Which is the correct expression?

  • A. COUNT(Matched Events)
  • B. Matched Events(COUNT)
  • C. (COUNT) Matched Events
  • D. Matched Events COUNT()

Answer: A

 

NEW QUESTION 26
Which three ports can be used to send Syslogs to FortiSIEM? (Choose three.)

  • A. UDP 514
  • B. TCP 514
  • C. UDP9999
  • D. TCP 1470
  • E. UDP 162

Answer: A,D,E

 

NEW QUESTION 27
What operating system is FortiSIEM based on?

  • A. Cent OS
  • B. Ubuntu
  • C. RedHat
  • D. Microsoft Windows

Answer: A

 

NEW QUESTION 28
Which protocol is almost always required for the FortiSIEM GUI discovery process?

  • A. SNMP
  • B. WMI
  • C. Syslog
  • D. Telnet

Answer: A

 

NEW QUESTION 29
An administrator defines SMTP as a critical process on a Linux server. If the SMTP process is stopped, FortiSIEM would generate a critical event with which event type?

  • A. Postfix-Mail-Slop
  • B. Generic_SMTP_Process_Exit
  • C. PH_DEV_MON_PROC_STOP
  • D. PH_DEV_MON_SMTP_STOP

Answer: D

 

NEW QUESTION 30
Refer to the exhibit.

A FortiSIEM administrator wants to collect both SIEM event logs and performance and availability metrics (PAM) events from a Microsoft Windows server Which protocol should the administrator select in the Access Protocol drop-down list so that FortiSIEM will collect both SIEM and PAM events?

  • A. TELNET
  • B. LDAP start TLS
  • C. WMI
  • D. LDAPS

Answer: A

 

NEW QUESTION 31
An administrator wants to search for events received from Linux and Windows agents.
Which attribute should the administrator use in search filters, to view events received from agents only.

  • A. External Event Receive Protocol
  • B. External Event Receive Agents
  • C. External Event Receive Raw Logs
  • D. Event Received Proto Agents

Answer: A

 

NEW QUESTION 32
......

Pass Fortinet NSE5_FSM-5.2 Exam Info and Free Practice Test: https://www.actual4dump.com/Fortinet/NSE5_FSM-5.2-actualtests-dumps.html

New 2021 Latest Questions NSE5_FSM-5.2 Dumps - Use Updated Fortinet Exam: https://drive.google.com/open?id=1H6gS8YNeYeDDu7xyI1u01umJrLRf5rRI