NSE5_FSM-5.2 Dumps Updated Jan 29, 2023 Practice Test and 43 unique questions [Q24-Q49]

Share

NSE5_FSM-5.2 Dumps Updated Jan 29, 2023 Practice Test and 43 unique questions

2023 Latest 100% Exam Passing Ratio - NSE5_FSM-5.2 Dumps PDF

NEW QUESTION 24
Which three ports can be used to send Syslogs to FortiSIEM? (Choose three.)

  • A. UDP 514
  • B. UDP 162
  • C. TCP 1470
  • D. TCP 514
  • E. UDP9999

Answer: A,B,C

 

NEW QUESTION 25
Which process converts Raw log data to structured data?

  • A. Data enrichment
  • B. Data parsing
  • C. Data classification
  • D. Data validation

Answer: B

 

NEW QUESTION 26
Refer to the exhibit.

An administrator is trying to identify an issue using an expression bated on the Expression Builder settings shown in the exhibit however, the error message shown in the exhibit indicates that the expression is invalid.
Which is the correct expression?

  • A. Matched Events COUNT()
  • B. COUNT(Matched Events)
  • C. (COUNT) Matched Events
  • D. Matched Events(COUNT)

Answer: B

 

NEW QUESTION 27
Which database is used for storing anomaly data, that is calculated for different parameters, such as traffic and device resource usage running averages, and standard deviation values?

  • A. Profile DB
  • B. CMDB
  • C. Event DB
  • D. SVN DB

Answer: A

 

NEW QUESTION 28
An administrator wants to search for events received from Linux and Windows agents.
Which attribute should the administrator use in search filters, to view events received from agents only.

  • A. External Event Receive Agents
  • B. Event Received Proto Agents
  • C. External Event Receive Raw Logs
  • D. External Event Receive Protocol

Answer: C

 

NEW QUESTION 29
Device discovery information is stored in which database?

  • A. CMDB
  • B. Profile DB
  • C. Event DB
  • D. SVN DB

Answer: A

 

NEW QUESTION 30
Refer to the exhibit.

The FortiSIEM administrator is examining events for two devices to investigate an issue However, the administrator is not getting any results from their search.
Based on the selected fillers shown in the exhibit, why is the search returning no results?

  • A. An invalid IP subnet is typed in the Value column
  • B. The wrong option is selected in the Operator column
  • C. Parenthesis are missing
  • D. The wrong boolean operator is selected in the Next column

Answer: D

 

NEW QUESTION 31
What are the four possible incident status values?

  • A. Active, cleared, cleared manually, system cleared
  • B. Active, auto cleared, manual, false positive
  • C. Active, closed, manual, resolved
  • D. Active, dosed, cleared, open

Answer: C

 

NEW QUESTION 32
Which FortiSIEM components can do performance availability and performance monitoring?

  • A. Collectors only
  • B. Supervisor only
  • C. Supervisor and workers only
  • D. Supervisor, worker, and collector

Answer: D

 

NEW QUESTION 33
If the reported packet loss is between 50% and 98%. which status is assigned to the device in the Availability column of summary dashboard?

  • A. Up status is assigned because of received packets
  • B. Critical status is assigned because of reduction in number of packets received
  • C. Degraded status is assigned because of packet loss
  • D. Down status is assigned because of packet loss.

Answer: C

 

NEW QUESTION 34
An administrator wants to search for events received from Linux and Windows agents.
Which attribute should the administrator use in search filters, to view events received from agents only.

  • A. External Event Receive Agents
  • B. External Event Receive Protocol
  • C. Event Received Proto Agents
  • D. External Event Receive Raw Logs

Answer: B

 

NEW QUESTION 35
What protocol can be used to collect Windows event logs in an agentless method?

  • A. SSH
  • B. SNMP
  • C. SMTP
  • D. WMI

Answer: D

 

NEW QUESTION 36
Refer to the exhibit.

If events are grouped by Reporting IP, Event Type, and user attributes in FortiSIEM, how ,many results will be displayed?

  • A. There results will be displayed.
  • B. Five results will be displayed.
  • C. Seven results will be displayed.
  • D. Unique attribute cannot be grouped.

Answer: B

 

NEW QUESTION 37
Refer to the exhibit.

A FortiSIEM administrator wants to collect both SIEM event logs and performance and availability metrics (PAM) events from a Microsoft Windows server Which protocol should the administrator select in the Access Protocol drop-down list so that FortiSIEM will collect both SIEM and PAM events?

  • A. LDAPS
  • B. TELNET
  • C. WMI
  • D. LDAP start TLS

Answer: B

 

NEW QUESTION 38
Refer to the exhibit.

If events are grouped by Event Receive Time, Reporting IP, and User attributes in FortiSIEM, how many results will be displayed?

  • A. Unique attributes cannot be grouped
  • B. Four results will be displayed
  • C. Two results will be displayed
  • D. Eight results will be displayed

Answer: A

 

NEW QUESTION 39
If an incident's status is Cleared, what does this mean?

  • A. A clear condition set on a rule was satisfied.
  • B. A security rule issue has been resolved.
  • C. Two hours have passed since the incident occurred and the incident has not reoccurred.
  • D. The incident was cleared by an operator.

Answer: A

 

NEW QUESTION 40
Refer to the exhibit.

A FortiSIEM is continuously receiving syslog events from a FortiGate firewall The FortiSlfcM administrator is trying to search the raw event logs for the last two hours that contain the keyword tcp . However, the administrator is getting no results from the search.
Based on the selected filters shown in the exhibit, why are there no search results?

  • A. The keyword is case sensitive Instead of typing TCP in the Value field. the administrator should type tcp.
  • B. The administrator selected - in the Operator column That a the wrong operator.
  • C. The administrator selected AND in the Next drop-down list. This is the wrong boolean operator.
  • D. In the Time section, the administrator selected the Relative Last option, and in the drop-down lists, selected 2 and Hours as the lime period The time period should be 24 hours.

Answer: B

 

NEW QUESTION 41
Refer to the exhibit.

What do the yellow stars listed in the Monitor column indicate?

  • A. A yellow star indicates that a metric was not applied during discovery and, therefore, FortiSEIM was unable to collect data.
  • B. A yellow star indicates that a metric was applied during discovery, but data collection has not started
  • C. A yellow star indicates that a metric was applied during discovery, and data has been collected successfully
  • D. A yellow star indicates that a metric was applied during discovery, but FortiSIEM is unable to collect data.

Answer: A

 

NEW QUESTION 42
Refer to the exhibit.

If events are grouped by Event Receive Time, Reporting IP, and User attributes in FortiSIEM, how many results will be displayed?

  • A. Unique attributes cannot be grouped
  • B. Four results will be displayed
  • C. Two results will be displayed
  • D. Eight results will be displayed

Answer: A

 

NEW QUESTION 43
Which command displays the Linux agent status?

  • A. Service linux-agent status
  • B. Service fsm-linux-agent status
  • C. Service fortisiem-linux-agent status
  • D. Service Ao-linux-agent status

Answer: C

 

NEW QUESTION 44
Which two export methods are available for FortiSIEM analytics results? (Choose two.)

  • A. PDF
  • B. CSV
  • C. HTML
  • D. PNG

Answer: A,B

 

NEW QUESTION 45
What is a prerequisite for a FortiSIEM supervisor with a worker deployment, using the proprietary flat file database?

  • A. The \archive mount must be on a local disk
  • B. The CMDB database must be on NFS
  • C. The event database must be on NFS
  • D. The event database must be on a local disk

Answer: C

 

NEW QUESTION 46
An administrator defines SMTP as a critical process on a Linux server. If the SMTP process is stopped, FortiSIEM would generate a critical event with which event type?

  • A. Generic_SMTP_Process_Exit
  • B. Postfix-Mail-Slop
  • C. PH_DEV_MON_SMTP_STOP
  • D. PH_DEV_MON_PROC_STOP

Answer: D

 

NEW QUESTION 47
If an incident's status is Cleared, what does this mean?

  • A. Two hours have passed since the incident occurred and the incident has not reoccurred.
  • B. A clear condition set on a rule was satisfied.
  • C. A security rule issue has been resolved.
  • D. The incident was cleared by an operator.

Answer: A

 

NEW QUESTION 48
......

Verified NSE5_FSM-5.2 dumps Q&As - 100% Pass from BootcampPDF: https://www.bootcamppdf.com/NSE5_FSM-5.2_exam-dumps.html

Pass Exam With Full Sureness - NSE5_FSM-5.2 Dumps with 43 Questions: https://drive.google.com/open?id=1aqDJAFz1qAraFK19LqULaw7SNQzkGAJq