[Q19-Q43] Updated Jul-2022 Exam Engine or PDF for the Fortinet NSE5_FSM-5.2 test to help you quickly prepare for the Fortinet exam!

Share

Updated Jul-2022 Test Engine or PDF for the Fortinet NSE5_FSM-5.2 test to help you quickly prepare for the Fortinet exam!

Full NSE5_FSM-5.2 Practice Test and 43 unique questions with explanations waiting just for you, get it now!

NEW QUESTION 19
Refer to the exhibit.

An administrator is trying to identify an issue using an expression bated on the Expression Builder settings shown in the exhibit however, the error message shown in the exhibit indicates that the expression is invalid.
Which is the correct expression?

  • A. Matched Events COUNT()
  • B. Matched Events(COUNT)
  • C. COUNT(Matched Events)
  • D. (COUNT) Matched Events

Answer: C

 

NEW QUESTION 20
In FotiSlEM enterprise licensing mode, if the link between the collector and data center FortiSlEM cluster a down what happens?

  • A. The collector drops incoming events like syslog. but slops performance collection
  • B. The collector processes stop, and events are dropped
  • C. The collector continues performance collection of devices, but stops receiving syslog
  • D. The collector buffers events

Answer: B

 

NEW QUESTION 21
Refer to the exhibit.

Three events are collected over a 10-minutc time period from two servers Server A and Server B.
Based on the settings being used for the rule subpattern. how many incidents will the servers generate?

  • A. Server B will generate one incident and Server A will not generate any incidents
  • B. Server A will generate one incident and Server B will not generate any incidents
  • C. Server A will not generate any incidents and Server B will not generate any incidents
  • D. Server A will generate one incident and Server B wifl generate one incident

Answer: C

 

NEW QUESTION 22
Refer to the exhibit.

An administrator is trying to identify an issue using an expression bated on the Expression Builder settings shown in the exhibit however, the error message shown in the exhibit indicates that the expression is invalid.
Which is the correct expression?

  • A. Matched Events COUNT()
  • B. Matched Events(COUNT)
  • C. COUNT(Matched Events)
  • D. (COUNT) Matched Events

Answer: C

 

NEW QUESTION 23
Which three ports can be used to send Syslogs to FortiSIEM? (Choose three.)

  • A. UDP 514
  • B. TCP 514
  • C. UDP 162
  • D. TCP 1470
  • E. UDP9999

Answer: A,B,D

 

NEW QUESTION 24
Refer to the exhibit.

A FortiSIEM administrator wants to collect both SIEM event logs and performance and availability metrics (PAM) events from a Microsoft Windows server Which protocol should the administrator select in the Access Protocol drop-down list so that FortiSIEM will collect both SIEM and PAM events?

  • A. LDAP start TLS
  • B. LDAPS
  • C. WMI
  • D. TELNET

Answer: D

 

NEW QUESTION 25
Refer to the exhibit.

What do the yellow stars listed in the Monitor column indicate?

  • A. A yellow star indicates that a metric was applied during discovery, but FortiSIEM is unable to collect data.
  • B. A yellow star indicates that a metric was applied during discovery, and data has been collected successfully
  • C. A yellow star indicates that a metric was not applied during discovery and, therefore, FortiSEIM was unable to collect data.
  • D. A yellow star indicates that a metric was applied during discovery, but data collection has not started

Answer: D

 

NEW QUESTION 26
In the rules engine, which condition instructs FortiSIEM to summarize and count the matching evaluated data?

  • A. Filters
  • B. Time Window
  • C. Aggregation
  • D. Group By

Answer: D

 

NEW QUESTION 27
Which two FortiSIEM components work together to provide real-time event correlation?

  • A. Supervisor and collector
  • B. Worker and collector
  • C. Supervisor and worker
  • D. Collector and Windows agent

Answer: A

 

NEW QUESTION 28
Refer to the exhibit.

The FortiSIEM administrator is examining events for two devices to investigate an issue However, the administrator is not getting any results from their search.
Based on the selected fillers shown in the exhibit, why is the search returning no results?

  • A. The wrong boolean operator is selected in the Next column
  • B. The wrong option is selected in the Operator column
  • C. Parenthesis are missing
  • D. An invalid IP subnet is typed in the Value column

Answer: A

 

NEW QUESTION 29
An administrator defines SMTP as a critical process on a Linux server. If the SMTP process is stopped, FortiSIEM would generate a critical event with which event type?

  • A. Generic_SMTP_Process_Exit
  • B. PH_DEV_MON_SMTP_STOP
  • C. Postfix-Mail-Slop
  • D. PH_DEV_MON_PROC_STOP

Answer: B

 

NEW QUESTION 30
A FortiSIEM supervisor at headquarters is struggling to keep up with an increase of EPS (Events Per Second) being reported across the enterprise. What components should an administrator consider deploying to assist the supervisor with processing data?

  • A. Supervisor
  • B. Worker
  • C. Collector
  • D. Agent

Answer: B

 

NEW QUESTION 31
Which database is used for storing anomaly data, that is calculated for different parameters, such as traffic and device resource usage running averages, and standard deviation values?

  • A. CMDB
  • B. Event DB
  • C. Profile DB
  • D. SVN DB

Answer: C

 

NEW QUESTION 32
An administrator wants to search for events received from Linux and Windows agents.
Which attribute should the administrator use in search filters, to view events received from agents only.

  • A. External Event Receive Agents
  • B. Event Received Proto Agents
  • C. External Event Receive Protocol
  • D. External Event Receive Raw Logs

Answer: D

 

NEW QUESTION 33
What are the four possible incident status values?

  • A. Active, closed, manual, resolved
  • B. Active, auto cleared, manual, false positive
  • C. Active, cleared, cleared manually, system cleared
  • D. Active, dosed, cleared, open

Answer: A

 

NEW QUESTION 34
Which database is used for storing anomaly data, that is calculated for different parameters, such as traffic and device resource usage running averages, and standard deviation values?

  • A. CMDB
  • B. Profile DB
  • C. Event DB
  • D. SVN DB

Answer: C

 

NEW QUESTION 35
Refer to the exhibit.

If events are grouped by Event Receive Time, Reporting IP, and User attributes in FortiSIEM, how many results will be displayed?

  • A. Unique attributes cannot be grouped
  • B. Four results will be displayed
  • C. Eight results will be displayed
  • D. Two results will be displayed

Answer: A

 

NEW QUESTION 36
Which item is required to register a FortiSIEM appliance license?

  • A. Static storage
  • B. Static MAC address
  • C. Static IP address
  • D. Static Hardware ID

Answer: D

 

NEW QUESTION 37
Refer to the exhibit.

A FortiSlEM administrator wants to group some attributes for a report, but is not able to do so successfully.
As shown in the exhibit, why are some of the fields highlighted in red?

  • A. The attribute COUNT(Matched event) is an invalid expression.
  • B. The Event Receive Time attribute is not available for logs.
  • C. No RAW Event Log attribute is available for devices.
  • D. Unique attributes cannot be grouped.

Answer: D

 

NEW QUESTION 38
What is a prerequisite for FortiSIEM Linux agent installation?

  • A. The web server must be installed on the Linux server being monitored
  • B. The Linux agent manager server must be installed.
  • C. The auditd service must be installed on the Linux server being monitored
  • D. Both the web server and the audit service must be installed on the Linux server being monitored

Answer: D

 

NEW QUESTION 39
Refer to the exhibit.

A FortiSIEM administrator wants to collect both SIEM event logs and performance and availability metrics (PAM) events from a Microsoft Windows server Which protocol should the administrator select in the Access Protocol drop-down list so that FortiSIEM will collect both SIEM and PAM events?

  • A. LDAP start TLS
  • B. LDAPS
  • C. WMI
  • D. TELNET

Answer: D

 

NEW QUESTION 40
Refer to the exhibit.

The FortiSIEM administrator is examining events for two devices to investigate an issue However, the administrator is not getting any results from their search.
Based on the selected fillers shown in the exhibit, why is the search returning no results?

  • A. An invalid IP subnet is typed in the Value column
  • B. The wrong option is selected in the Operator column
  • C. Parenthesis are missing
  • D. The wrong boolean operator is selected in the Next column

Answer: A

 

NEW QUESTION 41
What are the minimum memory requirements for the FortiSIEM supervisor virtual appliance, when the proprietary flat file database is used?

  • A. 32GB RAM
  • B. 16GB RAM
  • C. 24GB RAM
  • D. 64GB RAM

Answer: C

 

NEW QUESTION 42
To determine whether or not syslog is being received from a network device, which is the best command from the backend?

  • A. netcat
  • B. phSyslogRecorder
  • C. phDeviceTest
  • D. tcpdump

Answer: D

 

NEW QUESTION 43
......

Full NSE5_FSM-5.2 Practice Test and 43 unique questions with explanations waiting just for you, get it now: https://actualtests.trainingquiz.com/NSE5_FSM-5.2-training-materials.html