Prepare NSE5_FSM-5.2 Question Answers - NSE5_FSM-5.2 Exam Dumps [Q22-Q47]

Share

Prepare NSE5_FSM-5.2 Question Answers - NSE5_FSM-5.2 Exam Dumps

Real Fortinet NSE5_FSM-5.2 Exam Questions [Updated 2021]

NEW QUESTION 22
Which command displays the Linux agent status?

  • A. Service fortisiem-linux-agent status
  • B. Service fsm-linux-agent status
  • C. Service linux-agent status
  • D. Service Ao-linux-agent status

Answer: A

 

NEW QUESTION 23
An administrator wants to search for events received from Linux and Windows agents.
Which attribute should the administrator use in search filters, to view events received from agents only.

  • A. External Event Receive Protocol
  • B. External Event Receive Agents
  • C. External Event Receive Raw Logs
  • D. Event Received Proto Agents

Answer: A

 

NEW QUESTION 24
Which database is used for storing anomaly data, that is calculated for different parameters, such as traffic and device resource usage running averages, and standard deviation values?

  • A. SVN DB
  • B. Profile DB
  • C. CMDB
  • D. Event DB

Answer: B

 

NEW QUESTION 25
In the rules engine, which condition instructs FortiSIEM to summarize and count the matching evaluated data?

  • A. Filters
  • B. Time Window
  • C. Group By
  • D. Aggregation

Answer: D

 

NEW QUESTION 26
Refer to the exhibit.

How was the FortiGate device discovered by FortiSIEM?

  • A. Through auto log discovery
  • B. Through syslog discovery
  • C. Using the pull events method
  • D. Through GUI log discovery

Answer: D

 

NEW QUESTION 27
Refer to the exhibit.

Three events are collected over a 10-minutc time period from two servers Server A and Server B.
Based on the settings being used for the rule subpattern. how many incidents will the servers generate?

  • A. Server B will generate one incident and Server A will not generate any incidents
  • B. Server A will generate one incident and Server B will not generate any incidents
  • C. Server A will not generate any incidents and Server B will not generate any incidents
  • D. Server A will generate one incident and Server B wifl generate one incident

Answer: C

 

NEW QUESTION 28
What is a prerequisite for a FortiSIEM supervisor with a worker deployment, using the proprietary flat file database?

  • A. The CMDB database must be on NFS
  • B. The event database must be on a local disk
  • C. The event database must be on NFS
  • D. The \archive mount must be on a local disk

Answer: C

 

NEW QUESTION 29
If an incident's status is Cleared, what does this mean?

  • A. A security rule issue has been resolved.
  • B. A clear condition set on a rule was satisfied.
  • C. The incident was cleared by an operator.
  • D. Two hours have passed since the incident occurred and the incident has not reoccurred.

Answer: B

 

NEW QUESTION 30
If the reported packet loss is between 50% and 98%. which status is assigned to the device in the Availability column of summary dashboard?

  • A. Critical status is assigned because of reduction in number of packets received
  • B. Degraded status is assigned because of packet loss
  • C. Down status is assigned because of packet loss.
  • D. Up status is assigned because of received packets

Answer: B

 

NEW QUESTION 31
A FortiSIEM supervisor at headquarters is struggling to keep up with an increase of EPS (Events Per Second) being reported across the enterprise. What components should an administrator consider deploying to assist the supervisor with processing data?

  • A. Collector
  • B. Agent
  • C. Worker
  • D. Supervisor

Answer: C

 

NEW QUESTION 32
Which process converts Raw log data to structured data?

  • A. Data enrichment
  • B. Data validation
  • C. Data parsing
  • D. Data classification

Answer: C

 

NEW QUESTION 33
What are the four categories of incidents?

  • A. Security, change, high risk, and low risk
  • B. Performance, availability, security, and change
  • C. Performance, devices, high risk, and low risk
  • D. Devices, users, high risk, and low risk

Answer: B

 

NEW QUESTION 34
Which FortiSIEM components are capable of performing device discovery?

  • A. Collector
  • B. Worker
  • C. FortiSIEM Linux agent
  • D. FortiSIEM Windows agent

Answer: A

 

NEW QUESTION 35
Refer to the exhibit.

If events are grouped by Reporting IP, Event Type, and user attributes in FortiSIEM, how ,many results will be displayed?

  • A. Five results will be displayed.
  • B. Unique attribute cannot be grouped.
  • C. Seven results will be displayed.
  • D. There results will be displayed.

Answer: A

 

NEW QUESTION 36
An administrator defines SMTP as a critical process on a Linux server. If the SMTP process is stopped, FortiSIEM would generate a critical event with which event type?

  • A. Postfix-Mail-Slop
  • B. Generic_SMTP_Process_Exit
  • C. PH_DEV_MON_PROC_STOP
  • D. PH_DEV_MON_SMTP_STOP

Answer: D

 

NEW QUESTION 37
Which item is required to register a FortiSIEM appliance license?

  • A. Static MAC address
  • B. Static Hardware ID
  • C. Static storage
  • D. Static IP address

Answer: B

 

NEW QUESTION 38
If a performance rule is triggered repeatedly due to high CPU use. what occurs m the incident table?

  • A. The Incident Count value increases, and the First Seen and Last Seen tomes update
  • B. The incident status changes to Repeated and the First Seen and Last Seen times are updated.
  • C. A new incident is created based on the Rule Frequency value, and the First Seen and Last Seen times are updated
  • D. A new incident is created each time the rule is triggered, and the First Seen and Last Seen times are updated.

Answer: D

 

NEW QUESTION 39
Refer to the exhibit.

The FortiSIEM administrator is examining events for two devices to investigate an issue However, the administrator is not getting any results from their search.
Based on the selected fillers shown in the exhibit, why is the search returning no results?

  • A. The wrong option is selected in the Operator column
  • B. The wrong boolean operator is selected in the Next column
  • C. Parenthesis are missing
  • D. An invalid IP subnet is typed in the Value column

Answer: D

 

NEW QUESTION 40
Refer to the exhibit.

An administrator is trying to identify an issue using an expression bated on the Expression Builder settings shown in the exhibit however, the error message shown in the exhibit indicates that the expression is invalid.
Which is the correct expression?

  • A. COUNT(Matched Events)
  • B. Matched Events(COUNT)
  • C. (COUNT) Matched Events
  • D. Matched Events COUNT()

Answer: A

 

NEW QUESTION 41
Which three ports can be used to send Syslogs to FortiSIEM? (Choose three.)

  • A. UDP 514
  • B. TCP 514
  • C. UDP9999
  • D. TCP 1470
  • E. UDP 162

Answer: A,D,E

 

NEW QUESTION 42
If an incident's status is Cleared, what does this mean?

  • A. A security rule issue has been resolved.
  • B. The incident was cleared by an operator.
  • C. A clear condition set on a rule was satisfied.
  • D. Two hours have passed since the incident occurred and the incident has not reoccurred.

Answer: D

 

NEW QUESTION 43
Refer to the exhibit.

Three events are collected over a 10-minutc time period from two servers Server A and Server B.
Based on the settings being used for the rule subpattern. how many incidents will the servers generate?

  • A. Server B will generate one incident and Server A will not generate any incidents
  • B. Server A will generate one incident and Server B will not generate any incidents
  • C. Server A will not generate any incidents and Server B will not generate any incidents
  • D. Server A will generate one incident and Server B wifl generate one incident

Answer: C

 

NEW QUESTION 44
Refer to the exhibit.

What do the yellow stars listed in the Monitor column indicate?

  • A. A yellow star indicates that a metric was applied during discovery, and data has been collected successfully
  • B. A yellow star indicates that a metric was applied during discovery, but data collection has not started
  • C. A yellow star indicates that a metric was applied during discovery, but FortiSIEM is unable to collect data.
  • D. A yellow star indicates that a metric was not applied during discovery and, therefore, FortiSEIM was unable to collect data.

Answer: D

 

NEW QUESTION 45
An administrator defines SMTP as a critical process on a Linux server. If the SMTP process is stopped, FortiSIEM would generate a critical event with which event type?

  • A. Postfix-Mail-Slop
  • B. PH_DEV_MON_SMTP_STOP
  • C. PH_DEV_MON_PROC_STOP
  • D. Generic_SMTP_Process_Exit

Answer: C

 

NEW QUESTION 46
......

NSE5_FSM-5.2 Exam Dumps Pass with Updated 2021: https://www.exams-boost.com/NSE5_FSM-5.2-valid-materials.html

Free NSE5_FSM-5.2 Exam Dumps to Pass Exam Easily: https://drive.google.com/open?id=1IoM6f1Fe2TSISpu0aCIxaAhYe4SrO6Bt