[2023] Pass Key features of NSE5_FSM-5.2 Course with Updated 43 Questions [Q19-Q39]

Share

[2023] Pass Key features of NSE5_FSM-5.2 Course with Updated 43 Questions

NSE5_FSM-5.2 Sample Practice Exam Questions 2023 Updated Verified

NEW QUESTION 19
Which three ports can be used to send Syslogs to FortiSIEM? (Choose three.)

  • A. TCP 514
  • B. UDP9999
  • C. UDP 514
  • D. TCP 1470
  • E. UDP 162

Answer: A,C,D

 

NEW QUESTION 20
If a performance rule is triggered repeatedly due to high CPU use. what occurs m the incident table?

  • A. The Incident Count value increases, and the First Seen and Last Seen tomes update
  • B. The incident status changes to Repeated and the First Seen and Last Seen times are updated.
  • C. A new incident is created based on the Rule Frequency value, and the First Seen and Last Seen times are updated
  • D. A new incident is created each time the rule is triggered, and the First Seen and Last Seen times are updated.

Answer: D

 

NEW QUESTION 21
Refer to the exhibit.

What do the yellow stars listed in the Monitor column indicate?

  • A. A yellow star indicates that a metric was applied during discovery, but FortiSIEM is unable to collect data.
  • B. A yellow star indicates that a metric was applied during discovery, and data has been collected successfully
  • C. A yellow star indicates that a metric was not applied during discovery and, therefore, FortiSEIM was unable to collect data.
  • D. A yellow star indicates that a metric was applied during discovery, but data collection has not started

Answer: D

 

NEW QUESTION 22
In the rules engine, which condition instructs FortiSIEM to summarize and count the matching evaluated data?

  • A. Filters
  • B. Aggregation
  • C. Group By
  • D. Time Window

Answer: C

 

NEW QUESTION 23
Refer to the exhibit.

A FortiSIEM administrator wants to collect both SIEM event logs and performance and availability metrics (PAM) events from a Microsoft Windows server Which protocol should the administrator select in the Access Protocol drop-down list so that FortiSIEM will collect both SIEM and PAM events?

  • A. LDAPS
  • B. LDAP start TLS
  • C. TELNET
  • D. WMI

Answer: C

 

NEW QUESTION 24
Refer to the exhibit.

Three events are collected over a 10-minutc time period from two servers Server A and Server B.
Based on the settings being used for the rule subpattern. how many incidents will the servers generate?

  • A. Server A will generate one incident and Server B will not generate any incidents
  • B. Server A will generate one incident and Server B wifl generate one incident
  • C. Server B will generate one incident and Server A will not generate any incidents
  • D. Server A will not generate any incidents and Server B will not generate any incidents

Answer: D

 

NEW QUESTION 25
Refer to the exhibit.

If events are grouped by Reporting IP, Event Type, and user attributes in FortiSIEM, how ,many results will be displayed?

  • A. There results will be displayed.
  • B. Unique attribute cannot be grouped.
  • C. Five results will be displayed.
  • D. Seven results will be displayed.

Answer: C

 

NEW QUESTION 26
What are the four categories of incidents?

  • A. Performance, devices, high risk, and low risk
  • B. Devices, users, high risk, and low risk
  • C. Security, change, high risk, and low risk
  • D. Performance, availability, security, and change

Answer: D

 

NEW QUESTION 27
Which process converts Raw log data to structured data?

  • A. Data classification
  • B. Data validation
  • C. Data parsing
  • D. Data enrichment

Answer: B

 

NEW QUESTION 28
Refer to the exhibit.

A FortiSIEM is continuously receiving syslog events from a FortiGate firewall The FortiSlfcM administrator is trying to search the raw event logs for the last two hours that contain the keyword tcp . However, the administrator is getting no results from the search.
Based on the selected filters shown in the exhibit, why are there no search results?

  • A. The administrator selected - in the Operator column That a the wrong operator.
  • B. The administrator selected AND in the Next drop-down list. This is the wrong boolean operator.
  • C. In the Time section, the administrator selected the Relative Last option, and in the drop-down lists, selected 2 and Hours as the lime period The time period should be 24 hours.
  • D. The keyword is case sensitive Instead of typing TCP in the Value field. the administrator should type tcp.

Answer: A

 

NEW QUESTION 29
Refer to the exhibit.

How was the FortiGate device discovered by FortiSIEM?

  • A. Through syslog discovery
  • B. Through GUI log discovery
  • C. Using the pull events method
  • D. Through auto log discovery

Answer: B

 

NEW QUESTION 30
A FortiSIEM administrator wants to restrict a network administrator to running searches for only firewall devices. Under role management, which option does the FortiSIEM administrator need to configure to achieve this scenario?

  • A. Data Conditions
  • B. UI Access
  • C. CMDB Report Conditions

Answer: A

 

NEW QUESTION 31
Which protocol is almost always required for the FortiSIEM GUI discovery process?

  • A. Telnet
  • B. WMI
  • C. SNMP
  • D. Syslog

Answer: C

 

NEW QUESTION 32
What is the best discovery scan option for a network environment where ping is disabled on all network devices?

  • A. L2 scan
  • B. Range scan
  • C. CMDB scan
  • D. Smart scan

Answer: D

 

NEW QUESTION 33
If the reported packet loss is between 50% and 98%. which status is assigned to the device in the Availability column of summary dashboard?

  • A. Down status is assigned because of packet loss.
  • B. Up status is assigned because of received packets
  • C. Degraded status is assigned because of packet loss
  • D. Critical status is assigned because of reduction in number of packets received

Answer: C

 

NEW QUESTION 34
Which discovery scan type is prone to miss a device, if the device is quiet and the entry foe that device is not present in the ARP table of adjacent devices?

  • A. L2 scan
  • B. Range scan
  • C. CMDB scan
  • D. Smart scan

Answer: D

 

NEW QUESTION 35
Refer to the exhibit.

A FortiSlEM administrator wants to group some attributes for a report, but is not able to do so successfully.
As shown in the exhibit, why are some of the fields highlighted in red?

  • A. The Event Receive Time attribute is not available for logs.
  • B. The attribute COUNT(Matched event) is an invalid expression.
  • C. No RAW Event Log attribute is available for devices.
  • D. Unique attributes cannot be grouped.

Answer: D

 

NEW QUESTION 36
Refer to the exhibit.

What do the yellow stars listed in the Monitor column indicate?

  • A. A yellow star indicates that a metric was applied during discovery, but data collection has not started
  • B. A yellow star indicates that a metric was not applied during discovery and, therefore, FortiSEIM was unable to collect data.
  • C. A yellow star indicates that a metric was applied during discovery, but FortiSIEM is unable to collect data.
  • D. A yellow star indicates that a metric was applied during discovery, and data has been collected successfully

Answer: B

 

NEW QUESTION 37
Refer to the exhibit.

The FortiSIEM administrator is examining events for two devices to investigate an issue However, the administrator is not getting any results from their search.
Based on the selected fillers shown in the exhibit, why is the search returning no results?

  • A. The wrong option is selected in the Operator column
  • B. An invalid IP subnet is typed in the Value column
  • C. The wrong boolean operator is selected in the Next column
  • D. Parenthesis are missing

Answer: C

 

NEW QUESTION 38
Refer to the exhibit.

An administrator is trying to identify an issue using an expression bated on the Expression Builder settings shown in the exhibit however, the error message shown in the exhibit indicates that the expression is invalid.
Which is the correct expression?

  • A. Matched Events COUNT()
  • B. COUNT(Matched Events)
  • C. (COUNT) Matched Events
  • D. Matched Events(COUNT)

Answer: B

 

NEW QUESTION 39
......

The New NSE5_FSM-5.2 2023 Updated Verified Study Guides & Best Courses: https://testking.itexamdownload.com/NSE5_FSM-5.2-valid-questions.html