Latest [Sep 27, 2022] Fortinet NSE5_FSM-5.2 Exam Practice Test To Gain Brilliante Result
Take a Leap Forward in Your Career by Earning Fortinet NSE5_FSM-5.2
NEW QUESTION 20
What is a prerequisite for a FortiSIEM supervisor with a worker deployment, using the proprietary flat file database?
- A. The \archive mount must be on a local disk
- B. The event database must be on NFS
- C. The CMDB database must be on NFS
- D. The event database must be on a local disk
Answer: B
NEW QUESTION 21
Which two FortiSIEM components work together to provide real-time event correlation?
- A. Supervisor and collector
- B. Collector and Windows agent
- C. Supervisor and worker
- D. Worker and collector
Answer: A
NEW QUESTION 22
Refer to the exhibit.
An administrator is trying to identify an issue using an expression bated on the Expression Builder settings shown in the exhibit however, the error message shown in the exhibit indicates that the expression is invalid.
Which is the correct expression?
- A. Matched Events(COUNT)
- B. (COUNT) Matched Events
- C. Matched Events COUNT()
- D. COUNT(Matched Events)
Answer: D
NEW QUESTION 23
Refer to the exhibit.
If events are grouped by Reporting IP, Event Type, and user attributes in FortiSIEM, how ,many results will be displayed?
- A. Unique attribute cannot be grouped.
- B. Seven results will be displayed.
- C. Five results will be displayed.
- D. There results will be displayed.
Answer: C
NEW QUESTION 24
Refer to the exhibit.
A FortiSlEM administrator wants to group some attributes for a report, but is not able to do so successfully.
As shown in the exhibit, why are some of the fields highlighted in red?
- A. The attribute COUNT(Matched event) is an invalid expression.
- B. Unique attributes cannot be grouped.
- C. The Event Receive Time attribute is not available for logs.
- D. No RAW Event Log attribute is available for devices.
Answer: B
NEW QUESTION 25
To determine SNMP discovery issues, which is the best command from the backend?
- A. snmpwalk
- B. phSNMPTest
- C. snmptest
- D. ssh
Answer: A
NEW QUESTION 26
If an incident's status is Cleared, what does this mean?
- A. Two hours have passed since the incident occurred and the incident has not reoccurred.
- B. A security rule issue has been resolved.
- C. The incident was cleared by an operator.
- D. A clear condition set on a rule was satisfied.
Answer: D
NEW QUESTION 27
An administrator defines SMTP as a critical process on a Linux server. If the SMTP process is stopped, FortiSIEM would generate a critical event with which event type?
- A. PH_DEV_MON_SMTP_STOP
- B. Generic_SMTP_Process_Exit
- C. PH_DEV_MON_PROC_STOP
- D. Postfix-Mail-Slop
Answer: C
NEW QUESTION 28
Which three ports can be used to send Syslogs to FortiSIEM? (Choose three.)
- A. TCP 514
- B. UDP 514
- C. UDP 162
- D. TCP 1470
- E. UDP9999
Answer: A,B,D
NEW QUESTION 29
An administrator wants to search for events received from Linux and Windows agents.
Which attribute should the administrator use in search filters, to view events received from agents only.
- A. Event Received Proto Agents
- B. External Event Receive Raw Logs
- C. External Event Receive Protocol
- D. External Event Receive Agents
Answer: B
NEW QUESTION 30
Which database is used for storing anomaly data, that is calculated for different parameters, such as traffic and device resource usage running averages, and standard deviation values?
- A. Event DB
- B. Profile DB
- C. SVN DB
- D. CMDB
Answer: A
NEW QUESTION 31
What is a prerequisite for FortiSIEM Linux agent installation?
- A. The Linux agent manager server must be installed.
- B. Both the web server and the audit service must be installed on the Linux server being monitored
- C. The web server must be installed on the Linux server being monitored
- D. The auditd service must be installed on the Linux server being monitored
Answer: B
NEW QUESTION 32
If a performance rule is triggered repeatedly due to high CPU use. what occurs m the incident table?
- A. A new incident is created based on the Rule Frequency value, and the First Seen and Last Seen times are updated
- B. A new incident is created each time the rule is triggered, and the First Seen and Last Seen times are updated.
- C. The Incident Count value increases, and the First Seen and Last Seen tomes update
- D. The incident status changes to Repeated and the First Seen and Last Seen times are updated.
Answer: B
NEW QUESTION 33
An administrator defines SMTP as a critical process on a Linux server. If the SMTP process is stopped, FortiSIEM would generate a critical event with which event type?
- A. PH_DEV_MON_PROC_STOP
- B. Generic_SMTP_Process_Exit
- C. PH_DEV_MON_SMTP_STOP
- D. Postfix-Mail-Slop
Answer: C
NEW QUESTION 34
Refer to the exhibit.
How was the FortiGate device discovered by FortiSIEM?
- A. Through GUI log discovery
- B. Through syslog discovery
- C. Through auto log discovery
- D. Using the pull events method
Answer: A
NEW QUESTION 35
Which three ports can be used to send Syslogs to FortiSIEM? (Choose three.)
- A. TCP 514
- B. UDP 514
- C. UDP 162
- D. TCP 1470
- E. UDP9999
Answer: B,C,D
NEW QUESTION 36
Which database is used for storing anomaly data, that is calculated for different parameters, such as traffic and device resource usage running averages, and standard deviation values?
- A. Profile DB
- B. SVN DB
- C. CMDB
- D. Event DB
Answer: A
NEW QUESTION 37
Refer to the exhibit.
A FortiSIEM is continuously receiving syslog events from a FortiGate firewall The FortiSlfcM administrator is trying to search the raw event logs for the last two hours that contain the keyword tcp . However, the administrator is getting no results from the search.
Based on the selected filters shown in the exhibit, why are there no search results?
- A. The administrator selected AND in the Next drop-down list. This is the wrong boolean operator.
- B. The administrator selected - in the Operator column That a the wrong operator.
- C. In the Time section, the administrator selected the Relative Last option, and in the drop-down lists, selected 2 and Hours as the lime period The time period should be 24 hours.
- D. The keyword is case sensitive Instead of typing TCP in the Value field. the administrator should type tcp.
Answer: B
NEW QUESTION 38
An administrator wants to search for events received from Linux and Windows agents.
Which attribute should the administrator use in search filters, to view events received from agents only.
- A. Event Received Proto Agents
- B. External Event Receive Protocol
- C. External Event Receive Raw Logs
- D. External Event Receive Agents
Answer: B
NEW QUESTION 39
Which FortiSIEM components can do performance availability and performance monitoring?
- A. Supervisor and workers only
- B. Supervisor only
- C. Collectors only
- D. Supervisor, worker, and collector
Answer: D
NEW QUESTION 40
Refer to the exhibit.
If events are grouped by Event Receive Time, Reporting IP, and User attributes in FortiSIEM, how many results will be displayed?
- A. Unique attributes cannot be grouped
- B. Four results will be displayed
- C. Eight results will be displayed
- D. Two results will be displayed
Answer: A
NEW QUESTION 41
To determine whether or not syslog is being received from a network device, which is the best command from the backend?
- A. phSyslogRecorder
- B. phDeviceTest
- C. tcpdump
- D. netcat
Answer: C
NEW QUESTION 42
Which two export methods are available for FortiSIEM analytics results? (Choose two.)
- A. PNG
- B. HTML
- C. PDF
- D. CSV
Answer: C,D
NEW QUESTION 43
In the rules engine, which condition instructs FortiSIEM to summarize and count the matching evaluated data?
- A. Aggregation
- B. Time Window
- C. Group By
- D. Filters
Answer: C
NEW QUESTION 44
......
Authentic Best resources for NSE5_FSM-5.2 Online Practice Exam: https://www.passtestking.com/Fortinet/NSE5_FSM-5.2-practice-exam-dumps.html
Updates Up to 365 days On Developing NSE5_FSM-5.2 Braindumps: https://drive.google.com/open?id=1in2nd5yRaMx7Gt3b64KOPbuc5slVQbBL