[Dec 27, 2021] Fully Updated Dumps PDF - Latest NSE5_FSM-5.2 Exam Questions and Answers [Q15-Q35]

Share

[Dec 27, 2021] Fully Updated Dumps PDF - Latest NSE5_FSM-5.2 Exam Questions and Answers

100% Free NSE5_FSM-5.2 Exam Dumps to Pass Exam Easily from Lead2Passed

NEW QUESTION 15
What are the minimum memory requirements for the FortiSIEM supervisor virtual appliance, when the proprietary flat file database is used?

  • A. 64GB RAM
  • B. 16GB RAM
  • C. 24GB RAM
  • D. 32GB RAM

Answer: D

 

NEW QUESTION 16
If an incident's status is Cleared, what does this mean?

  • A. A clear condition set on a rule was satisfied.
  • B. Two hours have passed since the incident occurred and the incident has not reoccurred.
  • C. The incident was cleared by an operator.
  • D. A security rule issue has been resolved.

Answer: B

 

NEW QUESTION 17
What is the best discovery scan option for a network environment where ping is disabled on all network devices?

  • A. CMDB scan
  • B. L2 scan
  • C. Smart scan
  • D. Range scan

Answer: C

 

NEW QUESTION 18
Which three ports can be used to send Syslogs to FortiSIEM? (Choose three.)

  • A. UDP 514
  • B. UDP9999
  • C. TCP 514
  • D. TCP 1470
  • E. UDP 162

Answer: A,C,D

 

NEW QUESTION 19
To determine whether or not syslog is being received from a network device, which is the best command from the backend?

  • A. tcpdump
  • B. phDeviceTest
  • C. phSyslogRecorder
  • D. netcat

Answer: A

 

NEW QUESTION 20
Refer to the exhibit.

How was the FortiGate device discovered by FortiSIEM?

  • A. Through GUI log discovery
  • B. Through auto log discovery
  • C. Using the pull events method
  • D. Through syslog discovery

Answer: A

 

NEW QUESTION 21
What is a prerequisite for FortiSIEM Linux agent installation?

  • A. The auditd service must be installed on the Linux server being monitored
  • B. The Linux agent manager server must be installed.
  • C. Both the web server and the audit service must be installed on the Linux server being monitored
  • D. The web server must be installed on the Linux server being monitored

Answer: C

 

NEW QUESTION 22
To determine SNMP discovery issues, which is the best command from the backend?

  • A. phSNMPTest
  • B. snmptest
  • C. ssh
  • D. snmpwalk

Answer: D

 

NEW QUESTION 23
Refer to the exhibit.

If events are grouped by Event Receive Time, Reporting IP, and User attributes in FortiSIEM, how many results will be displayed?

  • A. Four results will be displayed
  • B. Eight results will be displayed
  • C. Unique attributes cannot be grouped
  • D. Two results will be displayed

Answer: C

 

NEW QUESTION 24
Refer to the exhibit.

The FortiSIEM administrator is examining events for two devices to investigate an issue However, the administrator is not getting any results from their search.
Based on the selected fillers shown in the exhibit, why is the search returning no results?

  • A. Parenthesis are missing
  • B. The wrong boolean operator is selected in the Next column
  • C. An invalid IP subnet is typed in the Value column
  • D. The wrong option is selected in the Operator column

Answer: C

 

NEW QUESTION 25
If a performance rule is triggered repeatedly due to high CPU use. what occurs m the incident table?

  • A. A new incident is created based on the Rule Frequency value, and the First Seen and Last Seen times are updated
  • B. A new incident is created each time the rule is triggered, and the First Seen and Last Seen times are updated.
  • C. The Incident Count value increases, and the First Seen and Last Seen tomes update
  • D. The incident status changes to Repeated and the First Seen and Last Seen times are updated.

Answer: B

 

NEW QUESTION 26
Refer to the exhibit.

The FortiSIEM administrator is examining events for two devices to investigate an issue However, the administrator is not getting any results from their search.
Based on the selected fillers shown in the exhibit, why is the search returning no results?

  • A. An invalid IP subnet is typed in the Value column
  • B. Parenthesis are missing
  • C. The wrong boolean operator is selected in the Next column
  • D. The wrong option is selected in the Operator column

Answer: C

 

NEW QUESTION 27
In the advanced analytical rules engine in FortiSIEM, multiple subpatterms can be referenced using which three operation?(Choose three.)

  • A. FOLLOWED_BY
  • B. ELSE
  • C. OR
  • D. AND
  • E. NOT

Answer: B,D,E

 

NEW QUESTION 28
Which database is used for storing anomaly data, that is calculated for different parameters, such as traffic and device resource usage running averages, and standard deviation values?

  • A. CMDB
  • B. SVN DB
  • C. Event DB
  • D. Profile DB

Answer: D

 

NEW QUESTION 29
Which three ports can be used to send Syslogs to FortiSIEM? (Choose three.)

  • A. TCP 514
  • B. UDP 514
  • C. UDP9999
  • D. UDP 162
  • E. TCP 1470

Answer: B,D,E

 

NEW QUESTION 30
If an incident's status is Cleared, what does this mean?

  • A. A clear condition set on a rule was satisfied.
  • B. The incident was cleared by an operator.
  • C. Two hours have passed since the incident occurred and the incident has not reoccurred.
  • D. A security rule issue has been resolved.

Answer: A

 

NEW QUESTION 31
What are the minimum memory requirements for the FortiSIEM supervisor virtual appliance, when the proprietary flat file database is used?

  • A. 64GB RAM
  • B. 16GB RAM
  • C. 32GB RAM
  • D. 24GB RAM

Answer: D

 

NEW QUESTION 32
What protocol can be used to collect Windows event logs in an agentless method?

  • A. WMI
  • B. SSH
  • C. SMTP
  • D. SNMP

Answer: A

 

NEW QUESTION 33
Refer to the exhibit.

A FortiSlEM administrator wants to group some attributes for a report, but is not able to do so successfully.
As shown in the exhibit, why are some of the fields highlighted in red?

  • A. The Event Receive Time attribute is not available for logs.
  • B. No RAW Event Log attribute is available for devices.
  • C. Unique attributes cannot be grouped.
  • D. The attribute COUNT(Matched event) is an invalid expression.

Answer: C

 

NEW QUESTION 34
In the rules engine, which condition instructs FortiSIEM to summarize and count the matching evaluated data?

  • A. Time Window
  • B. Aggregation
  • C. Filters
  • D. Group By

Answer: D

 

NEW QUESTION 35
......

Free NSE5_FSM-5.2 Exam Questions NSE5_FSM-5.2 Actual Free Exam Questions: https://www.lead2passed.com/Fortinet/NSE5_FSM-5.2-practice-exam-dumps.html

Verified NSE5_FSM-5.2 dumps and 43 unique questions: https://drive.google.com/open?id=1--Kke4MF1DFcOU8RfHbA4KSoT0k24FKu