[Nov 25, 2021] NSE5_FSM-5.2 Exam Dumps - Try Best NSE5_FSM-5.2 Exam Questions - Lead2Passed
Verified NSE5_FSM-5.2 exam dumps Q&As with Correct 43 Questions and Answers
NEW QUESTION 17
Which discovery scan type is prone to miss a device, if the device is quiet and the entry foe that device is not present in the ARP table of adjacent devices?
- A. L2 scan
- B. Smart scan
- C. CMDB scan
- D. Range scan
Answer: B
NEW QUESTION 18
What is a prerequisite for FortiSIEM Linux agent installation?
- A. The auditd service must be installed on the Linux server being monitored
- B. The web server must be installed on the Linux server being monitored
- C. The Linux agent manager server must be installed.
- D. Both the web server and the audit service must be installed on the Linux server being monitored
Answer: D
NEW QUESTION 19
Refer to the exhibit.
How was the FortiGate device discovered by FortiSIEM?
- A. Through auto log discovery
- B. Through syslog discovery
- C. Using the pull events method
- D. Through GUI log discovery
Answer: D
NEW QUESTION 20
Refer to the exhibit.
A FortiSlEM administrator wants to group some attributes for a report, but is not able to do so successfully.
As shown in the exhibit, why are some of the fields highlighted in red?
- A. Unique attributes cannot be grouped.
- B. The attribute COUNT(Matched event) is an invalid expression.
- C. The Event Receive Time attribute is not available for logs.
- D. No RAW Event Log attribute is available for devices.
Answer: A
NEW QUESTION 21
Refer to the exhibit.
A FortiSIEM administrator wants to collect both SIEM event logs and performance and availability metrics (PAM) events from a Microsoft Windows server Which protocol should the administrator select in the Access Protocol drop-down list so that FortiSIEM will collect both SIEM and PAM events?
- A. TELNET
- B. LDAP start TLS
- C. WMI
- D. LDAPS
Answer: A
NEW QUESTION 22
Which process converts Raw log data to structured data?
- A. Data validation
- B. Data enrichment
- C. Data classification
- D. Data parsing
Answer: A
NEW QUESTION 23
If the reported packet loss is between 50% and 98%. which status is assigned to the device in the Availability column of summary dashboard?
- A. Critical status is assigned because of reduction in number of packets received
- B. Degraded status is assigned because of packet loss
- C. Down status is assigned because of packet loss.
- D. Up status is assigned because of received packets
Answer: B
NEW QUESTION 24
What operating system is FortiSIEM based on?
- A. Cent OS
- B. Ubuntu
- C. RedHat
- D. Microsoft Windows
Answer: A
NEW QUESTION 25
To determine SNMP discovery issues, which is the best command from the backend?
- A. ssh
- B. snmptest
- C. phSNMPTest
- D. snmpwalk
Answer: D
NEW QUESTION 26
Refer to the exhibit.
A FortiSIEM is continuously receiving syslog events from a FortiGate firewall The FortiSlfcM administrator is trying to search the raw event logs for the last two hours that contain the keyword tcp . However, the administrator is getting no results from the search.
Based on the selected filters shown in the exhibit, why are there no search results?
- A. The administrator selected AND in the Next drop-down list. This is the wrong boolean operator.
- B. In the Time section, the administrator selected the Relative Last option, and in the drop-down lists, selected 2 and Hours as the lime period The time period should be 24 hours.
- C. The keyword is case sensitive Instead of typing TCP in the Value field. the administrator should type tcp.
- D. The administrator selected - in the Operator column That a the wrong operator.
Answer: D
NEW QUESTION 27
Refer to the exhibit.
If events are grouped by Reporting IP, Event Type, and user attributes in FortiSIEM, how ,many results will be displayed?
- A. Five results will be displayed.
- B. Unique attribute cannot be grouped.
- C. Seven results will be displayed.
- D. There results will be displayed.
Answer: A
NEW QUESTION 28
Refer to the exhibit.
Three events are collected over a 10-minutc time period from two servers Server A and Server B.
Based on the settings being used for the rule subpattern. how many incidents will the servers generate?
- A. Server B will generate one incident and Server A will not generate any incidents
- B. Server A will generate one incident and Server B will not generate any incidents
- C. Server A will not generate any incidents and Server B will not generate any incidents
- D. Server A will generate one incident and Server B wifl generate one incident
Answer: C
NEW QUESTION 29
Which command displays the Linux agent status?
- A. Service fortisiem-linux-agent status
- B. Service fsm-linux-agent status
- C. Service linux-agent status
- D. Service Ao-linux-agent status
Answer: A
NEW QUESTION 30
Refer to the exhibit.
What do the yellow stars listed in the Monitor column indicate?
- A. A yellow star indicates that a metric was applied during discovery, and data has been collected successfully
- B. A yellow star indicates that a metric was not applied during discovery and, therefore, FortiSEIM was unable to collect data.
- C. A yellow star indicates that a metric was applied during discovery, but FortiSIEM is unable to collect data.
- D. A yellow star indicates that a metric was applied during discovery, but data collection has not started
Answer: D
NEW QUESTION 31
Which two export methods are available for FortiSIEM analytics results? (Choose two.)
- A. PNG
- B. HTML
- C. PDF
- D. CSV
Answer: C,D
NEW QUESTION 32
Refer to the exhibit.
How was the FortiGate device discovered by FortiSIEM?
- A. Through auto log discovery
- B. Through syslog discovery
- C. Using the pull events method
- D. Through GUI log discovery
Answer: D
NEW QUESTION 33
......
Fortinet NSE5_FSM-5.2 Test Engine PDF - All Free Dumps: https://www.lead2passed.com/Fortinet/NSE5_FSM-5.2-practice-exam-dumps.html
Get New NSE5_FSM-5.2 Certification – Valid Exam Dumps Questions: https://drive.google.com/open?id=1--Kke4MF1DFcOU8RfHbA4KSoT0k24FKu