[2021] Use Valid Exam NSE5_FSM-5.2 by PremiumVCEDump Books For Free Website [Q13-Q28]

Share

[2021] Use Valid Exam NSE5_FSM-5.2 by PremiumVCEDump Books For Free Website

Free NSE 5 Network Security Analyst NSE5_FSM-5.2 Official Cert Guide PDF Download

NEW QUESTION 13
To determine whether or not syslog is being received from a network device, which is the best command from the backend?

  • A. tcpdump
  • B. phDeviceTest
  • C. phSyslogRecorder
  • D. netcat

Answer: A

 

NEW QUESTION 14
Refer to the exhibit.

If events are grouped by Event Receive Time, Reporting IP, and User attributes in FortiSIEM, how many results will be displayed?

  • A. Four results will be displayed
  • B. Eight results will be displayed
  • C. Unique attributes cannot be grouped
  • D. Two results will be displayed

Answer: C

 

NEW QUESTION 15
What is a prerequisite for FortiSIEM Linux agent installation?

  • A. The auditd service must be installed on the Linux server being monitored
  • B. The Linux agent manager server must be installed.
  • C. Both the web server and the audit service must be installed on the Linux server being monitored
  • D. The web server must be installed on the Linux server being monitored

Answer: C

 

NEW QUESTION 16
An administrator wants to search for events received from Linux and Windows agents.
Which attribute should the administrator use in search filters, to view events received from agents only.

  • A. External Event Receive Raw Logs
  • B. External Event Receive Protocol
  • C. External Event Receive Agents
  • D. Event Received Proto Agents

Answer: A

 

NEW QUESTION 17
What protocol can be used to collect Windows event logs in an agentless method?

  • A. WMI
  • B. SSH
  • C. SMTP
  • D. SNMP

Answer: A

 

NEW QUESTION 18
If an incident's status is Cleared, what does this mean?

  • A. A clear condition set on a rule was satisfied.
  • B. Two hours have passed since the incident occurred and the incident has not reoccurred.
  • C. The incident was cleared by an operator.
  • D. A security rule issue has been resolved.

Answer: B

 

NEW QUESTION 19
Refer to the exhibit.

A FortiSIEM is continuously receiving syslog events from a FortiGate firewall The FortiSlfcM administrator is trying to search the raw event logs for the last two hours that contain the keyword tcp . However, the administrator is getting no results from the search.
Based on the selected filters shown in the exhibit, why are there no search results?

  • A. The keyword is case sensitive Instead of typing TCP in the Value field. the administrator should type tcp.
  • B. The administrator selected - in the Operator column That a the wrong operator.
  • C. The administrator selected AND in the Next drop-down list. This is the wrong boolean operator.
  • D. In the Time section, the administrator selected the Relative Last option, and in the drop-down lists, selected 2 and Hours as the lime period The time period should be 24 hours.

Answer: B

 

NEW QUESTION 20
Which two FortiSIEM components work together to provide real-time event correlation?

  • A. Worker and collector
  • B. Supervisor and collector
  • C. Collector and Windows agent
  • D. Supervisor and worker

Answer: B

 

NEW QUESTION 21
An administrator defines SMTP as a critical process on a Linux server. If the SMTP process is stopped, FortiSIEM would generate a critical event with which event type?

  • A. PH_DEV_MON_PROC_STOP
  • B. Postfix-Mail-Slop
  • C. PH_DEV_MON_SMTP_STOP
  • D. Generic_SMTP_Process_Exit

Answer: A

 

NEW QUESTION 22
Refer to the exhibit.

What do the yellow stars listed in the Monitor column indicate?

  • A. A yellow star indicates that a metric was applied during discovery, and data has been collected successfully
  • B. A yellow star indicates that a metric was applied during discovery, but FortiSIEM is unable to collect data.
  • C. A yellow star indicates that a metric was not applied during discovery and, therefore, FortiSEIM was unable to collect data.
  • D. A yellow star indicates that a metric was applied during discovery, but data collection has not started

Answer: C

 

NEW QUESTION 23
Which discovery scan type is prone to miss a device, if the device is quiet and the entry foe that device is not present in the ARP table of adjacent devices?

  • A. CMDB scan
  • B. L2 scan
  • C. Smart scan
  • D. Range scan

Answer: C

 

NEW QUESTION 24
A FortiSIEM administrator wants to restrict a network administrator to running searches for only firewall devices. Under role management, which option does the FortiSIEM administrator need to configure to achieve this scenario?

  • A. CMDB Report Conditions
  • B. UI Access
  • C. Data Conditions

Answer: C

 

NEW QUESTION 25
Which command displays the Linux agent status?

  • A. Service fsm-linux-agent status
  • B. Service fortisiem-linux-agent status
  • C. Service linux-agent status
  • D. Service Ao-linux-agent status

Answer: B

 

NEW QUESTION 26
Refer to the exhibit.

How was the FortiGate device discovered by FortiSIEM?

  • A. Through GUI log discovery
  • B. Through auto log discovery
  • C. Using the pull events method
  • D. Through syslog discovery

Answer: A

 

NEW QUESTION 27
In FotiSlEM enterprise licensing mode, if the link between the collector and data center FortiSlEM cluster a down what happens?

  • A. The collector continues performance collection of devices, but stops receiving syslog
  • B. The collector buffers events
  • C. The collector processes stop, and events are dropped
  • D. The collector drops incoming events like syslog. but slops performance collection

Answer: C

 

NEW QUESTION 28
......

Fortinet NSE5_FSM-5.2 Official Cert Guide PDF: https://www.premiumvcedump.com/Fortinet/valid-NSE5_FSM-5.2-premium-vce-exam-dumps.html

Exam NSE5_FSM-5.2: Fortinet NSE 5 - FortiSIEM 5.2 - PremiumVCEDump: https://drive.google.com/open?id=1IUWBw2YwVKZBHwbjso7Q3qyuxWTIKWs8