Feb-2022 Fortinet NSE5_FSM-5.2 Certification Real 2022 Mock Exam
NSE5_FSM-5.2 Exam Questions and Valid PMP Dumps PDF
NEW QUESTION 17
What are the minimum memory requirements for the FortiSIEM supervisor virtual appliance, when the proprietary flat file database is used?
- A. 64GB RAM
- B. 16GB RAM
- C. 24GB RAM
- D. 32GB RAM
Answer: D
NEW QUESTION 18
Which process converts Raw log data to structured data?
- A. Data enrichment
- B. Data parsing
- C. Data validation
- D. Data classification
Answer: C
NEW QUESTION 19
Which process converts Raw log data to structured data?
- A. Data parsing
- B. Data enrichment
- C. Data classification
- D. Data validation
Answer: A
NEW QUESTION 20
Which discovery scan type is prone to miss a device, if the device is quiet and the entry foe that device is not present in the ARP table of adjacent devices?
- A. CMDB scan
- B. L2 scan
- C. Range scan
- D. Smart scan
Answer: D
NEW QUESTION 21
What is a prerequisite for a FortiSIEM supervisor with a worker deployment, using the proprietary flat file database?
- A. The event database must be on NFS
- B. The CMDB database must be on NFS
- C. The event database must be on a local disk
- D. The \archive mount must be on a local disk
Answer: A
NEW QUESTION 22
Refer to the exhibit.
A FortiSIEM administrator wants to collect both SIEM event logs and performance and availability metrics (PAM) events from a Microsoft Windows server Which protocol should the administrator select in the Access Protocol drop-down list so that FortiSIEM will collect both SIEM and PAM events?
- A. LDAPS
- B. LDAP start TLS
- C. WMI
- D. TELNET
Answer: D
NEW QUESTION 23
Refer to the exhibit.
If events are grouped by Reporting IP, Event Type, and user attributes in FortiSIEM, how ,many results will be displayed?
- A. There results will be displayed.
- B. Unique attribute cannot be grouped.
- C. Seven results will be displayed.
- D. Five results will be displayed.
Answer: D
NEW QUESTION 24
Which three ports can be used to send Syslogs to FortiSIEM? (Choose three.)
- A. UDP 514
- B. TCP 1470
- C. UDP9999
- D. TCP 514
- E. UDP 162
Answer: A,B,E
NEW QUESTION 25
What protocol can be used to collect Windows event logs in an agentless method?
- A. SMTP
- B. WMI
- C. SSH
- D. SNMP
Answer: B
NEW QUESTION 26
In the advanced analytical rules engine in FortiSIEM, multiple subpatterms can be referenced using which three operation?(Choose three.)
- A. AND
- B. NOT
- C. FOLLOWED_BY
- D. OR
- E. ELSE
Answer: A,B,E
NEW QUESTION 27
Which database is used for storing anomaly data, that is calculated for different parameters, such as traffic and device resource usage running averages, and standard deviation values?
- A. Event DB
- B. CMDB
- C. SVN DB
- D. Profile DB
Answer: D
NEW QUESTION 28
In FotiSlEM enterprise licensing mode, if the link between the collector and data center FortiSlEM cluster a down what happens?
- A. The collector drops incoming events like syslog. but slops performance collection
- B. The collector processes stop, and events are dropped
- C. The collector buffers events
- D. The collector continues performance collection of devices, but stops receiving syslog
Answer: B
NEW QUESTION 29
Which command displays the Linux agent status?
- A. Service fortisiem-linux-agent status
- B. Service fsm-linux-agent status
- C. Service linux-agent status
- D. Service Ao-linux-agent status
Answer: A
NEW QUESTION 30
Which item is required to register a FortiSIEM appliance license?
- A. Static Hardware ID
- B. Static IP address
- C. Static storage
- D. Static MAC address
Answer: A
NEW QUESTION 31
An administrator wants to search for events received from Linux and Windows agents.
Which attribute should the administrator use in search filters, to view events received from agents only.
- A. External Event Receive Agents
- B. External Event Receive Protocol
- C. Event Received Proto Agents
- D. External Event Receive Raw Logs
Answer: D
NEW QUESTION 32
Which FortiSIEM components are capable of performing device discovery?
- A. Worker
- B. Collector
- C. FortiSIEM Windows agent
- D. FortiSIEM Linux agent
Answer: B
NEW QUESTION 33
Refer to the exhibit.
Three events are collected over a 10-minutc time period from two servers Server A and Server B.
Based on the settings being used for the rule subpattern. how many incidents will the servers generate?
- A. Server A will generate one incident and Server B will not generate any incidents
- B. Server B will generate one incident and Server A will not generate any incidents
- C. Server A will not generate any incidents and Server B will not generate any incidents
- D. Server A will generate one incident and Server B wifl generate one incident
Answer: C
NEW QUESTION 34
Refer to the exhibit.
What do the yellow stars listed in the Monitor column indicate?
- A. A yellow star indicates that a metric was applied during discovery, but FortiSIEM is unable to collect data.
- B. A yellow star indicates that a metric was applied during discovery, and data has been collected successfully
- C. A yellow star indicates that a metric was applied during discovery, but data collection has not started
- D. A yellow star indicates that a metric was not applied during discovery and, therefore, FortiSEIM was unable to collect data.
Answer: D
NEW QUESTION 35
Refer to the exhibit.
How was the FortiGate device discovered by FortiSIEM?
- A. Using the pull events method
- B. Through syslog discovery
- C. Through auto log discovery
- D. Through GUI log discovery
Answer: D
NEW QUESTION 36
An administrator defines SMTP as a critical process on a Linux server. If the SMTP process is stopped, FortiSIEM would generate a critical event with which event type?
- A. PH_DEV_MON_SMTP_STOP
- B. Postfix-Mail-Slop
- C. PH_DEV_MON_PROC_STOP
- D. Generic_SMTP_Process_Exit
Answer: A
NEW QUESTION 37
In the rules engine, which condition instructs FortiSIEM to summarize and count the matching evaluated data?
- A. Group By
- B. Aggregation
- C. Filters
- D. Time Window
Answer: A
NEW QUESTION 38
Refer to the exhibit.
What do the yellow stars listed in the Monitor column indicate?
- A. A yellow star indicates that a metric was applied during discovery, but FortiSIEM is unable to collect data.
- B. A yellow star indicates that a metric was applied during discovery, and data has been collected successfully
- C. A yellow star indicates that a metric was applied during discovery, but data collection has not started
- D. A yellow star indicates that a metric was not applied during discovery and, therefore, FortiSEIM was unable to collect data.
Answer: C
NEW QUESTION 39
......
NSE5_FSM-5.2 Question Bank: Free PDF Download Recently Updated Questions: https://www.premiumvcedump.com/Fortinet/valid-NSE5_FSM-5.2-premium-vce-exam-dumps.html
NSE5_FSM-5.2 Brain Dump: A Study Guide with Tips & Tricks for passing Exam: https://drive.google.com/open?id=1IUWBw2YwVKZBHwbjso7Q3qyuxWTIKWs8