[Jul-2023] Use Real NSE5_EDR-5.0 Dumps - 100% Free NSE5_EDR-5.0 Exam Dumps
NSE5_EDR-5.0 PDF Dumps Exam Questions – Valid NSE5_EDR-5.0 Dumps
NEW QUESTION # 17
FortiXDR relies on which feature as part of its automated extended response?
- A. Security Policies
- B. Forensic
- C. Communication Control
- D. Playbooks
Answer: A
NEW QUESTION # 18
How does FortiEDR implement post-infection protection?
- A. By using methods used by traditional EDR
- B. By insurance against ransomware
- C. By preventing data exfiltration or encryption even after a breach occurs
- D. By real-time filtering to prevent malware from executing
Answer: D
NEW QUESTION # 19
Which security policy has all of its rules disabled by default?
- A. Execution Prevention
- B. Device Control
- C. Ransomware Prevention
- D. Exfiltration Prevention
Answer: C
NEW QUESTION # 20
A FortiEDR security event is causing a performance issue with a third-parry application. What must you do first about the event?
- A. Contact Fortinet support
- B. Terminate the process and uninstall the third-party application
- C. Immediately create an exception
- D. Investigate the event to verify whether or not the application is safe
Answer: C
NEW QUESTION # 21
Which FortiEDR component is required to find malicious files on the entire network of an organization?
- A. FortiEDR Core
- B. FortiEDR Aggregator
- C. FortiEDR Threat Hunting Repository
- D. FortiEDR Central Manager
Answer: B
NEW QUESTION # 22
What is the purpose of the Threat Hunting feature?
- A. Delete any file from any collector in the organization
- B. Execute playbooks to isolate affected collectors in the organization
- C. Identify all instances of a known malicious file or hash and notify affected users
- D. Find and delete all instances ofa known malicious file or hash inthe organization
Answer: C
NEW QUESTION # 23
What is true about classifications assigned by Fortinet Cloud Sen/ice (FCS)?
- A. FCS revises the classification of the core based on its database
- B. The core only assigns a classification if FCS is not available
- C. The core is responsible for all classifications if FCS playbooks are disabled
- D. FCS is responsible for all classifications
Answer: A
NEW QUESTION # 24
Refer to the exhibit.
Based on the postman output shown in the exhibit why is the user getting an unauthorized error?
- A. FortiEDR requires a password reset the first time a user logs in
- B. API access is disabled on the central manager
- C. The user has been assigned Admin and Rest API roles
- D. Postman cannot reach the central manager
Answer: C
NEW QUESTION # 25
The FortiEDR axe classified an event as inconclusive, out a few seconds later FCS revised the classification to malicious. What playbook actions ate applied to the event?
- A. Playbook actions applied to handled events
- B. Playbook actions applied to malicious events
- C. Playbook actions applied to inconclusive events
- D. Playbook actions applied to suspicious events
Answer: B
NEW QUESTION # 26
An administrator needs to restrict access to the ADMINISTRATION tab inthe central manager for a specific account.
What role should the administrator assign to this account?
- A. User
- B. Local Admin
- C. REST API
- D. Admin
Answer: B
NEW QUESTION # 27
Refer to the exhibits.

The exhibits show the collector state and active connections. The collector is unable to connect to aggregator IP address 10.160.6.100 using default port.
Based on the netstat command output what must you do to resolve the connectivity issue?
- A. Reinstall collector agent and use port 8081
- B. Reinstall collector agent and use port 6514
- C. Reinstall collector agent and use port 555
- D. Reinstall collector agent and use port 443
Answer: A
NEW QUESTION # 28
An administrator finds a third party free software on a user's computer mat does not appear in me application list in the communication control console Which two statements are true about this situation? (Choose two)
- A. The application has not made any connection attempts
- B. The application is ignored as the reputation score is acceptable by the security policy
- C. The application is allowed in all communication control policies
- D. The application is blocked by the security policies
Answer: C,D
NEW QUESTION # 29
......
Ultimate NSE5_EDR-5.0 Guide to Prepare Free Latest Fortinet Practice Tests Dumps: https://www.premiumvcedump.com/Fortinet/valid-NSE5_EDR-5.0-premium-vce-exam-dumps.html
Get Top-Rated Fortinet NSE5_EDR-5.0 Exam Dumps Now: https://drive.google.com/open?id=1g0EVQCz5r7b-l6M__Fwxu4DtMGLJjM0S