NSE 5 Network Security Analyst NSE5_FSM-5.2 Dumps | Updated Dec 11, 2021 - Pass4cram
Master 2021 Latest The Questions NSE 5 Network Security Analyst and Pass NSE5_FSM-5.2 Real Exam!
NEW QUESTION 24
Refer to the exhibit.
A FortiSlEM administrator wants to group some attributes for a report, but is not able to do so successfully.
As shown in the exhibit, why are some of the fields highlighted in red?
- A. Unique attributes cannot be grouped.
- B. The attribute COUNT(Matched event) is an invalid expression.
- C. The Event Receive Time attribute is not available for logs.
- D. No RAW Event Log attribute is available for devices.
Answer: A
NEW QUESTION 25
Refer to the exhibit.
If events are grouped by Event Receive Time, Reporting IP, and User attributes in FortiSIEM, how many results will be displayed?
- A. Two results will be displayed
- B. Four results will be displayed
- C. Unique attributes cannot be grouped
- D. Eight results will be displayed
Answer: C
NEW QUESTION 26
Device discovery information is stored in which database?
- A. CMDB
- B. SVN DB
- C. Profile DB
- D. Event DB
Answer: A
NEW QUESTION 27
Which three ports can be used to send Syslogs to FortiSIEM? (Choose three.)
- A. UDP 514
- B. TCP 514
- C. UDP9999
- D. TCP 1470
- E. UDP 162
Answer: A,D,E
NEW QUESTION 28
A FortiSIEM supervisor at headquarters is struggling to keep up with an increase of EPS (Events Per Second) being reported across the enterprise. What components should an administrator consider deploying to assist the supervisor with processing data?
- A. Collector
- B. Agent
- C. Worker
- D. Supervisor
Answer: C
NEW QUESTION 29
Refer to the exhibit.
The FortiSIEM administrator is examining events for two devices to investigate an issue However, the administrator is not getting any results from their search.
Based on the selected fillers shown in the exhibit, why is the search returning no results?
- A. The wrong option is selected in the Operator column
- B. An invalid IP subnet is typed in the Value column
- C. Parenthesis are missing
- D. The wrong boolean operator is selected in the Next column
Answer: D
NEW QUESTION 30
Which two export methods are available for FortiSIEM analytics results? (Choose two.)
- A. PNG
- B. HTML
- C. PDF
- D. CSV
Answer: C,D
NEW QUESTION 31
Which item is required to register a FortiSIEM appliance license?
- A. Static MAC address
- B. Static Hardware ID
- C. Static storage
- D. Static IP address
Answer: B
NEW QUESTION 32
Which discovery scan type is prone to miss a device, if the device is quiet and the entry foe that device is not present in the ARP table of adjacent devices?
- A. L2 scan
- B. Smart scan
- C. CMDB scan
- D. Range scan
Answer: B
NEW QUESTION 33
What are the minimum memory requirements for the FortiSIEM supervisor virtual appliance, when the proprietary flat file database is used?
- A. 16GB RAM
- B. 32GB RAM
- C. 64GB RAM
- D. 24GB RAM
Answer: D
NEW QUESTION 34
An administrator wants to search for events received from Linux and Windows agents.
Which attribute should the administrator use in search filters, to view events received from agents only.
- A. External Event Receive Protocol
- B. External Event Receive Agents
- C. External Event Receive Raw Logs
- D. Event Received Proto Agents
Answer: A
NEW QUESTION 35
In the rules engine, which condition instructs FortiSIEM to summarize and count the matching evaluated data?
- A. Filters
- B. Time Window
- C. Group By
- D. Aggregation
Answer: D
NEW QUESTION 36
Which three ports can be used to send Syslogs to FortiSIEM? (Choose three.)
- A. TCP 514
- B. UDP 514
- C. UDP 162
- D. UDP9999
- E. TCP 1470
Answer: A,B,E
NEW QUESTION 37
What is the best discovery scan option for a network environment where ping is disabled on all network devices?
- A. L2 scan
- B. Smart scan
- C. CMDB scan
- D. Range scan
Answer: B
NEW QUESTION 38
Refer to the exhibit.
An administrator is trying to identify an issue using an expression bated on the Expression Builder settings shown in the exhibit however, the error message shown in the exhibit indicates that the expression is invalid.
Which is the correct expression?
- A. COUNT(Matched Events)
- B. Matched Events(COUNT)
- C. (COUNT) Matched Events
- D. Matched Events COUNT()
Answer: A
NEW QUESTION 39
In the advanced analytical rules engine in FortiSIEM, multiple subpatterms can be referenced using which three operation?(Choose three.)
- A. ELSE
- B. AND
- C. OR
- D. FOLLOWED_BY
- E. NOT
Answer: A,B,E
NEW QUESTION 40
What is a prerequisite for a FortiSIEM supervisor with a worker deployment, using the proprietary flat file database?
- A. The CMDB database must be on NFS
- B. The event database must be on a local disk
- C. The event database must be on NFS
- D. The \archive mount must be on a local disk
Answer: C
NEW QUESTION 41
If an incident's status is Cleared, what does this mean?
- A. A security rule issue has been resolved.
- B. The incident was cleared by an operator.
- C. A clear condition set on a rule was satisfied.
- D. Two hours have passed since the incident occurred and the incident has not reoccurred.
Answer: D
NEW QUESTION 42
Which two FortiSIEM components work together to provide real-time event correlation?
- A. Supervisor and collector
- B. Supervisor and worker
- C. Worker and collector
- D. Collector and Windows agent
Answer: A
NEW QUESTION 43
What are the four categories of incidents?
- A. Security, change, high risk, and low risk
- B. Performance, availability, security, and change
- C. Performance, devices, high risk, and low risk
- D. Devices, users, high risk, and low risk
Answer: B
NEW QUESTION 44
Refer to the exhibit.
How was the FortiGate device discovered by FortiSIEM?
- A. Through auto log discovery
- B. Through syslog discovery
- C. Using the pull events method
- D. Through GUI log discovery
Answer: D
NEW QUESTION 45
Refer to the exhibit.
A FortiSIEM is continuously receiving syslog events from a FortiGate firewall The FortiSlfcM administrator is trying to search the raw event logs for the last two hours that contain the keyword tcp . However, the administrator is getting no results from the search.
Based on the selected filters shown in the exhibit, why are there no search results?
- A. The administrator selected AND in the Next drop-down list. This is the wrong boolean operator.
- B. In the Time section, the administrator selected the Relative Last option, and in the drop-down lists, selected 2 and Hours as the lime period The time period should be 24 hours.
- C. The keyword is case sensitive Instead of typing TCP in the Value field. the administrator should type tcp.
- D. The administrator selected - in the Operator column That a the wrong operator.
Answer: D
NEW QUESTION 46
Refer to the exhibit.
If events are grouped by Reporting IP, Event Type, and user attributes in FortiSIEM, how ,many results will be displayed?
- A. Five results will be displayed.
- B. Unique attribute cannot be grouped.
- C. Seven results will be displayed.
- D. There results will be displayed.
Answer: A
NEW QUESTION 47
What are the four possible incident status values?
- A. Active, auto cleared, manual, false positive
- B. Active, dosed, cleared, open
- C. Active, cleared, cleared manually, system cleared
- D. Active, closed, manual, resolved
Answer: D
NEW QUESTION 48
......
A fully updated 2021 NSE5_FSM-5.2 Exam Dumps exam guide from training expert Pass4cram: https://www.pass4cram.com/NSE5_FSM-5.2_free-download.html
Practice To NSE5_FSM-5.2 - Pass4cram Remarkable Practice On your Fortinet NSE 5 - FortiSIEM 5.2 Exam: https://drive.google.com/open?id=1THx3S9jrZNJqxDnK1_3tdz2Sf3a8Qy1v