Excellent NSE5_FSM-5.2 Updated 2022 Dumps With 100% Exam Passing Guarantee
Best way to practice test for Fortinet NSE5_FSM-5.2
NEW QUESTION 20
Refer to the exhibit.
If events are grouped by Event Receive Time, Reporting IP, and User attributes in FortiSIEM, how many results will be displayed?
- A. Eight results will be displayed
- B. Two results will be displayed
- C. Four results will be displayed
- D. Unique attributes cannot be grouped
Answer: D
NEW QUESTION 21
Which three ports can be used to send Syslogs to FortiSIEM? (Choose three.)
- A. UDP 514
- B. TCP 1470
- C. UDP9999
- D. TCP 514
- E. UDP 162
Answer: A,B,E
NEW QUESTION 22
In the advanced analytical rules engine in FortiSIEM, multiple subpatterms can be referenced using which three operation?(Choose three.)
- A. AND
- B. NOT
- C. FOLLOWED_BY
- D. OR
- E. ELSE
Answer: A,B,E
NEW QUESTION 23
An administrator wants to search for events received from Linux and Windows agents.
Which attribute should the administrator use in search filters, to view events received from agents only.
- A. External Event Receive Agents
- B. Event Received Proto Agents
- C. External Event Receive Raw Logs
- D. External Event Receive Protocol
Answer: D
NEW QUESTION 24
Device discovery information is stored in which database?
- A. Event DB
- B. SVN DB
- C. Profile DB
- D. CMDB
Answer: D
NEW QUESTION 25
Refer to the exhibit.
If events are grouped by Event Receive Time, Reporting IP, and User attributes in FortiSIEM, how many results will be displayed?
- A. Eight results will be displayed
- B. Two results will be displayed
- C. Four results will be displayed
- D. Unique attributes cannot be grouped
Answer: D
NEW QUESTION 26
Refer to the exhibit.
An administrator is trying to identify an issue using an expression bated on the Expression Builder settings shown in the exhibit however, the error message shown in the exhibit indicates that the expression is invalid.
Which is the correct expression?
- A. Matched Events(COUNT)
- B. COUNT(Matched Events)
- C. (COUNT) Matched Events
- D. Matched Events COUNT()
Answer: B
NEW QUESTION 27
Refer to the exhibit.
The FortiSIEM administrator is examining events for two devices to investigate an issue However, the administrator is not getting any results from their search.
Based on the selected fillers shown in the exhibit, why is the search returning no results?
- A. Parenthesis are missing
- B. The wrong boolean operator is selected in the Next column
- C. An invalid IP subnet is typed in the Value column
- D. The wrong option is selected in the Operator column
Answer: B
NEW QUESTION 28
An administrator defines SMTP as a critical process on a Linux server. If the SMTP process is stopped, FortiSIEM would generate a critical event with which event type?
- A. PH_DEV_MON_SMTP_STOP
- B. Postfix-Mail-Slop
- C. Generic_SMTP_Process_Exit
- D. PH_DEV_MON_PROC_STOP
Answer: D
NEW QUESTION 29
Which FortiSIEM components can do performance availability and performance monitoring?
- A. Supervisor, worker, and collector
- B. Collectors only
- C. Supervisor only
- D. Supervisor and workers only
Answer: A
NEW QUESTION 30
Refer to the exhibit.
Three events are collected over a 10-minutc time period from two servers Server A and Server B.
Based on the settings being used for the rule subpattern. how many incidents will the servers generate?
- A. Server A will generate one incident and Server B will not generate any incidents
- B. Server B will generate one incident and Server A will not generate any incidents
- C. Server A will not generate any incidents and Server B will not generate any incidents
- D. Server A will generate one incident and Server B wifl generate one incident
Answer: C
NEW QUESTION 31
Which database is used for storing anomaly data, that is calculated for different parameters, such as traffic and device resource usage running averages, and standard deviation values?
- A. CMDB
- B. SVN DB
- C. Profile DB
- D. Event DB
Answer: D
NEW QUESTION 32
Refer to the exhibit.
If events are grouped by Reporting IP, Event Type, and user attributes in FortiSIEM, how ,many results will be displayed?
- A. There results will be displayed.
- B. Unique attribute cannot be grouped.
- C. Seven results will be displayed.
- D. Five results will be displayed.
Answer: D
NEW QUESTION 33
What are the minimum memory requirements for the FortiSIEM supervisor virtual appliance, when the proprietary flat file database is used?
- A. 64GB RAM
- B. 16GB RAM
- C. 24GB RAM
- D. 32GB RAM
Answer: D
NEW QUESTION 34
What are the minimum memory requirements for the FortiSIEM supervisor virtual appliance, when the proprietary flat file database is used?
- A. 64GB RAM
- B. 16GB RAM
- C. 32GB RAM
- D. 24GB RAM
Answer: D
NEW QUESTION 35
What protocol can be used to collect Windows event logs in an agentless method?
- A. SMTP
- B. WMI
- C. SSH
- D. SNMP
Answer: B
NEW QUESTION 36
Which FortiSIEM components are capable of performing device discovery?
- A. Worker
- B. Collector
- C. FortiSIEM Windows agent
- D. FortiSIEM Linux agent
Answer: B
NEW QUESTION 37
What is a prerequisite for FortiSIEM Linux agent installation?
- A. The Linux agent manager server must be installed.
- B. The auditd service must be installed on the Linux server being monitored
- C. Both the web server and the audit service must be installed on the Linux server being monitored
- D. The web server must be installed on the Linux server being monitored
Answer: C
NEW QUESTION 38
Refer to the exhibit.
A FortiSIEM is continuously receiving syslog events from a FortiGate firewall The FortiSlfcM administrator is trying to search the raw event logs for the last two hours that contain the keyword tcp . However, the administrator is getting no results from the search.
Based on the selected filters shown in the exhibit, why are there no search results?
- A. In the Time section, the administrator selected the Relative Last option, and in the drop-down lists, selected 2 and Hours as the lime period The time period should be 24 hours.
- B. The keyword is case sensitive Instead of typing TCP in the Value field. the administrator should type tcp.
- C. The administrator selected - in the Operator column That a the wrong operator.
- D. The administrator selected AND in the Next drop-down list. This is the wrong boolean operator.
Answer: C
NEW QUESTION 39
Refer to the exhibit.
How was the FortiGate device discovered by FortiSIEM?
- A. Using the pull events method
- B. Through syslog discovery
- C. Through auto log discovery
- D. Through GUI log discovery
Answer: D
NEW QUESTION 40
Refer to the exhibit.
A FortiSIEM administrator wants to collect both SIEM event logs and performance and availability metrics (PAM) events from a Microsoft Windows server Which protocol should the administrator select in the Access Protocol drop-down list so that FortiSIEM will collect both SIEM and PAM events?
- A. LDAPS
- B. LDAP start TLS
- C. WMI
- D. TELNET
Answer: D
NEW QUESTION 41
Refer to the exhibit.
How was the FortiGate device discovered by FortiSIEM?
- A. Using the pull events method
- B. Through syslog discovery
- C. Through auto log discovery
- D. Through GUI log discovery
Answer: D
NEW QUESTION 42
An administrator wants to search for events received from Linux and Windows agents.
Which attribute should the administrator use in search filters, to view events received from agents only.
- A. External Event Receive Agents
- B. External Event Receive Protocol
- C. Event Received Proto Agents
- D. External Event Receive Raw Logs
Answer: D
NEW QUESTION 43
In FotiSlEM enterprise licensing mode, if the link between the collector and data center FortiSlEM cluster a down what happens?
- A. The collector drops incoming events like syslog. but slops performance collection
- B. The collector processes stop, and events are dropped
- C. The collector buffers events
- D. The collector continues performance collection of devices, but stops receiving syslog
Answer: B
NEW QUESTION 44
......
Fortinet NSE 5 - FortiSIEM 5.2 Certification Sample Questions and Practice Exam: https://www.trainingdump.com/Fortinet/NSE5_FSM-5.2-practice-exam-dumps.html
Real Exam Questions & Answers - Fortinet NSE5_FSM-5.2 Dump is Ready: https://drive.google.com/open?id=1EnfxEIEIyQCAI5Sk0QNAUccqt5tdCcsX