Download NSE 5 - FortiSIEM 5.2.NSE5_FSM-5.2.VCEplus.2022-08-01.42q.vcex

Vendor: Fortinet
Exam Code: NSE5_FSM-5.2
Exam Name: NSE 5 - FortiSIEM 5.2
Date: Aug 01, 2022
File Size: 4 MB
Downloads: 2

How to open VCEX files?

Files with VCEX extension can be opened by ProfExam Simulator.

Demo Questions

Question 1
Refer to the exhibit.
   
A FortiSlEM administrator wants to group some attributes for a report, but is not able to do so successfully.
As shown in the exhibit, why are some of the fields highlighted in red?
  1. The Event Receive Time attribute is not available for logs.
  2. The attribute COUNT(Matched event) is an invalid expression.
  3. Unique attributes cannot be grouped.
  4. No RAW Event Log attribute is available for devices.
Correct answer: C
Question 2
In the rules engine, which condition instructs FortiSIEM to summarize and count the matching evaluated data?
  1. Time Window
  2. Aggregation
  3. Group By
  4. Filters
Correct answer: B
Explanation:
Question 3
Refer to the exhibit.
   
How was the FortiGate device discovered by FortiSIEM?
  1. Through GUI log discovery
  2. Through syslog discovery
  3. Using the pull events method
  4. Through auto log discovery
Correct answer: A
Explanation:
Question 4
Refer to the exhibit.
   
If events are grouped by Reporting IP, Event Type, and user attributes in FortiSIEM, how ,many results will be displayed?
  1. Seven results will be displayed.
  2. There results will be displayed.
  3. Unique attribute cannot be grouped.
  4. Five results will be displayed.
Correct answer: D
Explanation:
Question 5
Which two FortiSIEM components work together to provide real-time event correlation?
  1. Collector and Windows agent
  2. Supervisor and worker
  3. Worker and collector
  4. Supervisor and collector
Correct answer: D
Explanation:
Question 6
If an incident's status is Cleared, what does this mean?
  1. Two hours have passed since the incident occurred and the incident has not reoccurred.
  2. A clear condition set on a rule was satisfied.
  3. A security rule issue has been resolved.
  4. The incident was cleared by an operator.
Correct answer: B
Explanation:
Question 7
Refer to the exhibit.
   
A FortiSIEM is continuously receiving syslog events from a FortiGate firewall The FortiSlfcM administrator is trying to search the raw event logs for the last two hours that contain the keyword tcp . However, the administrator is getting no results from the search.
Based on the selected filters shown in the exhibit, why are there no search results?
  1. The keyword is case sensitive Instead of typing TCP in the Value field. the administrator should type tcp.
  2. In the Time section, the administrator selected the Relative Last option, and in the drop-down lists, selected 2 and Hours as the lime period The time period should be 24 hours.
  3. The administrator selected - in the Operator column That a the wrong operator.
  4. The administrator selected AND in the Next drop-down list. This is the wrong boolean operator.
Correct answer: C
Explanation:
Question 8
Which FortiSIEM components are capable of performing device discovery?
  1. FortiSIEM Windows agent
  2. Worker
  3. FortiSIEM Linux agent
  4. Collector
Correct answer: D
Explanation:
Question 9
Refer to the exhibit.
   
  
An administrator is trying to identify an issue using an expression bated on the Expression Builder settings shown in the exhibit however, the error message shown in the exhibit indicates that the expression is invalid.
Which is the correct expression?
  1. Matched Events COUNT()
  2. Matched Events(COUNT)
  3. COUNT(Matched Events)
  4. (COUNT) Matched Events
Correct answer: C
Explanation:
Question 10
If the reported packet loss is between 50% and 98%. which status is assigned to the device in the Availability column of summary dashboard?
  1. Down status is assigned because of packet loss.
  2. Up status is assigned because of received packets
  3. Critical status is assigned because of reduction in number of packets received
  4. Degraded status is assigned because of packet loss
Correct answer: D
Explanation:
HOW TO OPEN VCE FILES

Use VCE Exam Simulator to open VCE files
Avanaset

HOW TO OPEN VCEX AND EXAM FILES

Use ProfExam Simulator to open VCEX and EXAM files
ProfExam Screen

ProfExam
ProfExam at a 20% markdown

You have the opportunity to purchase ProfExam at a 20% reduced price

Get Now!