NSE5_FSM-5.2 Actual Questions Answers PDF 100% Cover Real Exam Questions
NSE5_FSM-5.2 Exam questions and answers
NEW QUESTION 11
Which process converts Raw log data to structured data?
- A. Data parsing
- B. Data enrichment
- C. Data classification
- D. Data validation
Answer: A
NEW QUESTION 12
Refer to the exhibit.
What do the yellow stars listed in the Monitor column indicate?
- A. A yellow star indicates that a metric was applied during discovery, but FortiSIEM is unable to collect data.
- B. A yellow star indicates that a metric was applied during discovery, and data has been collected successfully
- C. A yellow star indicates that a metric was applied during discovery, but data collection has not started
- D. A yellow star indicates that a metric was not applied during discovery and, therefore, FortiSEIM was unable to collect data.
Answer: C
NEW QUESTION 13
What is a prerequisite for FortiSIEM Linux agent installation?
- A. The Linux agent manager server must be installed.
- B. The auditd service must be installed on the Linux server being monitored
- C. Both the web server and the audit service must be installed on the Linux server being monitored
- D. The web server must be installed on the Linux server being monitored
Answer: C
NEW QUESTION 14
Refer to the exhibit.
A FortiSIEM administrator wants to collect both SIEM event logs and performance and availability metrics (PAM) events from a Microsoft Windows server Which protocol should the administrator select in the Access Protocol drop-down list so that FortiSIEM will collect both SIEM and PAM events?
- A. LDAPS
- B. LDAP start TLS
- C. WMI
- D. TELNET
Answer: D
NEW QUESTION 15
An administrator defines SMTP as a critical process on a Linux server. If the SMTP process is stopped, FortiSIEM would generate a critical event with which event type?
- A. PH_DEV_MON_SMTP_STOP
- B. Postfix-Mail-Slop
- C. PH_DEV_MON_PROC_STOP
- D. Generic_SMTP_Process_Exit
Answer: A
NEW QUESTION 16
What are the minimum memory requirements for the FortiSIEM supervisor virtual appliance, when the proprietary flat file database is used?
- A. 64GB RAM
- B. 16GB RAM
- C. 24GB RAM
- D. 32GB RAM
Answer: D
NEW QUESTION 17
What protocol can be used to collect Windows event logs in an agentless method?
- A. SMTP
- B. WMI
- C. SSH
- D. SNMP
Answer: B
NEW QUESTION 18
What is the best discovery scan option for a network environment where ping is disabled on all network devices?
- A. CMDB scan
- B. L2 scan
- C. Range scan
- D. Smart scan
Answer: D
NEW QUESTION 19
Which database is used for storing anomaly data, that is calculated for different parameters, such as traffic and device resource usage running averages, and standard deviation values?
- A. CMDB
- B. SVN DB
- C. Profile DB
- D. Event DB
Answer: D
NEW QUESTION 20
Refer to the exhibit.
A FortiSlEM administrator wants to group some attributes for a report, but is not able to do so successfully.
As shown in the exhibit, why are some of the fields highlighted in red?
- A. Unique attributes cannot be grouped.
- B. The Event Receive Time attribute is not available for logs.
- C. The attribute COUNT(Matched event) is an invalid expression.
- D. No RAW Event Log attribute is available for devices.
Answer: A
NEW QUESTION 21
An administrator wants to search for events received from Linux and Windows agents.
Which attribute should the administrator use in search filters, to view events received from agents only.
- A. External Event Receive Agents
- B. External Event Receive Protocol
- C. Event Received Proto Agents
- D. External Event Receive Raw Logs
Answer: D
NEW QUESTION 22
Which protocol is almost always required for the FortiSIEM GUI discovery process?
- A. Telnet
- B. Syslog
- C. SNMP
- D. WMI
Answer: C
NEW QUESTION 23
Refer to the exhibit.
A FortiSlEM administrator wants to group some attributes for a report, but is not able to do so successfully.
As shown in the exhibit, why are some of the fields highlighted in red?
- A. Unique attributes cannot be grouped.
- B. The Event Receive Time attribute is not available for logs.
- C. The attribute COUNT(Matched event) is an invalid expression.
- D. No RAW Event Log attribute is available for devices.
Answer: A
NEW QUESTION 24
If the reported packet loss is between 50% and 98%. which status is assigned to the device in the Availability column of summary dashboard?
- A. Up status is assigned because of received packets
- B. Down status is assigned because of packet loss.
- C. Degraded status is assigned because of packet loss
- D. Critical status is assigned because of reduction in number of packets received
Answer: C
NEW QUESTION 25
An administrator defines SMTP as a critical process on a Linux server. If the SMTP process is stopped, FortiSIEM would generate a critical event with which event type?
- A. PH_DEV_MON_SMTP_STOP
- B. Postfix-Mail-Slop
- C. Generic_SMTP_Process_Exit
- D. PH_DEV_MON_PROC_STOP
Answer: D
NEW QUESTION 26
What operating system is FortiSIEM based on?
- A. Microsoft Windows
- B. Cent OS
- C. RedHat
- D. Ubuntu
Answer: B
NEW QUESTION 27
Which command displays the Linux agent status?
- A. Service fortisiem-linux-agent status
- B. Service fsm-linux-agent status
- C. Service linux-agent status
- D. Service Ao-linux-agent status
Answer: A
NEW QUESTION 28
A FortiSIEM supervisor at headquarters is struggling to keep up with an increase of EPS (Events Per Second) being reported across the enterprise. What components should an administrator consider deploying to assist the supervisor with processing data?
- A. Supervisor
- B. Worker
- C. Collector
- D. Agent
Answer: B
NEW QUESTION 29
Refer to the exhibit.
The FortiSIEM administrator is examining events for two devices to investigate an issue However, the administrator is not getting any results from their search.
Based on the selected fillers shown in the exhibit, why is the search returning no results?
- A. Parenthesis are missing
- B. The wrong boolean operator is selected in the Next column
- C. An invalid IP subnet is typed in the Value column
- D. The wrong option is selected in the Operator column
Answer: B
NEW QUESTION 30
Refer to the exhibit.
Three events are collected over a 10-minutc time period from two servers Server A and Server B.
Based on the settings being used for the rule subpattern. how many incidents will the servers generate?
- A. Server A will generate one incident and Server B will not generate any incidents
- B. Server B will generate one incident and Server A will not generate any incidents
- C. Server A will not generate any incidents and Server B will not generate any incidents
- D. Server A will generate one incident and Server B wifl generate one incident
Answer: C
NEW QUESTION 31
In the rules engine, which condition instructs FortiSIEM to summarize and count the matching evaluated data?
- A. Filters
- B. Group By
- C. Time Window
- D. Aggregation
Answer: D
NEW QUESTION 32
......
TopExamCollection NSE5_FSM-5.2 Exam Practice Test Questions : https://www.topexamcollection.com/NSE5_FSM-5.2-vce-collection.html
Pass NSE5_FSM-5.2 Exam Info and Free Practice Test : https://drive.google.com/open?id=1Xw_kflroF0xLmB6o2JqeNagI2gvsGciK

