Online Questions - Valid Practice To your NSE5_FSM-5.2 Exam (Updated 43 Questions) [Q23-Q40]

Share

Online Questions - Valid Practice To your NSE5_FSM-5.2 Exam (Updated 43 Questions)

Practice To NSE5_FSM-5.2 - Remarkable Practice On your Fortinet NSE 5 - FortiSIEM 5.2 Exam

NEW QUESTION 23
Refer to the exhibit.

What do the yellow stars listed in the Monitor column indicate?

  • A. A yellow star indicates that a metric was applied during discovery, and data has been collected successfully
  • B. A yellow star indicates that a metric was not applied during discovery and, therefore, FortiSEIM was unable to collect data.
  • C. A yellow star indicates that a metric was applied during discovery, but FortiSIEM is unable to collect data.
  • D. A yellow star indicates that a metric was applied during discovery, but data collection has not started

Answer: D

 

NEW QUESTION 24
In the advanced analytical rules engine in FortiSIEM, multiple subpatterms can be referenced using which three operation?(Choose three.)

  • A. ELSE
  • B. AND
  • C. OR
  • D. FOLLOWED_BY
  • E. NOT

Answer: A,B,E

 

NEW QUESTION 25
Which process converts Raw log data to structured data?

  • A. Data enrichment
  • B. Data validation
  • C. Data parsing
  • D. Data classification

Answer: C

 

NEW QUESTION 26
Which command displays the Linux agent status?

  • A. Service fortisiem-linux-agent status
  • B. Service fsm-linux-agent status
  • C. Service linux-agent status
  • D. Service Ao-linux-agent status

Answer: A

 

NEW QUESTION 27
If an incident's status is Cleared, what does this mean?

  • A. A security rule issue has been resolved.
  • B. A clear condition set on a rule was satisfied.
  • C. The incident was cleared by an operator.
  • D. Two hours have passed since the incident occurred and the incident has not reoccurred.

Answer: B

 

NEW QUESTION 28
Which FortiSIEM components can do performance availability and performance monitoring?

  • A. Supervisor only
  • B. Supervisor and workers only
  • C. Collectors only
  • D. Supervisor, worker, and collector

Answer: D

 

NEW QUESTION 29
Which two export methods are available for FortiSIEM analytics results? (Choose two.)

  • A. PNG
  • B. HTML
  • C. PDF
  • D. CSV

Answer: C,D

 

NEW QUESTION 30
What operating system is FortiSIEM based on?

  • A. Cent OS
  • B. Ubuntu
  • C. RedHat
  • D. Microsoft Windows

Answer: A

 

NEW QUESTION 31
An administrator defines SMTP as a critical process on a Linux server. If the SMTP process is stopped, FortiSIEM would generate a critical event with which event type?

  • A. Postfix-Mail-Slop
  • B. PH_DEV_MON_SMTP_STOP
  • C. PH_DEV_MON_PROC_STOP
  • D. Generic_SMTP_Process_Exit

Answer: C

 

NEW QUESTION 32
Refer to the exhibit.

A FortiSIEM is continuously receiving syslog events from a FortiGate firewall The FortiSlfcM administrator is trying to search the raw event logs for the last two hours that contain the keyword tcp . However, the administrator is getting no results from the search.
Based on the selected filters shown in the exhibit, why are there no search results?

  • A. The administrator selected AND in the Next drop-down list. This is the wrong boolean operator.
  • B. In the Time section, the administrator selected the Relative Last option, and in the drop-down lists, selected 2 and Hours as the lime period The time period should be 24 hours.
  • C. The keyword is case sensitive Instead of typing TCP in the Value field. the administrator should type tcp.
  • D. The administrator selected - in the Operator column That a the wrong operator.

Answer: D

 

NEW QUESTION 33
Refer to the exhibit.

If events are grouped by Event Receive Time, Reporting IP, and User attributes in FortiSIEM, how many results will be displayed?

  • A. Two results will be displayed
  • B. Four results will be displayed
  • C. Unique attributes cannot be grouped
  • D. Eight results will be displayed

Answer: C

 

NEW QUESTION 34
Refer to the exhibit.

A FortiSIEM administrator wants to collect both SIEM event logs and performance and availability metrics (PAM) events from a Microsoft Windows server Which protocol should the administrator select in the Access Protocol drop-down list so that FortiSIEM will collect both SIEM and PAM events?

  • A. TELNET
  • B. LDAP start TLS
  • C. WMI
  • D. LDAPS

Answer: A

 

NEW QUESTION 35
Which three ports can be used to send Syslogs to FortiSIEM? (Choose three.)

  • A. UDP 514
  • B. TCP 514
  • C. UDP9999
  • D. TCP 1470
  • E. UDP 162

Answer: A,D,E

 

NEW QUESTION 36
Which database is used for storing anomaly data, that is calculated for different parameters, such as traffic and device resource usage running averages, and standard deviation values?

  • A. SVN DB
  • B. Event DB
  • C. Profile DB
  • D. CMDB

Answer: B

 

NEW QUESTION 37
Refer to the exhibit.

What do the yellow stars listed in the Monitor column indicate?

  • A. A yellow star indicates that a metric was applied during discovery, and data has been collected successfully
  • B. A yellow star indicates that a metric was applied during discovery, but data collection has not started
  • C. A yellow star indicates that a metric was applied during discovery, but FortiSIEM is unable to collect data.
  • D. A yellow star indicates that a metric was not applied during discovery and, therefore, FortiSEIM was unable to collect data.

Answer: D

 

NEW QUESTION 38
Refer to the exhibit.

If events are grouped by Event Receive Time, Reporting IP, and User attributes in FortiSIEM, how many results will be displayed?

  • A. Two results will be displayed
  • B. Four results will be displayed
  • C. Unique attributes cannot be grouped
  • D. Eight results will be displayed

Answer: C

 

NEW QUESTION 39
Refer to the exhibit.

The FortiSIEM administrator is examining events for two devices to investigate an issue However, the administrator is not getting any results from their search.
Based on the selected fillers shown in the exhibit, why is the search returning no results?

  • A. The wrong option is selected in the Operator column
  • B. The wrong boolean operator is selected in the Next column
  • C. Parenthesis are missing
  • D. An invalid IP subnet is typed in the Value column

Answer: D

 

NEW QUESTION 40
......

True NSE5_FSM-5.2 Exam Extraordinary Practice For the Exam: https://www.exam-killer.com/NSE5_FSM-5.2-valid-questions.html

Get 100% Passing Success With True NSE5_FSM-5.2 Exam: https://drive.google.com/open?id=19w4T5_kcKdONwA7w0kq1cu3j0QgJkd2L