Verified NSE5_EDR-5.0 dumps Q&As - 2023 Latest NSE5_EDR-5.0 Download [Q18-Q39]

Share

Verified NSE5_EDR-5.0  dumps Q&As - 2023 Latest NSE5_EDR-5.0  Download

Updated 100% Cover Real NSE5_EDR-5.0 Exam Questions - 100% Pass Guarantee


Fortinet NSE5_EDR-5.0 exam is designed for individuals who want to specialize in Endpoint Detection and Response (EDR) with a particular focus on the Fortinet FortiEDR product. Fortinet NSE 5 - FortiEDR 5.0 certification exam validates one's knowledge and skills in managing and deploying FortiEDR in complex enterprise environments. Those who pass the Fortinet NSE5_EDR-5.0 exam are capable of conducting advanced threat investigations, configuring and managing FortiEDR agents, and administering the FortiEDR management server.

 

NEW QUESTION # 18
Exhibit.

Based on the event shown in the exhibit which two statements about the event are true? (Choose two.)

  • A. The device is moved to isolation.
  • B. Playbooks is configured for this event.
  • C. The policy is in simulation mode
  • D. The event has been blocked

Answer: B,C


NEW QUESTION # 19
Refer to the exhibit.

Based on the postman output shown in the exhibit why is the user getting an unauthorized error?

  • A. API access is disabled on the central manager
  • B. FortiEDR requires a password reset the first time a user logs in
  • C. Postman cannot reach the central manager
  • D. The user has been assigned Admin and Rest API roles

Answer: D


NEW QUESTION # 20
What is the role of a collector in the communication control policy?

  • A. A collector is used to change the reputation score of any application that collector runs
  • B. A collector can quarantine unsafe applications from communicating
  • C. A collector blocks unsafe applications from running
  • D. A collector records applications that communicate externally

Answer: C


NEW QUESTION # 21
Refer to the exhibit.

Based on the event exception shown in the exhibit which two statements about the exception are true? (Choose two)

  • A. The exception is applied only on device C8092231196
  • B. A partial exception is applied to this event
  • C. FCS playbooks is enabled by Fortinet support
  • D. The system owner can modify the trigger rules parameters

Answer: A,B


NEW QUESTION # 22
The FortiEDR axe classified an event as inconclusive, out a few seconds later FCS revised the classification to malicious. What playbook actions ate applied to the event?

  • A. Playbook actions applied to suspicious events
  • B. Playbook actions applied to inconclusive events
  • C. Playbook actions applied to malicious events
  • D. Playbook actions applied to handled events

Answer: C


NEW QUESTION # 23
Refer to the exhibit.

Based on the threat hunting event details shown in the exhibit, which two statements about the event are true?
(Choose two.)

  • A. The PING EXE process was blocked
  • B. The activity event is associated with the file action
  • C. The user fortinet has executed a ping command
  • D. There are no MITRE details available for this event

Answer: A,D


NEW QUESTION # 24
What is the benefit of using file hash along with the file name in a threat hunting repository search?

  • A. It helps to check the malware even if the malware variant uses a different file name
  • B. It helps locate a file as threat hunting only allows hash search
  • C. It helps to make sure the hash is really a malware
  • D. It helps to find if some instances of the hash are actually associated with a different file

Answer: D


NEW QUESTION # 25
How does FortiEDR implement post-infection protection?

  • A. By real-time filtering to prevent malware from executing
  • B. By insurance against ransomware
  • C. By using methods used by traditional EDR
  • D. By preventing data exfiltration or encryption even after a breach occurs

Answer: A


NEW QUESTION # 26
Which two statements about the FortiEDR solution are true? (Choose two.)

  • A. It provides central management
  • B. It provides pant-to-point protection
  • C. It is Windows OS only
  • D. It provides pre-infection and post-infection protection

Answer: B,D


NEW QUESTION # 27
What is true about classifications assigned by Fortinet Cloud Sen/ice (FCS)?

  • A. The core is responsible for all classifications if FCS playbooks are disabled
  • B. FCS is responsible for all classifications
  • C. The core only assigns a classification if FCS is not available
  • D. FCS revises the classification of the core based on its database

Answer: D


NEW QUESTION # 28
An administrator needs to restrict access to the ADMINISTRATION tab inthe central manager for a specific account.
What role should the administrator assign to this account?

  • A. REST API
  • B. Local Admin
  • C. User
  • D. Admin

Answer: B


NEW QUESTION # 29
Exhibit.

Based on the forensics data shown in the exhibit, which two statements are true? (Choose two.)

  • A. The forensics data is displayed m the stacks view
  • B. The exfiltration prevention policy has blocked this event
  • C. The device has been isolated
  • D. An exception has been created for this event

Answer: B,C


NEW QUESTION # 30
......


Fortinet NSE5_EDR-5.0 exam is a 120-minute test that consists of 60 multiple-choice questions. NSE5_EDR-5.0 exam is available in English and Japanese and can be taken at any Pearson VUE test center worldwide. To pass the exam, candidates must achieve a score of at least 70%. NSE5_EDR-5.0 exam fee is $400, and candidates must register and pay for the exam through the Pearson VUE website.

 

Use Real Dumps - 100% Free NSE5_EDR-5.0 Exam Dumps: https://www.exam-killer.com/NSE5_EDR-5.0-valid-questions.html

Realistic NSE5_EDR-5.0 Dumps Latest Practice Tests Dumps: https://drive.google.com/open?id=1aQPdtTobqoGejxoAZ61D_G1DHpKrNjmh