Latest NSE5_EDR-5.0 Actual Free Exam Questions Updated 30 Questions [Q15-Q32]

Share

Latest NSE5_EDR-5.0 Actual Free Exam Questions Updated 30 Questions

Free NSE5_EDR-5.0 Exam Braindumps certification guide Q&A


Fortinet NSE 5 - FortiEDR 5.0 certification exam is designed to validate the knowledge and skills of professionals who are responsible for implementing and managing endpoint security solutions using Fortinet FortiEDR. Fortinet NSE 5 - FortiEDR 5.0 certification exam is intended for network security professionals, security managers, and IT administrators who are responsible for securing endpoints against advanced threats and malware.

 

NEW QUESTION # 15
Which threat hunting profile is the most resource intensive?

  • A. Inventory
  • B. Standard Collection
  • C. Comprehensive
  • D. Default

Answer: C


NEW QUESTION # 16
A FortiEDR security event is causing a performance issue with a third-parry application. What must you do first about the event?

  • A. Immediately create an exception
  • B. Terminate the process and uninstall the third-party application
  • C. Investigate the event to verify whether or not the application is safe
  • D. Contact Fortinet support

Answer: A


NEW QUESTION # 17
FortiXDR relies on which feature as part of its automated extended response?

  • A. Security Policies
  • B. Playbooks
  • C. Forensic
  • D. Communication Control

Answer: A


NEW QUESTION # 18
Refer to the exhibit.

Based on the threat hunting event details shown in the exhibit, which two statements about the event are true?
(Choose two.)

  • A. The PING EXE process was blocked
  • B. The user fortinet has executed a ping command
  • C. There are no MITRE details available for this event
  • D. The activity event is associated with the file action

Answer: A,C


NEW QUESTION # 19
Which scripting language is supported by the FortiEDR action managed?

  • A. Python
  • B. Perl
  • C. Bash
  • D. TCL

Answer: D


NEW QUESTION # 20
Refer to the exhibits.


The exhibits show application policy logs and application details Collector C8092231196 is a member of the Finance group What must an administrator do to block the FileZilia application?

  • A. Assign Finance policy to Default Collector Group
  • B. Assign Simulation Communication Control Policy to DBA group
  • C. Deny application in Finance policy
  • D. Assign Finance policy to DBA group

Answer: B


NEW QUESTION # 21
Refer to the exhibit.

Based on the event exception shown in the exhibit which two statements about the exception are true? (Choose two)

  • A. The system owner can modify the trigger rules parameters
  • B. The exception is applied only on device C8092231196
  • C. A partial exception is applied to this event
  • D. FCS playbooks is enabled by Fortinet support

Answer: B,C


NEW QUESTION # 22
Which security policy has all of its rules disabled by default?

  • A. Exfiltration Prevention
  • B. Device Control
  • C. Execution Prevention
  • D. Ransomware Prevention

Answer: D


NEW QUESTION # 23
Refer to the exhibit.

Based on the postman output shown in the exhibit why is the user getting an unauthorized error?

  • A. Postman cannot reach the central manager
  • B. API access is disabled on the central manager
  • C. The user has been assigned Admin and Rest API roles
  • D. FortiEDR requires a password reset the first time a user logs in

Answer: C


NEW QUESTION # 24
The FortiEDR axe classified an event as inconclusive, out a few seconds later FCS revised the classification to malicious. What playbook actions ate applied to the event?

  • A. Playbook actions applied to handled events
  • B. Playbook actions applied to suspicious events
  • C. Playbook actions applied to malicious events
  • D. Playbook actions applied to inconclusive events

Answer: C


NEW QUESTION # 25
Which FortiEDR component is required to find malicious files on the entire network of an organization?

  • A. FortiEDR Threat Hunting Repository
  • B. FortiEDR Central Manager
  • C. FortiEDR Core
  • D. FortiEDR Aggregator

Answer: D


NEW QUESTION # 26
Which two statements are true about the remediation function in the threat hunting module? (Choose two.)

  • A. The threat hunting module sends the user a notification to delete the file
  • B. The file is removed from the affected collectors
  • C. The threat hunting module deletes files from collectors that are currently online.
  • D. The file is quarantined

Answer: A,D


NEW QUESTION # 27
......

NSE5_EDR-5.0 Certification Overview Latest NSE5_EDR-5.0 PDF Dumps: https://www.itexamsimulator.com/NSE5_EDR-5.0-brain-dumps.html

Top Fortinet NSE5_EDR-5.0 Exam Audio Study Guide! Practice Questions Edition: https://drive.google.com/open?id=19lAaXAIs3JcuHTYHV-kNKQ25HRZTv7iq