Unique Top-selling NSE5_EDR-5.0 Exams - New 2023 Fortinet Pratice Exam [Q14-Q39]

Share

Unique Top-selling NSE5_EDR-5.0 Exams - New 2023 Fortinet Pratice Exam

NSE 5 Network Security Analyst Dumps NSE5_EDR-5.0 Exam for Full Questions - Exam Study Guide

NEW QUESTION 14
An administrator finds a third party free software on a user's computer mat does not appear in me application list in the communication control console Which two statements are true about this situation? (Choose two)

  • A. The application is blocked by the security policies
  • B. The application has not made any connection attempts
  • C. The application is ignored as the reputation score is acceptable by the security policy
  • D. The application is allowed in all communication control policies

Answer: A,D

 

NEW QUESTION 15
Refer to the exhibit.

Based on the postman output shown in the exhibit why is the user getting an unauthorized error?

  • A. API access is disabled on the central manager
  • B. Postman cannot reach the central manager
  • C. FortiEDR requires a password reset the first time a user logs in
  • D. The user has been assigned Admin and Rest API roles

Answer: D

 

NEW QUESTION 16
An administrator needs to restrict access to the ADMINISTRATION tab inthe central manager for a specific account.
What role should the administrator assign to this account?

  • A. Local Admin
  • B. User
  • C. Admin
  • D. REST API

Answer: A

 

NEW QUESTION 17
Which two statements about the FortiEDR solution are true? (Choose two.)

  • A. It provides central management
  • B. It provides pre-infection and post-infection protection
  • C. It provides pant-to-point protection
  • D. It is Windows OS only

Answer: B,C

 

NEW QUESTION 18
Exhibit.

Based on the forensics data shown in the exhibit which two statements are true? (Choose two.)

  • A. The execution prevention policy has blocked this event.
  • B. The device cannot be remediated
  • C. The event was blocked because the certificate is unsigned
  • D. Device C8092231196 has been isolated

Answer: C,D

 

NEW QUESTION 19
Which threat hunting profile is the most resource intensive?

  • A. Comprehensive
  • B. Default
  • C. Inventory
  • D. Standard Collection

Answer: A

 

NEW QUESTION 20
Refer to the exhibit.

Based on the threat hunting event details shown in the exhibit, which two statements about the event are true?
(Choose two.)

  • A. The activity event is associated with the file action
  • B. The user fortinet has executed a ping command
  • C. The PING EXE process was blocked
  • D. There are no MITRE details available for this event

Answer: C,D

 

NEW QUESTION 21
What is the role of a collector in the communication control policy?

  • A. A collector is used to change the reputation score of any application that collector runs
  • B. A collector can quarantine unsafe applications from communicating
  • C. A collector records applications that communicate externally
  • D. A collector blocks unsafe applications from running

Answer: D

 

NEW QUESTION 22
Refer to the exhibit.

Based on the FortiEDR status output shown in the exhibit, which two statements about the FortiEDR collector are true? (Choose two.)

  • A. The collector device cannot reach the central manager
  • B. The collector has been installed with an incorrect port number
  • C. The collector device has windows firewall enabled
  • D. The collector has been installed with an incorrect registration password

Answer: A,B

 

NEW QUESTION 23
Exhibit.

Based on the event shown in the exhibit which two statements about the event are true? (Choose two.)

  • A. The event has been blocked
  • B. The policy is in simulation mode
  • C. The device is moved to isolation.
  • D. Playbooks is configured for this event.

Answer: B,D

 

NEW QUESTION 24
FortiXDR relies on which feature as part of its automated extended response?

  • A. Communication Control
  • B. Playbooks
  • C. Forensic
  • D. Security Policies

Answer: D

 

NEW QUESTION 25
Refer to the exhibits.


The exhibits show application policy logs and application details Collector C8092231196 is a member of the Finance group What must an administrator do to block the FileZilia application?

  • A. Assign Finance policy to DBA group
  • B. Deny application in Finance policy
  • C. Assign Finance policy to Default Collector Group
  • D. Assign Simulation Communication Control Policy to DBA group

Answer: D

 

NEW QUESTION 26
......

Best way to practice test for Fortinet NSE5_EDR-5.0: https://examcertify.passleader.top/Fortinet/NSE5_EDR-5.0-exam-braindumps.html