Get NSE5_EDR-5.0 Braindumps & NSE5_EDR-5.0 Real Exam Questions [Q13-Q29]

Share

Get NSE5_EDR-5.0 Braindumps & NSE5_EDR-5.0 Real Exam Questions

Fortinet NSE5_EDR-5.0 Actual Questions and Braindumps


Fortinet NSE5_EDR-5.0 certification exam covers a range of topics, including endpoint security fundamentals, threat detection and response, FortiEDR architecture and deployment, and operational and administrative tasks. Candidates who pass NSE5_EDR-5.0 exam will have the skills and knowledge needed to deploy and manage FortiEDR solutions in a variety of environments.

 

NEW QUESTION # 13
Which FortiEDR component is required to find malicious files on the entire network of an organization?

  • A. FortiEDR Central Manager
  • B. FortiEDR Core
  • C. FortiEDR Aggregator
  • D. FortiEDR Threat Hunting Repository

Answer: C


NEW QUESTION # 14
Refer to the exhibit.

Based on the threat hunting event details shown in the exhibit, which two statements about the event are true?
(Choose two.)

  • A. The PING EXE process was blocked
  • B. The activity event is associated with the file action
  • C. The user fortinet has executed a ping command
  • D. There are no MITRE details available for this event

Answer: A,D


NEW QUESTION # 15
Which two statements about the FortiEDR solution are true? (Choose two.)

  • A. It is Windows OS only
  • B. It provides pant-to-point protection
  • C. It provides pre-infection and post-infection protection
  • D. It provides central management

Answer: B,C


NEW QUESTION # 16
Which security policy has all of its rules disabled by default?

  • A. Exfiltration Prevention
  • B. Device Control
  • C. Execution Prevention
  • D. Ransomware Prevention

Answer: D


NEW QUESTION # 17
The FortiEDR axe classified an event as inconclusive, out a few seconds later FCS revised the classification to malicious. What playbook actions ate applied to the event?

  • A. Playbook actions applied to inconclusive events
  • B. Playbook actions applied to malicious events
  • C. Playbook actions applied to handled events
  • D. Playbook actions applied to suspicious events

Answer: B


NEW QUESTION # 18
What is true about classifications assigned by Fortinet Cloud Sen/ice (FCS)?

  • A. The core only assigns a classification if FCS is not available
  • B. FCS is responsible for all classifications
  • C. The core is responsible for all classifications if FCS playbooks are disabled
  • D. FCS revises the classification of the core based on its database

Answer: D


NEW QUESTION # 19
Which scripting language is supported by the FortiEDR action managed?

  • A. Python
  • B. TCL
  • C. Bash
  • D. Perl

Answer: B


NEW QUESTION # 20
Refer to the exhibit.

Based on the postman output shown in the exhibit why is the user getting an unauthorized error?

  • A. API access is disabled on the central manager
  • B. FortiEDR requires a password reset the first time a user logs in
  • C. The user has been assigned Admin and Rest API roles
  • D. Postman cannot reach the central manager

Answer: C


NEW QUESTION # 21
Exhibit.

Based on the event shown in the exhibit which two statements about the event are true? (Choose two.)

  • A. Playbooks is configured for this event.
  • B. The device is moved to isolation.
  • C. The policy is in simulation mode
  • D. The event has been blocked

Answer: A,C


NEW QUESTION # 22
Refer to the exhibit.

Based on the threat hunting query shown in the exhibit which of the following is true?

  • A. The query will only check for network category
  • B. A security event will be triggered when the device attempts a RDP connection
  • C. This query is included in other organizations
  • D. RDP connections will be blocked and classified as suspicious

Answer: B


NEW QUESTION # 23
A company requires a global communication policy for a FortiEDR multi-tenant environment.
How can the administrator achieve this?

  • A. A local administrator creates a new communication control policy and assigns it globally to all organizations
  • B. An administrator creates a new communication control policy and shares it with other organizations
  • C. A local administrator creates new a communication control policy and shares it with other organizations
  • D. An administrator creates a new communication control policy for each organization

Answer: A


NEW QUESTION # 24
Exhibit.

Based on the forensics data shown in the exhibit which two statements are true? (Choose two.)

  • A. The execution prevention policy has blocked this event.
  • B. Device C8092231196 has been isolated
  • C. The event was blocked because the certificate is unsigned
  • D. The device cannot be remediated

Answer: B,C


NEW QUESTION # 25
......

NSE5_EDR-5.0 Dumps To Pass Fortinet Exam in 24 Hours - itPass4sure: https://freetorrent.itpass4sure.com/NSE5_EDR-5.0-practice-exam.html