[Q15-Q36] PASS NSE5_EDR-5.0 exam with Fortinet Real Exam Questions - 100% Valid!

Share

PASS NSE5_EDR-5.0 exam with Fortinet Real Exam Questions - 100% Valid!

Actual NSE5_EDR-5.0 Exam Recently Updated Questions with Free Demo

NEW QUESTION # 15
An administrator finds a third party free software on a user's computer mat does not appear in me application list in the communication control console Which two statements are true about this situation? (Choose two)

  • A. The application is blocked by the security policies
  • B. The application is allowed in all communication control policies
  • C. The application has not made any connection attempts
  • D. The application is ignored as the reputation score is acceptable by the security policy

Answer: A,B


NEW QUESTION # 16
An administrator needs to restrict access to the ADMINISTRATION tab inthe central manager for a specific account.
What role should the administrator assign to this account?

  • A. User
  • B. Admin
  • C. REST API
  • D. Local Admin

Answer: D


NEW QUESTION # 17
Which two statements are true about the remediation function in the threat hunting module? (Choose two.)

  • A. The threat hunting module sends the user a notification to delete the file
  • B. The file is quarantined
  • C. The threat hunting module deletes files from collectors that are currently online.
  • D. The file is removed from the affected collectors

Answer: A,B


NEW QUESTION # 18
What is true about classifications assigned by Fortinet Cloud Sen/ice (FCS)?

  • A. FCS is responsible for all classifications
  • B. FCS revises the classification of the core based on its database
  • C. The core is responsible for all classifications if FCS playbooks are disabled
  • D. The core only assigns a classification if FCS is not available

Answer: B


NEW QUESTION # 19
Which two statements about the FortiEDR solution are true? (Choose two.)

  • A. It is Windows OS only
  • B. It provides pant-to-point protection
  • C. It provides central management
  • D. It provides pre-infection and post-infection protection

Answer: B,D


NEW QUESTION # 20
Which FortiEDR component is required to find malicious files on the entire network of an organization?

  • A. FortiEDR Threat Hunting Repository
  • B. FortiEDR Aggregator
  • C. FortiEDR Core
  • D. FortiEDR Central Manager

Answer: B


NEW QUESTION # 21
The FortiEDR axe classified an event as inconclusive, out a few seconds later FCS revised the classification to malicious. What playbook actions ate applied to the event?

  • A. Playbook actions applied to inconclusive events
  • B. Playbook actions applied to handled events
  • C. Playbook actions applied to malicious events
  • D. Playbook actions applied to suspicious events

Answer: C


NEW QUESTION # 22
How does FortiEDR implement post-infection protection?

  • A. By preventing data exfiltration or encryption even after a breach occurs
  • B. By using methods used by traditional EDR
  • C. By real-time filtering to prevent malware from executing
  • D. By insurance against ransomware

Answer: C


NEW QUESTION # 23
Refer to the exhibit.

Based on the postman output shown in the exhibit why is the user getting an unauthorized error?

  • A. FortiEDR requires a password reset the first time a user logs in
  • B. API access is disabled on the central manager
  • C. Postman cannot reach the central manager
  • D. The user has been assigned Admin and Rest API roles

Answer: D


NEW QUESTION # 24
Which two types of remote authentication does the FortiEDR management console support? (Choose two.)

  • A. TACACS
  • B. LDAP
  • C. SAML
  • D. Radius

Answer: B,D


NEW QUESTION # 25
Exhibit.

Based on the forensics data shown in the exhibit which two statements are true? (Choose two.)

  • A. The execution prevention policy has blocked this event.
  • B. The event was blocked because the certificate is unsigned
  • C. The device cannot be remediated
  • D. Device C8092231196 has been isolated

Answer: B,D


NEW QUESTION # 26
What is the purpose of the Threat Hunting feature?

  • A. Identify all instances of a known malicious file or hash and notify affected users
  • B. Execute playbooks to isolate affected collectors in the organization
  • C. Find and delete all instances ofa known malicious file or hash inthe organization
  • D. Delete any file from any collector in the organization

Answer: A


NEW QUESTION # 27
......


Fortinet NSE5_EDR-5.0 certification exam covers a range of topics including advanced threat prevention and detection, Fortinet's advanced threat prevention technologies, FortiEDR deployment, and advanced threat response. Candidates are also tested on their knowledge of advanced threat analysis techniques and Fortinet's advanced threat intelligence capabilities.

 

NSE5_EDR-5.0 Free Sample Questions to Practice One Year Update: https://actualtests.dumpsquestion.com/NSE5_EDR-5.0-exam-dumps-collection.html