Exit demo NSE5_EDR-5.0 Fortinet NSE 5 - FortiEDR 5.0 PDF format · free preview

Fortinet NSE5_EDR-5.0 - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/nse5-edr-50.html

Question 1
Single choice

What is true about classifications assigned by Fortinet Cloud Sen/ice (FCS)?

A.

The core is responsible for all classifications if FCS playbooks are disabled

B.

The core only assigns a classification if FCS is not available

C.

FCS revises the classification of the core based on its database

D.

FCS is responsible for all classifications

Question 2
Multiple choice

Refer to the exhibit.

Based on the event shown in the exhibit, which two statements about the event are true? (Choose two.)

A.

The NGAV policy has blocked TestApplication exe

B.

TestApplication exe is sophisticated malware

C.

The user was able to launch TestApplication exe

D.

FCS classified the event as malicious

Question 3
Single choice

How does FortiEDR implement post-infection protection?

A.

By preventing data exfiltration or encryption even after a breach occurs

B.

By using methods used by traditional EDR

C.

By insurance against ransomware

D.

By real-time filtering to prevent malware from executing

Question 4
Single choice

Which scripting language is supported by the FortiEDR action managed?

A.

TCL

B.

Python

C.

Perl

D.

Bash

Question 5
Single choice

Which security policy has all of its rules disabled by default?

A.

Device Control

B.

Ransomware Prevention

C.

Execution Prevention

D.

Exfiltration Prevention

Question 6
Multiple choice

Which connectors can you use for the FortiEDR automated incident response? (Choose two.)

A.

FortiNAC

B.

FortiGate

C.

FortiSiem

D.

FortiSandbox

Question 7
Multiple choice

Exhibit.

Based on the event shown in the exhibit which two statements about the event are true? (Choose two.)

A.

The device is moved to isolation.

B.

Playbooks is configured for this event.

C.

The event has been blocked

D.

The policy is in simulation mode

Question 8
Single choice

Which FortiEDR component is required to find malicious files on the entire network of an organization?

A.

FortiEDR Aggregator

B.

FortiEDR Central Manager

C.

FortiEDR Threat Hunting Repository

D.

FortiEDR Core

Question 9
Single choice

Which threat hunting profile is the most resource intensive?

A.

Comprehensive

B.

Inventory

C.

Default

D.

Standard Collection

Question 10
Single choice

What is the role of a collector in the communication control policy?

A.

A collector blocks unsafe applications from running

B.

A collector is used to change the reputation score of any application that collector runs

C.

A collector records applications that communicate externally

D.

A collector can quarantine unsafe applications from communicating

Showing 10 of 41 questions · Unlock the full set