Authentic Fortinet NSE5_EDR-5.0 Exam Dumps PDF - Oct-2023 Updated
NSE5_EDR-5.0 Dumps Special Discount for limited time Try FOR FREE
NEW QUESTION # 16
Refer to the exhibits.

The exhibits show application policy logs and application details Collector C8092231196 is a member of the Finance group What must an administrator do to block the FileZilia application?
- A. Assign Simulation Communication Control Policy to DBA group
- B. Assign Finance policy to DBA group
- C. Deny application in Finance policy
- D. Assign Finance policy to Default Collector Group
Answer: A
NEW QUESTION # 17
Which two statements about the FortiEDR solution are true? (Choose two.)
- A. It provides central management
- B. It is Windows OS only
- C. It provides pre-infection and post-infection protection
- D. It provides pant-to-point protection
Answer: C,D
NEW QUESTION # 18
What is the benefit of using file hash along with the file name in a threat hunting repository search?
- A. It helps locate a file as threat hunting only allows hash search
- B. It helps to make sure the hash is really a malware
- C. It helps to check the malware even if the malware variant uses a different file name
- D. It helps to find if some instances of the hash are actually associated with a different file
Answer: D
NEW QUESTION # 19
Which scripting language is supported by the FortiEDR action managed?
- A. Bash
- B. Perl
- C. TCL
- D. Python
Answer: C
NEW QUESTION # 20
Refer to the exhibit.
Based on the postman output shown in the exhibit why is the user getting an unauthorized error?
- A. FortiEDR requires a password reset the first time a user logs in
- B. API access is disabled on the central manager
- C. The user has been assigned Admin and Rest API roles
- D. Postman cannot reach the central manager
Answer: C
NEW QUESTION # 21
Exhibit.
Based on the forensics data shown in the exhibit which two statements are true? (Choose two.)
- A. The event was blocked because the certificate is unsigned
- B. Device C8092231196 has been isolated
- C. The device cannot be remediated
- D. The execution prevention policy has blocked this event.
Answer: A,B
NEW QUESTION # 22
Refer to the exhibits.

The exhibits show the collector state and active connections. The collector is unable to connect to aggregator IP address 10.160.6.100 using default port.
Based on the netstat command output what must you do to resolve the connectivity issue?
- A. Reinstall collector agent and use port 6514
- B. Reinstall collector agent and use port 443
- C. Reinstall collector agent and use port 555
- D. Reinstall collector agent and use port 8081
Answer: D
NEW QUESTION # 23
An administrator finds a third party free software on a user's computer mat does not appear in me application list in the communication control console Which two statements are true about this situation? (Choose two)
- A. The application has not made any connection attempts
- B. The application is blocked by the security policies
- C. The application is ignored as the reputation score is acceptable by the security policy
- D. The application is allowed in all communication control policies
Answer: B,D
NEW QUESTION # 24
Which two types of remote authentication does the FortiEDR management console support? (Choose two.)
- A. SAML
- B. TACACS
- C. LDAP
- D. Radius
Answer: C,D
NEW QUESTION # 25
A FortiEDR security event is causing a performance issue with a third-parry application. What must you do first about the event?
- A. Terminate the process and uninstall the third-party application
- B. Investigate the event to verify whether or not the application is safe
- C. Contact Fortinet support
- D. Immediately create an exception
Answer: D
NEW QUESTION # 26
A company requires a global communication policy for a FortiEDR multi-tenant environment.
How can the administrator achieve this?
- A. An administrator creates a new communication control policy and shares it with other organizations
- B. An administrator creates a new communication control policy for each organization
- C. A local administrator creates new a communication control policy and shares it with other organizations
- D. A local administrator creates a new communication control policy and assigns it globally to all organizations
Answer: D
NEW QUESTION # 27
Which two statements are true about the remediation function in the threat hunting module? (Choose two.)
- A. The file is quarantined
- B. The threat hunting module deletes files from collectors that are currently online.
- C. The threat hunting module sends the user a notification to delete the file
- D. The file is removed from the affected collectors
Answer: A,C
NEW QUESTION # 28
......
NSE5_EDR-5.0 Dumps for success in Actual Exam: https://www.actualvce.com/Fortinet/NSE5_EDR-5.0-valid-vce-dumps.html