Fortinet NSE 5 - FortiSIEM 5.2 NSE5_FSM-5.2 Prüfungsfragen mit Lösungen:
1. To determine whether or not syslog is being received from a network device, which is the best command from the backend?
A) tcpdump
B) phSyslogRecorder
C) phDeviceTest
D) netcat
2. Refer to the exhibit.
A FortiSIEM administrator wants to collect both SIEM event logs and performance and availability metrics (PAM) events from a Microsoft Windows server Which protocol should the administrator select in the Access Protocol drop-down list so that FortiSIEM will collect both SIEM and PAM events?
A) TELNET
B) LDAPS
C) WMI
D) LDAP start TLS
3. What are the minimum memory requirements for the FortiSIEM supervisor virtual appliance, when the proprietary flat file database is used?
A) 24GB RAM
B) 16GB RAM
C) 64GB RAM
D) 32GB RAM
4. Refer to the exhibit.
A FortiSIEM is continuously receiving syslog events from a FortiGate firewall The FortiSlfcM administrator is trying to search the raw event logs for the last two hours that contain the keyword tcp . However, the administrator is getting no results from the search.
Based on the selected filters shown in the exhibit, why are there no search results?
A) The keyword is case sensitive Instead of typing TCP in the Value field. the administrator should type tcp.
B) In the Time section, the administrator selected the Relative Last option, and in the drop-down lists, selected 2 and Hours as the lime period The time period should be 24 hours.
C) The administrator selected AND in the Next drop-down list. This is the wrong boolean operator.
D) The administrator selected - in the Operator column That a the wrong operator.
5. Which three ports can be used to send Syslogs to FortiSIEM? (Choose three.)
A) UDP 514
B) UDP 162
C) UDP9999
D) TCP 514
E) TCP 1470
Fragen und Antworten:
| 1. Frage Antwort: A | 2. Frage Antwort: A | 3. Frage Antwort: A | 4. Frage Antwort: D | 5. Frage Antwort: A,D,E |






1151 Kundenbewertungen

