Get Instant Access to NSE5_EDR-5.0 Practice Exam Questions
Reliable Study Materials & Testing Engine for NSE5_EDR-5.0 Exam Success!
Fortinet NSE5_EDR-5.0 certification is highly valued in the cybersecurity industry, as it demonstrates an individual's ability to effectively use the FortiEDR solution to secure endpoints and detect and respond to security threats. Fortinet NSE 5 - FortiEDR 5.0 certification is suitable for security analysts, network administrators, security architects, and other professionals who are responsible for securing network endpoints.
To prepare for the NSE5_EDR-5.0 exam, candidates should have a solid understanding of network security and endpoint protection concepts. They should also have experience working with Fortinet's FortiEDR 5.0 solution, as well as other security technologies. Fortinet offers a range of training resources to help candidates prepare for the exam, including self-paced courses, instructor-led training, and hands-on labs. With the NSE5_EDR-5.0 certification, IT professionals can demonstrate their expertise in network security and endpoint protection, which can lead to career advancement and increased job opportunities.
NEW QUESTION # 17
Refer to the exhibit.
Based on the threat hunting query shown in the exhibit which of the following is true?
- A. A security event will be triggered when the device attempts a RDP connection
- B. The query will only check for network category
- C. RDP connections will be blocked and classified as suspicious
- D. This query is included in other organizations
Answer: A
NEW QUESTION # 18
Which two statements are true about the remediation function in the threat hunting module? (Choose two.)
- A. The file is removed from the affected collectors
- B. The threat hunting module deletes files from collectors that are currently online.
- C. The threat hunting module sends the user a notification to delete the file
- D. The file is quarantined
Answer: C,D
NEW QUESTION # 19
Refer to the exhibits.

The exhibits show the collector state and active connections. The collector is unable to connect to aggregator IP address 10.160.6.100 using default port.
Based on the netstat command output what must you do to resolve the connectivity issue?
- A. Reinstall collector agent and use port 8081
- B. Reinstall collector agent and use port 6514
- C. Reinstall collector agent and use port 555
- D. Reinstall collector agent and use port 443
Answer: A
NEW QUESTION # 20
FortiXDR relies on which feature as part of its automated extended response?
- A. Security Policies
- B. Forensic
- C. Communication Control
- D. Playbooks
Answer: A
NEW QUESTION # 21
Exhibit.
Based on the forensics data shown in the exhibit, which two statements are true? (Choose two.)
- A. The device has been isolated
- B. The forensics data is displayed m the stacks view
- C. An exception has been created for this event
- D. The exfiltration prevention policy has blocked this event
Answer: A,D
NEW QUESTION # 22
What is true about classifications assigned by Fortinet Cloud Sen/ice (FCS)?
- A. FCS revises the classification of the core based on its database
- B. The core only assigns a classification if FCS is not available
- C. The core is responsible for all classifications if FCS playbooks are disabled
- D. FCS is responsible for all classifications
Answer: A
NEW QUESTION # 23
What is the role of a collector in the communication control policy?
- A. A collector is used to change the reputation score of any application that collector runs
- B. A collector records applications that communicate externally
- C. A collector can quarantine unsafe applications from communicating
- D. A collector blocks unsafe applications from running
Answer: D
NEW QUESTION # 24
Exhibit.
Based on the event shown in the exhibit which two statements about the event are true? (Choose two.)
- A. The event has been blocked
- B. Playbooks is configured for this event.
- C. The device is moved to isolation.
- D. The policy is in simulation mode
Answer: B,D
NEW QUESTION # 25
Which security policy has all of its rules disabled by default?
- A. Execution Prevention
- B. Device Control
- C. Ransomware Prevention
- D. Exfiltration Prevention
Answer: C
NEW QUESTION # 26
An administrator finds a third party free software on a user's computer mat does not appear in me application list in the communication control console Which two statements are true about this situation? (Choose two)
- A. The application has not made any connection attempts
- B. The application is ignored as the reputation score is acceptable by the security policy
- C. The application is allowed in all communication control policies
- D. The application is blocked by the security policies
Answer: C,D
NEW QUESTION # 27
Which two statements about the FortiEDR solution are true? (Choose two.)
- A. It provides pant-to-point protection
- B. It is Windows OS only
- C. It provides pre-infection and post-infection protection
- D. It provides central management
Answer: A,C
NEW QUESTION # 28
Refer to the exhibit.
Based on the event shown in the exhibit, which two statements about the event are true? (Choose two.)
- A. FCS classified the event as malicious
- B. The user was able to launch TestApplication exe
- C. TestApplication exe is sophisticated malware
- D. The NGAV policy has blocked TestApplication exe
Answer: C,D
NEW QUESTION # 29
......
Validate your Skills with Updated NSE5_EDR-5.0 Exam Questions & Answers and Test Engine: https://examsboost.dumpstorrent.com/NSE5_EDR-5.0-exam-prep.html