Font size
WorksheetsEXAM NSE5_EDR-5.0
Total questions: 42
Worksheet time: 25mins
Which two types of remote authentication does the FortiEDR management console support? (Choose two.)
TACACS
Radius
LDAP
SAML
Which two types of traffic are allowed while the device is in isolation mode? (Choose two.)
HTTP sessions
ICMP sessions
Incoming RDP connections
Outgoing SSH connections
Which FortiEDR component must have JumpBox functionality to connect with FortiAnalyzer?
Collector
Aggregator
Core
Central manager
Which two statements are true about the remediation function in the threat hunting module? (Choose two.)
The file is quarantined.
The file is removed from the affected collectors.
The threat hunting module deletes files from collectors that are currently online.
The threat hunting module sends the user a notification to delete the file.
Which FortiEDR component is required to find malicious files on the entire network of an organization?
FortiEDR Core
FortiEDR Central Manager
FortiEDR Threat Hunting Repository
FortiEDR Aggregator
A company requires a global communication policy for a FortiEDR multi-tenant environment.
How can the administrator achieve this?
An administrator creates a new communication control policy and shares it with other organizations.
A local administrator creates a new communication control policy and shares it with other organizations.
A local administrator creates a new communication control policy and assigns it globally to all organizations.
An administrator creates a new communication control policy for each organization.
FortiXDR relies on which feature as part of its automated extended response?
Security Policies
Forensic
Playbooks
Communication Control
A company requires a global exception for a FortiEDR multi-tenant environment.
How can the administrator achieve this?
The local administrator can create a new exception and share it with other organizations.
A user account can create a new exception and share it with other organizations.
The administrator can create a new exception and assign it globally to all organizations.
The administrator can create a new exception policy for each organization hosted on FortiEDR.
An administrator needs to restrict access to the ADMINISTRATION tab in the central manager for a specific account.
What role should the administrator assign to this account?
User
Admin
REST API
Local Admin
What is the purpose of the Threat Hunting feature?
Execute playbooks to isolate affected collectors in the organization
Find and delete all instances of a known malicious file or hash in the organization
Delete any file from any collector in the organization
Identify all instances of a known malicious file or hash and notify affected users
Which two investigation issues requires a full memory dump of the FortiEDR collector? (Choose two.)
System hang issue
Third-party application issues
System crash issue
Collector and core connectivity issue events
Which connectors can you use for the FortiEDR automated incident response? (Choose two.)
FortiSandbox
FortiNAC
FortiSiem
FortiGate
How does FortiEDR implement post-infection protection?
By preventing data exfiltration or encryption even after a breach occurs
By insurance against ransomware
By real-time filtering to prevent malware from executing
By using methods used by traditional EDR
What is the benefit of using file hash along with the file name in a threat hunting repository search?
It helps to check the malware even if the malware variant uses a different file name.
It helps to make sure the hash is really a malware.
It helps to find if some instances of the hash are actually associated with a different file.
It helps locate a file as threat hunting only allows hash search.
Which threat hunting profile is the most resource intensive?
Inventory
Comprehensive
Standard Collection
Default
What is the role of a collector in the communication control policy?
A collector is used to change the reputation score of any application that collector runs
A collector can quarantine unsafe applications from communicating
A collector blocks unsafe applications from running
A collector records applications that communicate externally
How does the FortiEDR approach compare to the traditional EDR? (Choose two.)
FortiEDR blocks threats in real time, eliminating the response gap
Traditional EDR is faster
There is no difference in response time
FortiEDR requires less staff
Which two events can trigger FortiEDR NGAV policy violations? (Choose two.)
When a malicious file attempts to communicate externally
When a malicious file is executed
When a malicious file is read
When a malicious file attempts to access data
An administrator finds a third party free software on a user’s computer that does not appear in the application list in the communication control console.
Which two statements are true about this situation? (Choose two.)
The application is allowed in all communication control policies
The application is blocked by the security policies
The application is ignored as the reputation score is acceptable by the security policy
The application has not made any connection attempts
What is true about classifications assigned by Fortinet Cloud Service (FCS)?
FCS revises the classification of the core based on its database.
The core only assigns a classification if FCS is not available.
FCS is responsible for all classifications.
The core is responsible for all classifications if FCS playbooks are disabled.
Which statement is true about the flow analyzer view in forensics?
Two events can be compared side-by-side.
It shows details about processes and sub processes.
It displays a graphic flow diagram.
The stack memory of a specific device can be retrieved.
The FortiEDR core classified an event as inconclusive, but a few seconds later FCS revised the classification to malicious.
What playbook actions are applied to the event?
Playbook actions applied to suspicious events
Playbook actions applied to inconclusive events
Playbook actions applied to handled events
Playbook actions applied to malicious events
When installing a FortiEDR collector, why is a ‘Registration Password’ for collectors needed?
To restrict installation and uninstallation of collectors
To verify Fortinet support request
To restrict access to the management console
To verify new group assignment
An administrator finds that a newly installed collector does not display on the INVENTORY tab in the central manager.
What two troubleshooting steps must the administrator perform? (Choose two.)
Export the collector logs from the central manager.
Verify the central manager has connectivity to FCS.
Verify TCP ports 8081 and 555 are open.
Check if the FortiEDR services are running on the collector device.
Which security policy has all of its rules disabled by default?
Exfiltration Prevention
Execution Prevention
Device Control
Ransomware Prevention
With respect to operating FortiEDR, what does proactive risk mitigation refer to?
Automatically blocking users from installing unauthorized applications
Automatically blocking endpoints from communicating to network resources
Automatically blocking applications from communicating if they have a poor reputation or CVE score
Automatically blocking communication from all applications unless they are specifically enabled
Which FortiEDR protection uses NGAV functionality?
Incident Response
Pre-infection
Risk Mitigation
Post-infection
A FortiEDR security event is causing a performance issue with a third-party application.
What must you do first about the event?
Investigate the event to verify whether or not the application is safe
Contact Fortinet support
Terminate the process and uninstall the third-party application
Immediately create an exception
Which three steps does FortiXDR perform to find and prevent cyberattacks? (Choose three.)
Extended analysis
Extended detection
Extended discovery
Extended investigation
Extended response
Which two criteria are requirements of integrating FortiEDR into the Fortinet Security Fabric? (Choose two.)
Core with Core only functionality
A Forensics add-on license
Central Manager connected to FCS
A valid API user with access to connectors
What is true about the Payroll Manager.exe event?
An event has not been handled by a console admin
An event has been deleted
A rule assigned action is set to block but the policy is in simulation mode
An event has been handled by the communication control policy
Based on the event exception shown in the exhibit, which two statements about the exception are true? (Choose two.)
FCS playbooks is enabled by Fortinet support.
The system owner can modify the trigger rules parameters.
A partial exception is applied to this event.
The exception is applied only on device C8092231196.
Based on the postman output shown in the exhibit, why is the user getting an unauthorized error?
Postman cannot reach the central manager.
API access is disabled on the central manager.
The user has been assigned Admin and Rest API roles.
FortiEDR requires a password reset the first time a user logs in.
The exhibits show the collector state and active connections. The collector is unable to connect to aggregator IP address 10.160.6.100 using default port.
Based on the netstat command output what must you do to resolve the connectivity issue?
Reinstall collector agent and use port 555
Reinstall collector agent and use port 443
Reinstall collector agent and use port 8081
Reinstall collector agent and use port 6514
Based on the forensics data shown in the exhibit, which two statements are true? (Choose two.)
An exception has been created for this event.
The device has been isolated.
The forensics data is displayed in the stacks view.
The exfiltration prevention policy has blocked this event.
Based on the event shown in the exhibit, which two statements about the event are true? (Choose two.)
The policy is in simulation mode.
The device is moved to isolation.
The event has been blocked.
Playbooks is configured for this event.
The exhibits show application policy logs and application details. Collector C8092231196 is a member of the Finance group.
What must an administrator do to block the FileZilla application?
Deny application in Finance policy
Assign Finance policy to DBA group
Assign Finance policy to Default Collector Group
Assign Simulation Communication Control Policy to DBA group
Based on the threat hunting event details shown in the exhibit, which two statements about the event are true? (Choose two.)
The activity event is associated with the file action.
The user fortinet has executed a ping command.
The PING.EXE process was blocked.
There are no MITRE details available for this event.
Based on the event shown in the exhibit, which two statements about the event are true? (Choose two.)
The NGAV policy has blocked TestApplication.exe.
FCS classified the event as malicious.
TestApplication.exe is sophisticated malware.
The user was able to launch TestApplication.exe.
Based on the forensics data shown in the exhibit, which two statements are true? (Choose two.)
The device cannot be remediated
The execution prevention policy has blocked this event.
The event was blocked because the certificate is unsigned.
Device C8092231196 has been isolated.
Based on the threat hunting query shown in the exhibit, which of the following is true?
A security event will be triggered when the device attempts a RDP connection.
This query is included in other organizations.
The query will only check for network category.
RDP connections will be blocked and classified as suspicious.
Based on the FortiEDR status output shown in the exhibit, which two statements about the FortiEDR collector are true? (Choose two.)
The collector device has windows firewall enabled.
The collector has been installed with an incorrect port number.
The collector has been installed with an incorrect registration password.
The collector device cannot reach the central manager.
