Fortinet nse5-edr-5-0 practice test

Exam Title: Fortinet NSE 5 - FortiEDR 5.0

Last update: Nov 27 ,2025
Question 1

Which connectors can you use for the FortiEDR automated incident response? (Choose two.)

  • A. FortiNAC
  • B. FortiGate
  • C. FortiSiem
  • D. FortiSandbox
Answer:

B, C


vote your answer:
A
B
C
D
A 0 B 0 C 0 D 0
Comments
Question 2

What is true about classifications assigned by Fortinet Cloud Sen/ice (FCS)?

  • A. The core is responsible for all classifications if FCS playbooks are disabled
  • B. The core only assigns a classification if FCS is not available
  • C. FCS revises the classification of the core based on its database
  • D. FCS is responsible for all classifications
Answer:

C


vote your answer:
A
B
C
D
A 0 B 0 C 0 D 0
Comments
Question 3

Refer to the exhibit.

Based on the FortiEDR status output shown in the exhibit, which two statements about the FortiEDR
collector are true? (Choose two.)

  • A. The collector device has windows firewall enabled
  • B. The collector has been installed with an incorrect port number
  • C. The collector has been installed with an incorrect registration password
  • D. The collector device cannot reach the central manager
Answer:

B, D


vote your answer:
A
B
C
D
A 0 B 0 C 0 D 0
Comments
Question 4

A company requires a global communication policy for a FortiEDR multi-tenant environment.
How can the administrator achieve this?

  • A. An administrator creates a new communication control policy and shares it with other organizations
  • B. A local administrator creates new a communication control policy and shares it with other organizations
  • C. A local administrator creates a new communication control policy and assigns it globally to all organizations
  • D. An administrator creates a new communication control policy for each organization
Answer:

C


vote your answer:
A
B
C
D
A 0 B 0 C 0 D 0
Comments
Question 5

Refer to the exhibit.

Based on the event exception shown in the exhibit which two statements about the exception are
true? (Choose two)

  • A. A partial exception is applied to this event
  • B. FCS playbooks is enabled by Fortinet support
  • C. The exception is applied only on device C8092231196
  • D. The system owner can modify the trigger rules parameters
Answer:

A, C


vote your answer:
A
B
C
D
A 0 B 0 C 0 D 0
Comments
Question 6

Which two statements are true about the remediation function in the threat hunting module?
(Choose two.)

  • A. The file is removed from the affected collectors
  • B. The threat hunting module sends the user a notification to delete the file
  • C. The file is quarantined
  • D. The threat hunting module deletes files from collectors that are currently online.
Answer:

B, C


vote your answer:
A
B
C
D
A 0 B 0 C 0 D 0
Comments
Question 7

Exhibit.

Based on the forensics data shown in the exhibit, which two statements are true? (Choose two.)

  • A. An exception has been created for this event
  • B. The forensics data is displayed m the stacks view
  • C. The device has been isolated
  • D. The exfiltration prevention policy has blocked this event
Answer:

C, D


vote your answer:
A
B
C
D
A 0 B 0 C 0 D 0
Comments
Question 8

The FortiEDR axe classified an event as inconclusive, out a few seconds later FCS revised the
classification to malicious. What playbook actions ate applied to the event?

  • A. Playbook actions applied to inconclusive events
  • B. Playbook actions applied to handled events
  • C. Playbook actions applied to suspicious events
  • D. Playbook actions applied to malicious events
Answer:

D


vote your answer:
A
B
C
D
A 0 B 0 C 0 D 0
Comments
Question 9

Which threat hunting profile is the most resource intensive?

  • A. Comprehensive
  • B. Inventory
  • C. Default
  • D. Standard Collection
Answer:

A


vote your answer:
A
B
C
D
A 0 B 0 C 0 D 0
Comments
Question 10

Which two types of remote authentication does the FortiEDR management console support?
(Choose two.)

  • A. Radius
  • B. SAML
  • C. TACACS
  • D. LDAP
Answer:

A, D


vote your answer:
A
B
C
D
A 0 B 0 C 0 D 0
Comments
Page 1 out of 2
Viewing questions 1-10 out of 30
Go To
page 2