Fortinet NSE 5 - FortiEDR 5.0 (NSE5_EDR) - Fortinet Actual Exam Questions
Last updated on April 25, 2026
Exhibit. Based on the forensics data shown in the exhibit which two statements are true? (Choose two.)
The device cannot be remediated
The event was blocked because the certificate is unsigned
Device C8092231196 has been isolated
The execution prevention policy has blocked this event.
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
Refer to the exhibit. Based on the threat hunting query shown in the exhibit which of the following is true?
RDP connections will be blocked and classified as suspicious
A security event will be triggered when the device attempts a RDP connection
This query is included in other organizations
The query will only check for network category
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
An administrator needs to restrict access to the ADMINISTRATION tab in the central manager for a specific account. What role should the administrator assign to this account?
Admin
User
Local Admin
REST API
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
What is true about classifications assigned by Fortinet Cloud Sen/ice (FCS)?
The core is responsible for all classifications if FCS playbooks are disabled
The core only assigns a classification if FCS is not available
FCS revises the classification of the core based on its database
FCS is responsible for all classifications
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
What is the benefit of using file hash along with the file name in a threat hunting repository search?
It helps to make sure the hash is really a malware
It helps to check the malware even if the malware variant uses a different file name
It helps to find if some instances of the hash are actually associated with a different file
It helps locate a file as threat hunting only allows hash search
to join the discussion
No discussions yet. Be the first to ask!
Delete Comment
Are you sure? This action cannot be undone.
Finish Practice?
Are you sure you want to finish? This will end your practice session.