최신 NSE 5 Network Security Analyst NSE5_FSM-5.2 무료샘플문제:
1. Refer to the exhibit.
A FortiSIEM is continuously receiving syslog events from a FortiGate firewall The FortiSlfcM administrator is trying to search the raw event logs for the last two hours that contain the keyword tcp . However, the administrator is getting no results from the search.
Based on the selected filters shown in the exhibit, why are there no search results?
A) The administrator selected AND in the Next drop-down list. This is the wrong boolean operator.
B) The keyword is case sensitive Instead of typing TCP in the Value field. the administrator should type tcp.
C) In the Time section, the administrator selected the Relative Last option, and in the drop-down lists, selected 2 and Hours as the lime period The time period should be 24 hours.
D) The administrator selected - in the Operator column That a the wrong operator.
2. Device discovery information is stored in which database?
A) SVN DB
B) Profile DB
C) CMDB
D) Event DB
3. In the advanced analytical rules engine in FortiSIEM, multiple subpatterms can be referenced using which three operation?(Choose three.)
A) FOLLOWED_BY
B) ELSE
C) AND
D) NOT
E) OR
4. A FortiSIEM administrator wants to restrict a network administrator to running searches for only firewall devices. Under role management, which option does the FortiSIEM administrator need to configure to achieve this scenario?
A) UI Access
B) CMDB Report Conditions
C) Data Conditions
질문과 대답:
질문 # 1 정답: D | 질문 # 2 정답: C | 질문 # 3 정답: B,C,D | 질문 # 4 정답: C |