Exam Details

  • Exam Code
    :NSE5_EDR-5.0
  • Exam Name
    :Fortinet NSE 5 - FortiEDR 5.0
  • Certification
    :Fortinet Certifications
  • Vendor
    :Fortinet
  • Total Questions
    :41 Q&As
  • Last Updated
    :Jun 10, 2025

Fortinet Fortinet Certifications NSE5_EDR-5.0 Questions & Answers

  • Question 21:

    FortiXDR relies on which feature as part of its automated extended response?

    A. Playbooks

    B. Security Policies

    C. Forensic

    D. Communication Control

  • Question 22:

    The FortiEDR axe classified an event as inconclusive, out a few seconds later FCS revised the classification to malicious.

    What playbook actions ate applied to the event?

    A. Playbook actions applied to inconclusive events

    B. Playbook actions applied to handled events

    C. Playbook actions applied to suspicious events

    D. Playbook actions applied to malicious events

  • Question 23:

    Which two statements are true about the remediation function in the threat hunting module? (Choose two.)

    A. The file is removed from the affected collectors

    B. The threat hunting module sends the user a notification to delete the file

    C. The file is quarantined

    D. The threat hunting module deletes files from collectors that are currently online.

  • Question 24:

    Refer to the exhibit.

    Based on the event exception shown in the exhibit which two statements about the exception are true? (Choose two)

    A. A partial exception is applied to this event

    B. FCS playbooks is enabled by Fortinet support

    C. The exception is applied only on device C8092231196

    D. The system owner can modify the trigger rules parameters

  • Question 25:

    Refer to the exhibit.

    Based on the threat hunting query shown in the exhibit which of the following is true?

    A. RDP connections will be blocked and classified as suspicious

    B. A security event will be triggered when the device attempts a RDP connection

    C. This query is included in other organizations

    D. The query will only check for network category

  • Question 26:

    Refer to the exhibits.

    The exhibits show application policy logs and application details Collector C8092231196 is a member of the Finance group What must an administrator do to block the FileZilia application?

    A. Deny application in Finance policy

    B. Assign Finance policy to DBA group

    C. Assign Finance policy to Default Collector Group

    D. Assign Simulation Communication Control Policy to DBA group

  • Question 27:

    Refer to the exhibits.

    The exhibits show the collector state and active connections. The collector is unable to connect to aggregator IP address 10.160.6.100 using default port. Based on the netstat command output what must you do to resolve the connectivity issue?

    A. Reinstall collector agent and use port 443

    B. Reinstall collector agent and use port 8081

    C. Reinstall collector agent and use port 555

    D. Reinstall collector agent and use port 6514

  • Question 28:

    What is the benefit of using file hash along with the file name in a threat hunting repository search?

    A. It helps to make sure the hash is really a malware

    B. It helps to check the malware even if the malware variant uses a different file name

    C. It helps to find if some instances of the hash are actually associated with a different file

    D. It helps locate a file as threat hunting only allows hash search

  • Question 29:

    An administrator needs to restrict access to the ADMINISTRATION tab in the central manager for a specific account. What role should the administrator assign to this account?

    A. Admin

    B. User

    C. Local Admin

    D. REST API

  • Question 30:

    Exhibit.

    Based on the forensics data shown in the exhibit which two statements are true? (Choose two.)

    A. The device cannot be remediated

    B. The event was blocked because the certificate is unsigned

    C. Device C8092231196 has been isolated

    D. The execution prevention policy has blocked this event.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Fortinet exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your NSE5_EDR-5.0 exam preparations and Fortinet certification application, do not hesitate to visit our Vcedump.com to find your solutions here.