Fortinet NSE5_FSM-5.2 Exam Overview:
| Certification Vendor: | Fortinet |
|---|---|
| Exam Name: | Fortinet NSE 5 - FortiSIEM 5.2 Certification Exam |
| Exam Number: | NSE5_FSM-5.2 |
| Related Certifications: | Fortinet Network Security Expert Program Fortinet NSE 4 Fortinet NSE 5 - FortiSIEM |
| Exam Price: | $200 USD (approximate, varies by region) |
| Available Languages: | English |
| Real Exam Qty: | 30-60 |
| Exam Duration: | 60-90 |
| Exam Format: | Multiple select, Multiple choice |
| Certificate Validity Period: | 2 years |
| Passing Score: | Approximately 60-70% |
| Recommended Training: | FortiSIEM 5.2 Administration Course (Fortinet Training Institute) |
| Exam Registration: | Fortinet Training & Certification Portal Pearson VUE Fortinet Exams |
| Sample Questions: | Fortinet NSE5_FSM-5.2 Sample Questions |
| Exam Way: | Online proctored or testing center (Pearson VUE) |
| Pre Condition: | Recommended prior experience with network security monitoring and Fortinet NSE 4 level knowledge. |
| Official Syllabus URL: | https://www.fortinet.com/training-certification |
Fortinet NSE5_FSM-5.2 Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| Topic 1: Monitoring and Reporting | - Performance monitoring
|
| Topic 2: FortiSIEM Architecture and Deployment | - System architecture components
|
| Topic 3: Event Management and Correlation | - Event processing pipeline
|
| Topic 4: Troubleshooting and Integration | - Issue diagnosis
|
| Topic 5: Configuration and Administration | - System maintenance
|
Fortinet NSE 5 - FortiSIEM 5.2 Sample Questions:
Which discovery scan type is prone to miss a device, if the device is quiet and the entry foe that device is not present in the ARP table of adjacent devices?
- A. CMDB scan
- B. Range scan
- C. Smart scan
- D. L2 scan
Correct Answer: C 🗳️
Device discovery information is stored in which database?
- A. Profile DB
- B. Event DB
- C. SVN DB
- D. CMDB
Correct Answer: D 🗳️
Refer to the exhibit.
Three events are collected over a 10-minutc time period from two servers Server A and Server B.
Based on the settings being used for the rule subpattern. how many incidents will the servers generate?
- A. Server A will not generate any incidents and Server B will not generate any incidents
- B. Server A will generate one incident and Server B will not generate any incidents
- C. Server B will generate one incident and Server A will not generate any incidents
- D. Server A will generate one incident and Server B wifl generate one incident
Correct Answer: A 🗳️
What is a prerequisite for a FortiSIEM supervisor with a worker deployment, using the proprietary flat file database?
- A. The \archive mount must be on a local disk
- B. The CMDB database must be on NFS
- C. The event database must be on a local disk
- D. The event database must be on NFS
Correct Answer: D 🗳️
In FotiSlEM enterprise licensing mode, if the link between the collector and data center FortiSlEM cluster a down what happens?
- A. The collector drops incoming events like syslog. but slops performance collection
- B. The collector processes stop, and events are dropped
- C. The collector buffers events
- D. The collector continues performance collection of devices, but stops receiving syslog
Correct Answer: B 🗳️
We're so confident of our products that we provide no hassle product exchange.


By Arno

