Fortinet NSE5_FSM-5.2 Exam Overview:
| Certification Vendor: | Fortinet |
| Exam Name: | Fortinet NSE 5 - FortiSIEM 5.2 Certification Exam |
| Exam Number: | NSE5_FSM-5.2 |
| Related Certifications: | Fortinet NSE 4 Fortinet NSE 5 - FortiSIEM Fortinet Network Security Expert Program |
| Exam Price: | $200 USD (approximate, varies by region) |
| Available Languages: | English |
| Real Exam Qty: | 30-60 |
| Exam Duration: | 60-90 |
| Exam Format: | Multiple choice, Multiple select |
| Certificate Validity Period: | 2 years |
| Passing Score: | Approximately 60-70% |
| Recommended Training: | FortiSIEM 5.2 Administration Course (Fortinet Training Institute) |
| Exam Registration: | Fortinet Training & Certification Portal Pearson VUE Fortinet Exams |
| Sample Questions: | Fortinet NSE5_FSM-5.2 Sample Questions |
| Exam Way: | Online proctored or testing center (Pearson VUE) |
| Pre Condition: | Recommended prior experience with network security monitoring and Fortinet NSE 4 level knowledge. |
| Official Syllabus URL: | https://www.fortinet.com/training-certification |
Fortinet NSE5_FSM-5.2 Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| Topic 1: Monitoring and Reporting | - Performance monitoring
|
| Topic 2: FortiSIEM Architecture and Deployment | - System architecture components
|
| Topic 3: Event Management and Correlation | - Event processing pipeline
|
| Topic 4: Troubleshooting and Integration | - Issue diagnosis
|
| Topic 5: Configuration and Administration | - System maintenance
|
Fortinet NSE 5 - FortiSIEM 5.2 Sample Questions:
1. Which discovery scan type is prone to miss a device, if the device is quiet and the entry foe that device is not present in the ARP table of adjacent devices?
A) CMDB scan
B) Range scan
C) Smart scan
D) L2 scan
2. Device discovery information is stored in which database?
A) Profile DB
B) Event DB
C) SVN DB
D) CMDB
3. Refer to the exhibit.
Three events are collected over a 10-minutc time period from two servers Server A and Server B.
Based on the settings being used for the rule subpattern. how many incidents will the servers generate?
A) Server A will not generate any incidents and Server B will not generate any incidents
B) Server A will generate one incident and Server B will not generate any incidents
C) Server B will generate one incident and Server A will not generate any incidents
D) Server A will generate one incident and Server B wifl generate one incident
4. What is a prerequisite for a FortiSIEM supervisor with a worker deployment, using the proprietary flat file database?
A) The \archive mount must be on a local disk
B) The CMDB database must be on NFS
C) The event database must be on a local disk
D) The event database must be on NFS
5. In FotiSlEM enterprise licensing mode, if the link between the collector and data center FortiSlEM cluster a down what happens?
A) The collector drops incoming events like syslog. but slops performance collection
B) The collector processes stop, and events are dropped
C) The collector buffers events
D) The collector continues performance collection of devices, but stops receiving syslog
Solutions:
| Question # 1 Answer: C | Question # 2 Answer: D | Question # 3 Answer: A | Question # 4 Answer: D | Question # 5 Answer: B |
We're so confident of our products that we provide no hassle product exchange.


By Abel

