Fortinet NSE 5 - FortiEDR 5.0 Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 244 questions. Use the simulator for timed and flashcard mode.

Try Simulator

NSE5-EDR-5-0 Sample Questions

  1. Question 1

    Q1

    A financial institution is deploying FortiEDR in a multi-tenancy model to serve different internal departments as separate tenants. The security architect needs to ensure that administrators for the 'Investment Banking' tenant cannot view or manage endpoints belonging to the 'Retail Banking' tenant. Which FortiEDR feature is the primary mechanism for enforcing this level of strict data and administrative segregation?

    Show answer & explanation

    Correct answer: C

    FortiEDR's multi-tenancy is built around the concept of 'Organizations'. Each Organization is a self-contained unit with its own devices, policies, events, and administrators. Data and administrative access are strictly isolated at the Organization level by design, which is the primary mechanism for achieving the required segregation. While RBAC and device groups are used for granular control within an Organization, they do not provide the foundational separation between tenants.

  2. Question 2

    Q2

    A security operator at a Managed Security Service Provider (MSSP) is using the FortiEDR REST API to automate the onboarding of new customers. The script needs to perform the following actions in order: create a new Organization for the customer, generate a collector installation package for that specific Organization, and then assign a default security policy. Which API endpoint would be used to generate the customer-specific collector package?

    Show answer & explanation

    Correct answer: B

    The FortiEDR REST API uses specific endpoints to manage resources. To generate a collector installation package that is tied to a particular tenant (Organization), the API call must be made to an endpoint that is scoped to that Organization's ID. The correct endpoint structure is /api/v1/organizations/{org_id}/installers, where {org_id} is the unique identifier for the newly created customer Organization. The other options are either incorrectly formatted or do not scope the request to a specific organization.

  3. Question 3

    Q3

    A hospital is using FortiEDR to protect legacy medical devices running an unsupported version of Windows. These devices use a proprietary, unsigned application for critical operations. The 'Execution Prevention' security policy is blocking this application, causing service disruption. The administrator needs to allow this specific application to run without weakening the overall security posture for other applications. What is the most precise and secure method to create this exception in FortiEDR?

    Show answer & explanation

    Correct answer: D

    The most secure and precise method for creating an exception is to use the application's cryptographic hash (SHA-256). This ensures that only the exact, unaltered proprietary application is allowed to run. An exception based on file path is less secure, as malware could potentially replace the legitimate file at that location. Disabling the policy or setting it to log-only mode would significantly weaken the security for all other applications on the devices, which is not desirable.

  4. Question 4

    Q4

    A security team has designed a FortiEDR playbook to automatically respond to 'Malicious File Detected' events on standard user workstations. The desired workflow is: 1) Isolate the affected device, 2) Terminate the malicious process, 3) Delete the malicious file, and 4) Open a ticket in a third-party system via a webhook. The administrator observes that devices are being isolated, but the malicious process is not being terminated. What is the most likely cause for this partial playbook execution?

    Show answer & explanation

    Correct answer: D

    FortiEDR playbooks execute actions sequentially. If the 'Stop on Failure' option is enabled (which is common), and a preceding action like 'Isolate Device' fails or times out (e.g., due to network issues with the endpoint), the playbook will halt execution and subsequent actions like 'Terminate Process' will not be attempted. The administrator should check the playbook execution logs for failures in the 'Isolate Device' step.

  5. Question 5

    Q5

    A SOC analyst is investigating a complex alert and needs to understand the full attack chain. The analyst wants to find all network connections made by a specific process, svchost.exe, that were initiated after a suspicious PowerShell command was executed on the endpoint CORP-WS-123. Which FortiEDR feature provides the most effective and direct way to perform this type of historical, correlated analysis?

    Show answer & explanation

    Correct answer: C

    The Forensics analysis view is designed for deep-dive investigations into endpoint activity. It collects and correlates a rich set of data, including process creation, file modifications, registry changes, and network connections, presenting them in a timeline and process tree. This allows the analyst to filter for the specific device, locate the PowerShell execution event, and then examine all subsequent activities, including network connections made by svchost.exe, to reconstruct the attack chain directly.

  6. Question 6

    Q6Multiple answers

    A threat hunter suspects that an attacker is using a living-off-the-land technique by running malicious scripts via the legitimate Windows utility wmic.exe. The hunter wants to create a query to find all instances where wmic.exe was launched with the command-line argument process call create. Which two components are required to build this query in the FortiEDR Threat Hunting interface? (Select TWO).

    Show answer & explanation

    Correct answers: A, B, E

    To construct this threat hunting query, the analyst needs to specify the type of event to look for and the specific attributes of that event. The core event is the creation of a process. Therefore, 'Event Type: Process Creation' is the correct starting point. Then, to find the specific utility and its arguments, two filters are needed: one to specify the process name (wmic.exe) and another to search within its command line for the specific malicious arguments (process call create). While both filters are correct, the question asks for two required components, and the event type is fundamental. The combination of Process Creation event type and filters on Process Name and Process Command Line is necessary.

  7. Question 7

    Q7

    An organization has integrated FortiEDR with their FortiGate firewall as part of the Security Fabric. A playbook is configured to use the 'Block address with FortiGate' action when a high-severity threat is detected. After an event, the security team notices the endpoint's IP address was not blocked on the FortiGate. Troubleshooting reveals that the Fabric connection is up and other integrations are working. What is a likely misconfiguration specific to this automated response action?

    Show answer & explanation

    Correct answer: B

    The 'Block address with FortiGate' action in a FortiEDR playbook requires a specific parameter: the name of an existing address group on the target FortiGate. FortiEDR adds the offending IP address to this pre-defined group, which must then be used in a firewall policy on the FortiGate to deny traffic. If this address group name is missing or misspelled in the playbook action configuration, FortiEDR cannot tell the FortiGate where to place the IP, and the block will fail even if the Fabric connection is healthy.

  8. Question 8

    Q8

    A FortiEDR collector on a critical server is repeatedly disconnecting and reconnecting to the Central Manager, causing alert floods and inconsistent policy application. The network team has confirmed there is no packet loss between the server and the Central Manager. The server's CPU and memory utilization are normal. Which of the following is the most probable cause for this 'flapping' behavior?

    Show answer & explanation

    Correct answer: A

    Secure communications, especially those involving certificates and authentication, are highly dependent on synchronized system time. If the server's clock has drifted significantly from the Central Manager's clock, the TLS/SSL handshake required to establish a secure connection can fail. This leads to a cycle where the collector attempts to connect, fails the security check, disconnects, and then retries, causing the observed 'flapping'. This should be one of the first things to check when network connectivity is confirmed to be stable.

  9. Question 9

    Q9

    True or False: When FortiEDR is deployed in a multi-tenant configuration, a Global Administrator can create threat hunting profiles that are automatically inherited and visible to all individual tenant administrators.

    Show answer & explanation

    Correct answer: B

    FortiEDR's multi-tenancy model enforces strict data isolation between Organizations (tenants). Resources such as threat hunting profiles, security policies, and events created within one Organization are not visible or accessible to another. A Global Administrator manages the system and Organizations but does not create content that is automatically shared across these isolated tenant environments. Each tenant administrator must create and manage their own threat hunting profiles.

  10. Question 10

    Q10

    An administrator is configuring a Communication Control policy to prevent corporate laptops from accessing known malicious domains associated with phishing campaigns. The goal is to block any outbound TCP connection attempt to these domains from any process on the endpoint. Which rule configuration in the policy would achieve this?

    Show answer & explanation

    Correct answer: A

    This configuration correctly specifies all the necessary parameters. 'Action: Block' defines the desired outcome. 'Direction: Outgoing' targets traffic originating from the endpoint. 'Protocol: Any' (or TCP specifically) covers the connection type. 'Remote Address' is where the list of malicious domains or IPs would be entered. 'Application: Any' ensures the rule applies regardless of which process (e.g., browser, email client) initiates the connection, providing comprehensive protection.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the NSE5-EDR-5-0 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 244 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon