NSE5-EDR-5-0 Sample Questions

NSE5-EDR-5-0 Sample Questions & Answers

Communication-control policies, security policies, and playbooks carry the most weight, built on FortiEDR architecture and installation, analyzing security events and threat hunting, FortiXDR and Security Fabric integration, and alert-driven troubleshooting.

Launch the full NSE5-EDR-5-0 simulator →

Showing 10 of 20 free samples.

  1. Question 1IntermediateSelect 3

    Events, forensics, and threat hunting · Configure threat hunting profiles and scheduled queries

    A threat hunter suspects that an attacker is using a living-off-the-land technique by running malicious scripts via the legitimate Windows utility wmic.exe. The hunter wants to create a query to find all instances where wmic.exe was launched with the command-line argument process call create. Which two components are required to build this query in the FortiEDR Threat Hunting interface? (Select TWO).

    Show answer & explanation

    Correct answers: A, B, E

    To construct this threat hunting query, the analyst needs to specify the type of event to look for and the specific attributes of that event. The core event is the creation of a process. Therefore, 'Event Type: Process Creation' is the correct starting point. Then, to find the specific utility and its arguments, two filters are needed: one to specify the process name (wmic.exe) and another to search within its command line for the specific malicious arguments (process call create). While both filters are correct, the question asks for two required components, and the event type is fundamental. The combination of Process Creation event type and filters on Process Name and Process Command Line is necessary.

  2. Question 2Advanced

    FortiEDR integration · Configure security fabric using FortiEDR

    An organization has integrated FortiEDR with their FortiGate firewall as part of the Security Fabric. A playbook is configured to use the 'Block address with FortiGate' action when a high-severity threat is detected. After an event, the security team notices the endpoint's IP address was not blocked on the FortiGate. Troubleshooting reveals that the Fabric connection is up and other integrations are working. What is a likely misconfiguration specific to this automated response action?

    Show answer & explanation

    Correct answer: B

    The 'Block address with FortiGate' action in a FortiEDR playbook requires a specific parameter: the name of an existing address group on the target FortiGate. FortiEDR adds the offending IP address to this pre-defined group, which must then be used in a firewall policy on the FortiGate to deny traffic. If this address group name is missing or misspelled in the playbook action configuration, FortiEDR cannot tell the FortiGate where to place the IP, and the block will fail even if the Fabric connection is healthy.

  3. Question 3Intermediate

    FortiEDR troubleshooting · Perform FortiEDR troubleshooting

    A FortiEDR collector on a critical server is repeatedly disconnecting and reconnecting to the Central Manager, causing alert floods and inconsistent policy application. The network team has confirmed there is no packet loss between the server and the Central Manager. The server's CPU and memory utilization are normal. Which of the following is the most probable cause for this 'flapping' behavior?

    Show answer & explanation

    Correct answer: A

    Secure communications, especially those involving certificates and authentication, are highly dependent on synchronized system time. If the server's clock has drifted significantly from the Central Manager's clock, the TLS/SSL handshake required to establish a secure connection can fail. This leads to a cycle where the collector attempts to connect, fails the security check, disconnects, and then retries, causing the observed 'flapping'. This should be one of the first things to check when network connectivity is confirmed to be stable.

  4. Question 4Intermediate

    FortiEDR system · Deploy FortiEDR multi-tenancy

    True or False: When FortiEDR is deployed in a multi-tenant configuration, a Global Administrator can create threat hunting profiles that are automatically inherited and visible to all individual tenant administrators.

    Show answer & explanation

    Correct answer: B

    FortiEDR's multi-tenancy model enforces strict data isolation between Organizations (tenants). Resources such as threat hunting profiles, security policies, and events created within one Organization are not visible or accessible to another. A Global Administrator manages the system and Organizations but does not create content that is automatically shared across these isolated tenant environments. Each tenant administrator must create and manage their own threat hunting profiles.

  5. Question 5Intermediate

    FortiEDR security settings and policies · Configure communication control policy

    An administrator is configuring a Communication Control policy to prevent corporate laptops from accessing known malicious domains associated with phishing campaigns. The goal is to block any outbound TCP connection attempt to these domains from any process on the endpoint. Which rule configuration in the policy would achieve this?

    Show answer & explanation

    Correct answer: A

    This configuration correctly specifies all the necessary parameters. 'Action: Block' defines the desired outcome. 'Direction: Outgoing' targets traffic originating from the endpoint. 'Protocol: Any' (or TCP specifically) covers the connection type. 'Remote Address' is where the list of malicious domains or IPs would be entered. 'Application: Any' ensures the rule applies regardless of which process (e.g., browser, email client) initiates the connection, providing comprehensive protection.

  6. Question 6Intermediate

    FortiEDR troubleshooting · Perform alert analysis on FortiEDR security events and logs

    A SOC team is reviewing a high number of false positive alerts from the 'Suspicious Packer' detection rule, triggered by a legitimate in-house software deployment tool. To reduce alert fatigue while maintaining security, the team needs to tune the policy. What is the recommended approach to resolve this issue?

    Show answer & explanation

    Correct answer: B

    The best practice for tuning false positives is to create a specific, narrow exception. By creating an exception for the 'Suspicious Packer' rule that is scoped to the deployment tool's unique code-signing certificate, the system will ignore this specific detection for that legitimate, trusted application only. This resolves the false positive issue without disabling the rule for all other potentially malicious software, thereby maintaining the organization's security posture.

  7. Question 7Intermediate

    Events, forensics, and threat hunting · Investigate security events using forensics analysis

    During a forensic investigation, an analyst observes the following sequence of events on a compromised workstation. What does this event graph most likely represent?

    sequenceDiagram participant U as User participant E as Email Client participant W as Word.exe participant P as PowerShell.exe participant C as C2 Server U->>E: Opens phishing email E->>W: Launches malicious Word document W->>P: Executes macro, spawning PowerShell P->>C: Establishes C2 connection C-->>P: Downloads secondary payload
    Show answer & explanation

    Correct answer: C

    The diagram illustrates a classic fileless malware attack chain. It begins with social engineering (phishing email), uses a legitimate application (Word) to execute a malicious script (macro), and then leverages another legitimate tool (PowerShell) for in-memory execution and communication with a command-and-control (C2) server. This avoids writing traditional malware executables to disk, which is the hallmark of a fileless attack.

  8. Question 8Advanced

    FortiEDR system · Explain FortiEDR architecture and technical positioning

    Case Study:

    A retail company, 'StyleStream', has deployed FortiEDR across its corporate headquarters and 200 retail stores. The stores have limited bandwidth and use a variety of point-of-sale (POS) systems running a custom Windows-based application. The CISO's primary goal is to prevent ransomware and data exfiltration from the POS systems without impacting their performance.

    The current FortiEDR deployment uses a single Central Manager at the headquarters. The security team has created a device group for all POS systems. They have noticed that during peak business hours, some POS systems become sluggish, and the network link to the stores gets saturated with traffic to the FortiEDR Central Manager.

    Requirements:

    1. Ensure robust ransomware protection is active on all POS systems.
    2. Prevent exfiltration of sensitive customer data.
    3. Minimize performance impact on the POS systems and reduce WAN traffic.
    4. Simplify policy management for the large number of stores.

    Which combination of FortiEDR settings and architecture provides the optimal solution for StyleStream?

    Show answer & explanation

    Correct answer: C

    This is the optimal solution. Deploying Aggregators in regional hubs reduces direct WAN traffic from each store to the central manager, addressing the bandwidth issue. Enabling the specific Ransomware and Exfiltration Prevention rules meets the CISO's primary security goals. Crucially, setting the collector to a low forensics collection level for the less-critical POS devices minimizes the performance impact by reducing the amount of data the agent processes and sends, which directly addresses the sluggishness and further reduces network traffic.

  9. Question 9Beginner

    FortiEDR security settings and policies · Explain Fortinet Cloud Service (FCS)

    When integrating FortiEDR with FortiSandbox Cloud through the Fortinet Cloud Service (FCS), what is the primary role of the sandbox in the threat detection process?

    Show answer & explanation

    Correct answer: B

    The primary function of FortiSandbox, whether on-premises or in the cloud, is to perform dynamic analysis (detonation) of files that are not definitively known to be good or bad. It executes the file in a safe, isolated virtual environment and observes its behavior to identify malicious characteristics. This process is crucial for detecting novel, zero-day malware that would not be caught by signature-based detection methods.

  10. Question 10Beginner

    Events, forensics, and threat hunting · Analyze security events and alerts

    A security analyst is investigating an alert and finds an event classified as 'Malicious' by FortiEDR. In the classification details, the source is listed as 'Fortinet'. What does this classification source indicate?

    Show answer & explanation

    Correct answer: C

    When the classification source for an event is shown as 'Fortinet', it means the verdict was provided by the Fortinet Cloud Service (FCS). The FortiEDR core sends telemetry and file hashes to FCS, which uses its vast repository of global threat intelligence, machine learning models, and sandbox analysis results to provide a definitive classification. This contrasts with classifications made by the local core or manually by an administrator.

Ready for the real thing?

The full NSE5-EDR-5-0 simulator has every exam-style question, timed mode, and instant scoring.