exam questions

Exam NSE5_EDR-5.0 All Questions

View all questions & answers for the NSE5_EDR-5.0 exam

Exam NSE5_EDR-5.0 topic 1 question 3 discussion

Actual exam question from Fortinet's NSE5_EDR-5.0
Question #: 3
Topic #: 1
[All NSE5_EDR-5.0 Questions]

Refer to the exhibit.

Based on the event shown in the exhibit, which two statements about the event are true? (Choose two.)

  • A. The NGAV policy has blocked TestApplication.exe.
  • B. FCS classified the event as malicious.
  • C. TestApplication.exe is sophisticated malware.
  • D. The user was able to launch TestApplication.exe.
Show Suggested Answer Hide Answer
Suggested Answer: CD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Agent1994
Highly Voted 1 year, 12 months ago
A. False. NGAV is execution prevention. https://docs.fortinet.com/document/fortiedr/5.2.1/administration-guide/354083/introducing-fortiedr B. False. It should say "by FortinetCloudServices" C. True. Mostly because A & B are false. D. True. Exfiltration happens after execution.
upvoted 5 times
Chogi_
1 year, 11 months ago
Ans. are C&D - exact explanation.
upvoted 2 times
...
...
rac_sp
Most Recent 1 year ago
Selected Answer: CD
The file was executed. As you can see in the screenshot the Exfiltration Policy was invoked, therefore this policy is invoked in the post infection phase of the EDR protection method. So if it is in the post infection phase, then NGAV was not capable to block the execution of the file.
upvoted 2 times
...
Latrel
1 year, 2 months ago
the correct answer is C and D. Similar cenario available on the FortiEDR Lab Guide pag 38 "Stop and think! Why wasn’t the process caught by the Execution Prevention policy like you saw earlier? Because, in some cases, with brand new or very sophisticated malware, NGAV cannot detect the attack. This is when the post-infection prevention policies really shine. An unrecognized malicious program may occasionally be allowed to launch, but FortiEDR will stop it before it is able to cause harm."
upvoted 3 times
...
thinasci01
1 year, 4 months ago
the correct answer is C and D.
upvoted 1 times
...
joeytrib
1 year, 7 months ago
Selected Answer: CD
CD is the right answer !
upvoted 1 times
...
thommy88
1 year, 8 months ago
Selected Answer: CD
a= false because NGAV is exectuion prevention b= false because i is not "by fortinetCloudServices
upvoted 2 times
...
BrunoLu
1 year, 10 months ago
Selected Answer: AC
A. TRUE. NGAV is execution prevention."This blocks the execution of files that are identified as malicious or suspected to be malicious." I find this in the link: https://docs.fortinet.com/document/fortiedr/5.2.1/administration-guide/354083/introducing-fortiedr B. False. It should say "by FortinetCloudServices" C. True. D. FALSE. The NGAV will block it
upvoted 3 times
BrunoLu
1 year, 10 months ago
B.It's history say by fortinet
upvoted 1 times
...
...
headhunter24
2 years ago
correct answer A & C
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...