nse5_edr-50 Exam QuestionsBrowse all questions from this exam

nse5_edr-50 Exam - Question 3


Refer to the exhibit.

Based on the event shown in the exhibit, which two statements about the event are true? (Choose two.)

Show Answer
Correct Answer: ABCD

TestApplication.exe is identified as sophisticated malware based on the triggered Exfiltration Prevention rules, which are invoked after execution, indicating it bypassed the initial detection. This means the user was able to launch TestApplication.exe, as the post-execution rules were applied, signifying the program executed on the system.

Discussion

8 comments
Sign in to comment
Agent1994Options: CD
Jan 22, 2023

A. False. NGAV is execution prevention. https://docs.fortinet.com/document/fortiedr/5.2.1/administration-guide/354083/introducing-fortiedr B. False. It should say "by FortinetCloudServices" C. True. Mostly because A & B are false. D. True. Exfiltration happens after execution.

Chogi_
Jan 27, 2023

Ans. are C&D - exact explanation.

BrunoLuOptions: AC
Mar 9, 2023

A. TRUE. NGAV is execution prevention."This blocks the execution of files that are identified as malicious or suspected to be malicious." I find this in the link: https://docs.fortinet.com/document/fortiedr/5.2.1/administration-guide/354083/introducing-fortiedr B. False. It should say "by FortinetCloudServices" C. True. D. FALSE. The NGAV will block it

BrunoLu
Mar 9, 2023

B.It's history say by fortinet

Latrel
Nov 12, 2023

the correct answer is C and D. Similar cenario available on the FortiEDR Lab Guide pag 38 "Stop and think! Why wasn’t the process caught by the Execution Prevention policy like you saw earlier? Because, in some cases, with brand new or very sophisticated malware, NGAV cannot detect the attack. This is when the post-infection prevention policies really shine. An unrecognized malicious program may occasionally be allowed to launch, but FortiEDR will stop it before it is able to cause harm."

headhunter24Options: AC
Jan 14, 2023

correct answer A & C

thommy88Options: CD
May 10, 2023

a= false because NGAV is exectuion prevention b= false because i is not "by fortinetCloudServices

rac_spOptions: CD
Jan 2, 2024

The file was executed. As you can see in the screenshot the Exfiltration Policy was invoked, therefore this policy is invoked in the post infection phase of the EDR protection method. So if it is in the post infection phase, then NGAV was not capable to block the execution of the file.

joeytribOptions: CD
May 30, 2023

CD is the right answer !

thinasci01
Sep 17, 2023

the correct answer is C and D.