nse5_edr-50 Exam QuestionsBrowse all questions from this exam

nse5_edr-50 Exam - Question 7


Based on the event shown in the exhibit, which two statements about the event are true? (Choose two.)

Show Answer
Correct Answer: AD

The event is related to Training-eXtended Detection, which operates in simulation mode, and the playbooks are configured for this event, indicated by the device being moved automatically between collector groups.

Discussion

9 comments
Sign in to comment
fontabest99Options: BD
Dec 28, 2022

the correct answer are B and D, FortiEDR study guide pag 96

RodrigoG
Jan 15, 2023

that is incorrect, A and D are correct, the device was moved to the HSG (by playbook), it wasnt isolated

ebenav11Options: BD
Apr 19, 2023

The correct answer are B and D Any policy in Simulation Mode, has the next label Simulation Device PC-X was moved from collector group Default-Group to collector group High Security Collector Group once Simulation Device PC-Y was isolated once In this case device wasnt isolated.

pgg1896Options: AD
Jun 21, 2023

eXtended Detection Policy operates only in simulation mode, A&D are correct

BrunoLuOptions: AD
Mar 9, 2023

A&D,I check the FortiEDR study guide pag 96,but i think A and D is correct

joeytribOptions: BD
Jun 4, 2023

BD are the right answers study guide p96

nse_studentOptions: AD
Jul 7, 2023

A & D Correct

thinasci01Options: AD
Sep 17, 2023

the correct answer is A and D.

LatrelOptions: AD
Nov 12, 2023

the correct answer is A and D

rac_spOptions: AD
Jan 8, 2024

first, it was an extended detection. So automation plays a rule here. Extended detections operates in simulation mode