Skip to content

NSE5-EDR-5-0 Fortinet NSE 5 - FortiEDR 5.0 Practice Questions

Prepare for NSE5-EDR-5-0 with more than an answer.

244 questions in the full set20 sample questionsUpdated Jan 25, 2026
Exam fee
$400 USD
Level
Professional
Valid for
2 years
Domains covered on the exam 5
  1. FortiEDR System25%
  2. FortiEDR Security Settings and Policies30%
  3. Events, Forensics, and Threat Hunting25%
  4. FortiEDR Integration10%
  5. FortiEDR Troubleshooting10%
  1. 1

    What is the primary architectural difference between FortiEDR and FortiXDR?

    Show answer details

    Correct answer: B

    The key distinction between EDR (Endpoint Detection and Response) and XDR (Extended Detection and Response) lies in the scope of data collection. FortiEDR is focused on deep visibility and control at the endpoint. FortiXDR extends this capability by integrating telemetry from a broader range of security layers across the Fortinet Security Fabric (such as FortiGate, FortiMail, etc.) to provide cross-product correlation and a more holistic view of threats.

  2. 2

    An administrator is installing the FortiEDR Central Manager on a new virtual machine. During the setup wizard, the administrator is prompted to select a persona for the installation. Which two personas are valid options during this process? (Select TWO).

    Show answer details

    Correct answer: A, B

  3. 3

    A FortiEDR playbook is configured to trigger on the event 'Ransomware Detected'. Which of the following actions is a unique and critical post-infection protection capability that FortiEDR can automate in this scenario?

    Show answer details

    Correct answer: C

    A key differentiator for FortiEDR's ransomware protection is its post-infection capability. After detecting and terminating a ransomware process, FortiEDR can automatically restore the files that were encrypted by leveraging a cache of the original files it maintains. This 'remediation' or 'rollback' capability is a powerful tool to recover from an attack with minimal data loss, going beyond simple detection and blocking.

  4. 4

    True or False: The FortiEDR Threat Hunting feature only allows searching for Indicators of Compromise (IOCs) such as file hashes and IP addresses, but not for behavioral patterns (TTPs).

    Show answer details

    Correct answer: B

    FortiEDR's Threat Hunting capabilities are comprehensive. In addition to searching for static IOCs like hashes, IPs, and domains, it allows for powerful behavioral hunting. Analysts can create complex queries to search for Tactics, Techniques, and Procedures (TTPs), such as a specific process spawning another process with certain command-line arguments, which is essential for detecting advanced threats.

  5. 5

    After deploying FortiEDR, an administrator notices that the Security Events log contains numerous entries related to legitimate administrative scripts being flagged. To prevent these from generating alerts, an exception must be created. Which piece of information would be the LEAST reliable identifier to use for creating a long-term, secure exception?

    Show answer details

    Correct answer: C

    Using the process name of the interpreter (like powershell.exe or cscript.exe) is the least reliable and most insecure method for an exception. This would effectively whitelist all actions taken by that interpreter, creating a massive security blind spot that attackers could easily exploit. The hash is specific to one version of the file, and the signing certificate is specific to the trusted publisher. The process name is far too generic and dangerous to use as an exception criterion.

  6. 6

    A financial institution is deploying FortiEDR in a multi-tenancy model to serve different internal departments as separate tenants. The security architect needs to ensure that administrators for the 'Investment Banking' tenant cannot view or manage endpoints belonging to the 'Retail Banking' tenant. Which FortiEDR feature is the primary mechanism for enforcing this level of strict data and administrative segregation?

    Show answer details

    Correct answer: C

    FortiEDR's multi-tenancy is built around the concept of 'Organizations'. Each Organization is a self-contained unit with its own devices, policies, events, and administrators. Data and administrative access are strictly isolated at the Organization level by design, which is the primary mechanism for achieving the required segregation. While RBAC and device groups are used for granular control within an Organization, they do not provide the foundational separation between tenants.

  7. 7

    A security operator at a Managed Security Service Provider (MSSP) is using the FortiEDR REST API to automate the onboarding of new customers. The script needs to perform the following actions in order: create a new Organization for the customer, generate a collector installation package for that specific Organization, and then assign a default security policy. Which API endpoint would be used to generate the customer-specific collector package?

    Show answer details

    Correct answer: B

    The FortiEDR REST API uses specific endpoints to manage resources. To generate a collector installation package that is tied to a particular tenant (Organization), the API call must be made to an endpoint that is scoped to that Organization's ID. The correct endpoint structure is /api/v1/organizations/{org_id}/installers, where {org_id} is the unique identifier for the newly created customer Organization. The other options are either incorrectly formatted or do not scope the request to a specific organization.

  8. 8

    A hospital is using FortiEDR to protect legacy medical devices running an unsupported version of Windows. These devices use a proprietary, unsigned application for critical operations. The 'Execution Prevention' security policy is blocking this application, causing service disruption. The administrator needs to allow this specific application to run without weakening the overall security posture for other applications. What is the most precise and secure method to create this exception in FortiEDR?

    Show answer details

    Correct answer: D

    The most secure and precise method for creating an exception is to use the application's cryptographic hash (SHA-256). This ensures that only the exact, unaltered proprietary application is allowed to run. An exception based on file path is less secure, as malware could potentially replace the legitimate file at that location. Disabling the policy or setting it to log-only mode would significantly weaken the security for all other applications on the devices, which is not desirable.

  9. 9

    A security team has designed a FortiEDR playbook to automatically respond to 'Malicious File Detected' events on standard user workstations. The desired workflow is: 1) Isolate the affected device, 2) Terminate the malicious process, 3) Delete the malicious file, and 4) Open a ticket in a third-party system via a webhook. The administrator observes that devices are being isolated, but the malicious process is not being terminated. What is the most likely cause for this partial playbook execution?

    Show answer details

    Correct answer: D

    FortiEDR playbooks execute actions sequentially. If the 'Stop on Failure' option is enabled (which is common), and a preceding action like 'Isolate Device' fails or times out (e.g., due to network issues with the endpoint), the playbook will halt execution and subsequent actions like 'Terminate Process' will not be attempted. The administrator should check the playbook execution logs for failures in the 'Isolate Device' step.

  10. 10

    A SOC analyst is investigating a complex alert and needs to understand the full attack chain. The analyst wants to find all network connections made by a specific process, svchost.exe, that were initiated after a suspicious PowerShell command was executed on the endpoint CORP-WS-123. Which FortiEDR feature provides the most effective and direct way to perform this type of historical, correlated analysis?

    Show answer details

    Correct answer: C

    The Forensics analysis view is designed for deep-dive investigations into endpoint activity. It collects and correlates a rich set of data, including process creation, file modifications, registry changes, and network connections, presenting them in a timeline and process tree. This allows the analyst to filter for the specific device, locate the PowerShell execution event, and then examine all subsequent activities, including network connections made by svchost.exe, to reconstruct the attack chain directly.

Create an account to continue.