Fortinet NSE5_FSM-5.2 Exam Overview:
| Certification Vendor: | Fortinet |
| Exam Name: | Fortinet NSE 5 - FortiSIEM 5.2 Certification Exam |
| Exam Number: | NSE5_FSM-5.2 |
| Related Certifications: | Fortinet NSE 4 Fortinet NSE 5 - FortiSIEM Fortinet Network Security Expert Program |
| Real Exam Qty: | 30-60 |
| Exam Duration: | 60-90 |
| Exam Format: | Multiple choice, Multiple select |
| Exam Price: | $200 USD (approximate, varies by region) |
| Certificate Validity Period: | 2 years |
| Available Languages: | English |
| Passing Score: | Approximately 60-70% |
| Recommended Training: | FortiSIEM 5.2 Administration Course (Fortinet Training Institute) |
| Exam Registration: | Fortinet Training & Certification Portal Pearson VUE Fortinet Exams |
| Sample Questions: | Fortinet NSE5_FSM-5.2 Sample Questions |
| Exam Way: | Online proctored or testing center (Pearson VUE) |
| Pre Condition: | Recommended prior experience with network security monitoring and Fortinet NSE 4 level knowledge. |
| Official Syllabus URL: | https://www.fortinet.com/training-certification |
Fortinet NSE5_FSM-5.2 Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| Monitoring and Reporting | - Dashboards and reporting
|
| Troubleshooting and Integration | - Issue diagnosis
|
| Event Management and Correlation | - Event processing pipeline
|
| FortiSIEM Architecture and Deployment | - Installation and initial configuration
|
| Configuration and Administration | - User and role management
|
Fortinet NSE 5 - FortiSIEM 5.2 Sample Questions:
1. A FortiSIEM supervisor at headquarters is struggling to keep up with an increase of EPS (Events Per Second) being reported across the enterprise. What components should an administrator consider deploying to assist the supervisor with processing data?
A) Worker
B) Agent
C) Supervisor
D) Collector
2. Which three ports can be used to send Syslogs to FortiSIEM? (Choose three.)
A) UDP 162
B) UDP9999
C) UDP 514
D) TCP 514
E) TCP 1470
3. An administrator wants to search for events received from Linux and Windows agents.
Which attribute should the administrator use in search filters, to view events received from agents only.
A) Event Received Proto Agents
B) External Event Receive Raw Logs
C) External Event Receive Agents
D) External Event Receive Protocol
4. Which process converts Raw log data to structured data?
A) Data classification
B) Data parsing
C) Data enrichment
D) Data validation
5. To determine whether or not syslog is being received from a network device, which is the best command from the backend?
A) phSyslogRecorder
B) tcpdump
C) netcat
D) phDeviceTest
Solutions:
| Question # 1 Answer: A | Question # 2 Answer: C,D,E | Question # 3 Answer: D | Question # 4 Answer: B | Question # 5 Answer: B |
We're so confident of our products that we provide no hassle product exchange.


By Atwood

