Fortinet NSE6_EDR_AD-7.0 Certification Exam Sample Questions and Answers

FortiEDR Administrator Dumps, NSE6_EDR_AD-7.0 Dumps, Fortinet FortiEDR Administrator PDF, NSE6_EDR_AD-7.0 PDF, FortiEDR Administrator VCE, Fortinet FortiEDR Administrator Questions PDF, Fortinet Exam VCE, Fortinet NSE6_EDR_AD-7.0 VCE, FortiEDR Administrator Cheat SheetBefore you write the Fortinet FortiEDR Administrator (NSE6_EDR_AD-7.0) certification exam, you may have certain doubts in your mind regarding the pattern of the test, the types of questions asked in it, the difficulty level of the questions and time required to complete the questions. These Fortinet NSE 6 Certified - SASE (FortiEDR Administrator) sample questions and demo exam help you in removing these doubts and prepare you to take the test.

The best approach to pass your Fortinet NSE6_EDR_AD-7.0 exam is to challenge and improve your knowledge. To test your learning and identify improvement areas with actual exam format, we suggest you practice with Premium Fortinet NSE6_EDR_AD-7.0 Certification Practice Exam. The practice test is one of the most important elements of your Fortinet NSE 6 - FortiEDR 7.0 Administrator exam study strategy to discover your strengths and weaknesses, to improve your time management skills and to get an idea of the score you can expect.

Fortinet NSE6_EDR_AD-7.0 (FortiEDR Administrator) Sample Questions:

01. An application team needs the FortiEDR Collector on one server to stop working during a vendor support session and to resume afterward, keeping the server's Collector in the Inventory.
Which approach is recommended?
a) Set its policies to Simulation
b) Disable the Collector from the Central Manager
c) Uninstall the Collector and reinstall it afterward
d) Create an exception that matches every process on it
 
02. The branch Collectors are configured to use a Core for metadata analysis. A WAN failure leaves every Core unreachable from the Collectors at a branch office for several hours. The devices at the branch stay powered on.
How do those Collectors behave during the outage?
a) They switch to autonomous mode and keep protecting the device locally
b) They forward every connection request to the Aggregator for a decision instead
c) They isolate their devices until they can reach a Core again
d) They allow all connections without inspection until a Core returns
 
03. A playbook in Prevention mode enables Block address on Firewall only for the Malicious classification. A new security event is first displayed as Suspicious. Later, FCS completes its analysis and gives the event a final classification of Malicious.
What happens to the firewall block?
a) It never runs, because the event first appeared as Suspicious
b) It ran at Suspicious and is not repeated for Malicious
c) It waits until an analyst manually reclassifies the event
d) It runs, as it follows the final classification
 
04. Sandbox integration is fully configured. A user runs an unsigned file downloaded from the internet that FortiEDR has not analyzed before. The sandbox later returns a malicious verdict.
Which statement describes FortiEDR's behavior?
a) The file was held from running until the sandbox verdict arrived
b) The file is classified as safe and the event is marked as handled
c) The first run was not delayed; later execution attempts of the file are blocked
d) The device is isolated automatically by the sandbox connector
 
05. A Windows user reports that an application can no longer connect externally and that saving some files fails. The administrator wants to confirm on the device itself whether the FortiEDR Collector blocked these actions.
Where should the administrator look on the device?
a) The Aggregator's logs for that device's traffic
b) The Windows Application event log
c) The Threat Hunting Repository for that device's activity
d) The FortiEDR System events list in the Central Manager
 
06. After an on-premises upgrade, Threat Hunting returns no activity events for any device. The administrator confirms that every Collector Group's Threat Hunting collection profile includes the queried event types and that the Collectors are Running.
What should the administrator check next?
a) The playbook assigned to each Collector Group
b) Whether each Collector Group's security policies are in Prevention
c) The eXtended Detection Source connector settings
d) The installation status of the Threat Hunting Repository
 
07. The Core CORE-DC-02 has shown the Degraded state for several days. The administrator opens a case with Fortinet technical support and plans to use the Export Logs feature.
Which two statements about Export Logs are true?
(Choose two.)
a) The export also includes the device's Threat Hunting activity for the same period
b) Logs need to be retrieved only when support asks for them
c) It retrieves technical information from Collectors, Cores, Aggregators and the Management server
d) The exported content is plain text so it can be pasted directly into the case
e) The administrator must analyze the logs to find the cause before support can use them
 
08. An administrator installed the FortiEDR Collector with the VDI option on a virtual desktop master image, then cloned the image to create 200 desktops. In the Inventory, the cloned desktops all appear as one and the same Collector instead of separate Collectors.
What is the most likely cause?
a) The clones are Pending Reboot, so they are listed together until each one restarts
b) The Collector configuration was not erased from the master image before the image was cloned
c) The license capacity was exceeded, so extra desktops reuse the first Collector's entry
d) The clones share one Collector Group, which the Inventory shows as a single Collector
 
09. Since FortiEDR was installed alongside the organization's existing antivirus product, users on several workstations report that their devices are slow and sometimes hang. The Collectors on those workstations show as Running.
Which action does the FortiEDR troubleshooting guidance recommend?
a) Add exclusions for each product in both FortiEDR and the other antivirus
b) Disable the Collectors until the antivirus is removed
c) Switch the workstations' security policies to Simulation mode
d) Deploy an additional Aggregator to reduce the load
 
10. An organization uses an in-house asset management system that accepts actions only through its own API and cannot poll other systems. The security team wants FortiEDR to call that API automatically whenever a Malicious event is raised.
Which approach should the administrator use?
a) Give the asset system a FortiEDR user with the REST API permission
b) Enable Send Syslog with the asset system as the destination
c) Upload an Action Manager script and enable it in the playbook Custom section
d) Add the asset system as a NAC connector for NAC isolation

Solutions:

Question: 01

Answer: b

Question: 02

Answer: a

Question: 03

Answer: d

Question: 04

Answer: c

Question: 05

Answer: b

Question: 06

Answer: d

Question: 07

Answer: b, c

Question: 08

Answer: b

Question: 09

Answer: a

Question: 10

Answer: c

Note: If you find any error in these Fortinet NSE 6 - FortiEDR 7.0 Administrator sample questions, you can update us by write an email on feedback@nwexam.com.

Rating: 4.8 / 5 (111 votes)