Fortinet NSE6_NDR_AN-26 Certification Exam Syllabus
A great way to start the Fortinet NSE 6 Certified - Cloud Security (FortiNDR Cloud Analyst) preparation is to begin by properly appreciating the role that syllabus and study guide play in the Fortinet NSE6_NDR_AN-26 certification exam. This study guide is an instrument to get you on the same page with Fortinet and understand the nature of the Fortinet FortiNDR Cloud Analyst exam.
Our team of experts has composed this Fortinet NSE6_NDR_AN-26 exam preparation guide to provide the overview about Fortinet NSE 6 - FortiNDR Cloud 26 Analyst exam, study material, sample questions, practice exam and ways to interpret the exam objectives to help you assess your readiness for the Fortinet FortiNDR Cloud Analyst exam by identifying prerequisite areas of knowledge. We recommend you to refer the simulation questions and practice test listed in this guide to determine what type of questions will be asked and the level of difficulty that could be tested in the Fortinet FortiNDR Cloud Analyst certification exam.
Fortinet NSE6_NDR_AN-26 Exam Overview:
| Exam Name | Fortinet NSE 6 - FortiNDR Cloud 26 Analyst |
| Exam Number | NSE6_NDR_AN-26 FortiNDR Cloud Analyst |
| Exam Price | $200 USD |
| Duration | 65–75 minutes |
| Number of Questions | 30-40 |
| Passing Score | Pass / Fail |
| Recommended Training | FortiNDR Cloud Analyst |
| Exam Registration | PEARSON VUE |
| Sample Questions | Fortinet NSE6_NDR_AN-26 Sample Questions |
| Practice Exam | Fortinet NSE 6 Certified - Cloud Security Practice Test |
Fortinet NSE6_NDR_AN-26 Exam Topics:
| Section | Objectives |
|---|---|
Architecture and system settings (15–25% of the exam) |
|
| Explain the FortiNDR Cloud architecture |
- Fortinet FortiNDR offerings
- FortiNDR Cloud SaaS offering - Back-end concepts - Entity information extraction - Enrichment - Detection matching and intelligence correlation - Data storage - Features of the front end - Portal management - Use cases (display mode, subscription provisioning, annotation provisioning) |
| Identify the FortiNDR Cloud sensors |
- FortiNDR Cloud sensors
- Sensor types - Sensor data - Sensor registration - Metadata production - Event types - Special considerations - Use cases: sensors, MITRE ATT&CK detections, frameworks |
Events and queries (25–35% of the exam) |
|
| Explain event types and fields |
- Protocol definition (Flow, DNS, HTTP, SSL, SMB, DEC/RPC)
- Key available fields (Flow, DNS, HTTP, SSL, SMB, DEC/RPC) - Security implications (Flow, DNS, HTTP, SSL, SMB, DEC/RPC) - Use cases: flow events (fields, sub-fields, metadata) |
| Configure IQL query to match security events |
- IQL purpose
- IQL uses - IQL syntax structures - Entity search and IQL search (simple search using “entity”, IQL and flow search, using regex in the search, SMTP search, using the IN and LIKE syntax, output with a global map, challenge, expert challenge) |
Detection (15–25% of the exam) |
|
| Analyze detections and behavioral observations |
- Detector with details
- Severity levels - Confidence levels - Resolution options - Basic tools for scoping the impact of a detection - Behavioral observations - Observation details - Investigation stage - Use case: IOC investigation |
| Implement detectors |
- New detector
- Run list - Tuning detections |
Investigations and integrations (20–30% of the exam) |
|
| Perform investigations to detect threats |
- Search settings
- Describe gathering context - Open-source intelligence (OSINT) - VirusTotal - External entities - File hashes - Timeline usage - Steps for changing to a different tactic - Query modification - Packet capture - Resolution types - Detection resolution - Use cases: Investigate an outbreak alert, investigate a detection |
| Explain how to integrate FortiNDR Cloud (API/connectors) |
- FortiNDR: FortiNDR Cloud connector
- FortiEDR: FortiEDR panel, detection investigating, host isolation - FortiNDR Cloud API: API functions |
| Perform threat hunting activities |
- Concepts and definitions
- A practical model for conducting cyberthreat hunting - Tactics, Techniques, and Procedures (TTP)-based threat hunting - Fortinet-Gigamon Threat Hunting whitepaper - Ransomware |
Fortinet FortiNDR Cloud Analyst Exam Description:
The NSE 6 in Security Operations certification validates your ability to deploy, manage, and monitor advanced Fortinet security operations products secure networks and applications. The certification exams cover the day-to-day tasks related to Fortinet advanced security operations devices.
- Fortinet Certification |
- Fortinet Cloud Security Certification |
- Fortinet NSE 6 Certified - Cloud Security |
- NSE6_NDR_AN-26 FortiNDR Cloud Analyst |
- NSE6_NDR_AN-26 Online Test |
- NSE6_NDR_AN-26 |
- Fortinet FortiNDR Cloud Analyst Certification |
- FortiNDR Cloud Analyst Practice Test |
- Fortinet FortiNDR Cloud Analyst Primer |
- FortiNDR Cloud Analyst Study Guide |
- FortiNDR Cloud Analyst |
- Fortinet NSE 6 - FortiNDR Cloud Analyst |
- NSE6_NDR_AN-26 Syllabus |
- Fortinet NSE 6 - FortiNDR Cloud 26 Analyst |
- FortiNDR Cloud Analyst Certification Cost |
- FortiNDR Cloud Analyst Certification Syllabus |
- Fortinet FortiNDR Cloud Analyst Training |
- Fortinet NSE6_NDR_AN-26 Books |
- Fortinet FortiNDR Cloud Analyst Books
