Fortinet NSE6_EDR_AD-7.0 - Fortinet NSE 6 - FortiEDR 7.0 Administrator Exam
Page: 3 / 7
Total 34 questions
Question #11 (Topic: Exam A)
Refer to the exhibits.


The application policy logs and application details are shown. Collector C8092231196 is a member of the Finance group.
In this scenario, what must you do to block the FileZilla application?


The application policy logs and application details are shown. Collector C8092231196 is a member of the Finance group.
In this scenario, what must you do to block the FileZilla application?
A. Assign the Finance policy to a broader collector group, such as the Default Collector Group.
B. Assign the Simulation Communication Control Policy to the DBA group.
C. Deny the application in the Finance policy.
D. Assign the Finance policy to the DBA group.
Answer: D
Question #12 (Topic: Exam A)
You added three new applications to FortiEDR using only the Path attribute.
What are two expected outcomes of this configuration? (Choose two.)
What are two expected outcomes of this configuration? (Choose two.)
A. These applications will be disabled until explicitly enabled.
B. All instances of these applications will be blocked, regardless of location.
C. These applications will be blocked only if the file name also matches.
D. Only applications in the specified directory paths will be blocked.
Answer: CD
Question #13 (Topic: Exam A)
Refer to the exhibit.

Based on the exhibit, which statement about this treat hunting query is true?

Based on the exhibit, which statement about this treat hunting query is true?
A. RDP connections will be automatically blocked and classified as suspicious.
B. A security incident will be generated whenever the device attempts an RDP connection.
C. The query is limited to detecting network activity and does not inspect process behavior.
D. The query is configured as a global hunting rule and is automatically visible across all organizations.
Answer: B
Question #14 (Topic: Exam A)
Refer to the exhibit.

A FortiEDR analyst is prioritizing response efforts.
One application has a vulnerability score of Critical but an Unknown ACI rating, while another has a Medium vulnerability score with active ACI evidence of adversary targeting.
Which application must be addressed first?

A FortiEDR analyst is prioritizing response efforts.
One application has a vulnerability score of Critical but an Unknown ACI rating, while another has a Medium vulnerability score with active ACI evidence of adversary targeting.
Which application must be addressed first?
A. The application with the Medium vulnerability score and ACI evidence should be addressed first.
B. The decision depends only on asset criticality, not scores.
C. The application with the Critical vulnerability score should be addressed first.
D. Both applications should be treated equally because patching is necessary.
Answer: A
Question #15 (Topic: Exam A)
Refer to the exhibit.

Based on the incident details shown in the exhibit, which two statements about this incident are true? (Choose two.)

Based on the incident details shown in the exhibit, which two statements about this incident are true? (Choose two.)
A. The incident has already been fully handled.
B. The incident occurred on only one device.
C. The destination IP address is blocked by FortiGate.
D. The incident is classified by the FortiEDR Core.
Answer: CD