我們PDFExamDumps為你在真實的環境中找到真正的Fortinet的NSE6_EDR_AD-7.0考試準備過程,如果你是初學者和想提高你的教育知識或專業技能,PDFExamDumps Fortinet的NSE6_EDR_AD-7.0考試考古題將提供給你,一步步實現你的願望,你有任何關於考試的問題,我們PDFExamDumps Fortinet的NSE6_EDR_AD-7.0幫你解決,在一年之內,我們提供免費的更新,請你多關注一下我們網站。
| Section | Weight | Objectives |
|---|---|---|
| Topic 1: FortiEDR System Architecture and Deployment | 25% | - Multi-tenancy deployment - Architecture and technical positioning - API-based management operations - Inventory management and system tools - Installation and deployment process |
| Topic 2: Integration and Security Fabric | 15% | - FortiXDR deployment and configuration - Fortinet Security Fabric integration |
| Topic 3: Security Settings and Policies | 25% | - Playbooks creation and management - Fortinet Cloud Service (FCS) integration - Security policies configuration - Communication control policies |
| Topic 4: Monitoring and Troubleshooting | 10% | - Log and alert troubleshooting - Performance and issue diagnosis - System monitoring and health checks |
| Topic 5: Events, Forensics, and Threat Hunting | 25% | - Security event and alert analysis - Threat hunting data interpretation - Forensic analysis and incident investigation - Threat hunting profiles and queries |
為了通過Fortinet NSE6_EDR_AD-7.0 認證考試,請選擇我們的PDFExamDumps來取得好的成績。你不會後悔這樣做的,花很少的錢取得如此大的成果這是值得的。我們的PDFExamDumps不僅能給你一個好的考試準備,讓你順利通過Fortinet NSE6_EDR_AD-7.0 認證考試,而且還會為你提供免費的一年更新服務。
問題 #21
You are asked to configure a query to run every 15 minutes, automatically searching for specific registry modifications across all endpoints. Which FortiEDR feature must you configure? (Choose one answer)
答案:B
解題說明:
The correct answer is C.
The FortiEDR guide explains that Threat Hunting searches across endpoint activity events, including registry activity. It states that Threat Hunting can search based on attributes of files, registry keys and values, network, processes, event log, and activity event types. This fits the requirement to search for specific registry modifications across endpoints.
The guide also explains that after filtering activity events, the query can be saved and defined as a Scheduled Query. It says: "Scheduled Query: Mark this option to automate the process of detecting threats so that this query is run automatically according to the schedule that you define." It also states that a security event is automatically created in the Incidents tab when matches are detected, and notifications can be sent through email, Syslog, and other configured methods.
The guide further states that the Repeat Every/On options define the frequency and schedule when the query runs. Therefore, a 15-minute recurring query is handled through the Scheduled Query capability in Threat Hunting, not Communication Control, policy override, or a manual Playbook trigger.
Strictly speaking, the guide calls this a scheduled query under Threat Hunting saved queries, not a
"communication control rule" or "manual query." Option C is the intended answer.
=========
問題 #22
Refer to the Exhibit:
Based on the event shown in the exhibit, which two statements about the event are true? (Choose two answers)
答案:A,D
解題說明:
The correct answers are A and B .
The exhibit shows the event classification as Malicious , classified by FortinetCloudServices , and the history states that device R2D2-kvm63 was moved from the Training Collector Group to the High Security Collector Group . This is a Playbook action. The FortiEDR guide explains that after classification changes, the Overview pane displays the history of automatic FortiEDR actions, including Playbook policy-related actions .
The guide specifically lists Move device to High Security Group under Investigation actions in Playbook policies. It states that a checkmark in a classification column means the device is automatically moved to the High Security Collector Group when a security event with that classification is triggered. So the exhibit proves that Playbooks are configured for this event.
The second correct answer is B because the triggered rule is under Training * Extended Detection . The FortiEDR guide states that the eXtended Detection Policy logs events and displays them in the Incidents tab, but no blocking options are provided for this policy.
Option C is wrong because moving a device to the High Security Collector Group is not the same as isolating the device. Isolation would block communication to/from the affected Collector. The exhibit shows a Collector Group move, not isolation.
Option D is wrong because Extended Detection does not block. The guide explicitly says Extended Detection events are logged and displayed, with no blocking options provided.
=========
問題 #23
Refer to the Exhibit:
Based on the investigation view shown in the exhibit, which two statements about this event are true? (Choose two answers)
答案:B,C
解題說明:
The correct answers are A and C .
The exhibit shows a green checkmark in the Exception column for the filezilla.exe event. In FortiEDR, an exception means a whitelist has been created for a specific flow/security-event pattern. The guide states that exceptions limit enforcement of a rule and that after an exception is defined, identical new events are no longer triggered. It also explains that past security events display an icon indicating that an exception has been defined for them.
The exhibit also shows the event flow ending in filezilla.exe with a red highlighted activity and a blocked symbol. In the Incidents/Investigation workflow, FortiEDR represents blocked policy violations as security events, and the guide explains that FortiEDR can enforce policy by blocking malicious connection establishment requests to prevent exfiltration. It also states that Block means the malicious exfiltration or file- changing attempt was blocked.
問題 #24
Within the FortiEDR architecture, which component needs JumpBox capabilities to enable authenticated and controlled communication with FortiAnalyzer? (Choose one answer)
答案:D
解題說明:
The correct answer is A. Core.
For FortiAnalyzer / FortiAnalyzer Cloud integration, the FortiEDR 7.0.0 Administration Guide states that one prerequisite is "A Jumpbox with connectivity to FortiAnalyzer." The same section says to refer to Setting up the FortiEDR Core for details about installing a FortiEDR Core and configuring it as a Jumpbox. In the connector configuration, the guide also states that the Jumpbox field is used to select the FortiEDR Jumpbox that will communicate with FortiAnalyzer or FortiAnalyzer Cloud.
So, the FortiEDR component associated with JumpBox capability is the Core. The Central Manager must have connectivity to Fortinet Cloud Services, but it is not the component configured as the JumpBox. The Aggregator handles registration, configuration, and monitoring between Collectors/Cores and Central Manager, and the Reputation Server is unrelated to FortiAnalyzer JumpBox communication in this context.
=========
問題 #25
Refer to Exhibit.
Based on the Postman output shown in the exhibit, why is the user receiving an unauthorized error? (Choose one answer)
答案:A
解題說明:
The correct answer is C. The user account does not have the REST API role assigned .
The exhibit shows a Postman request to the FortiEDR Central Manager REST endpoint:
/management-rest/inventory/list-collectors
The response is 401 Unauthorized , which means the request reached the FortiEDR API endpoint but the supplied user credentials are not authorized for REST API access.
The FortiEDR 7.0.0 Administration Guide states that when adding or editing a user, the Rest API advanced option controls whether the user is allowed to access the FortiEDR Central Manager through API calls. The guide defines this option as: "Rest API - Specifies whether to allow the user to access the FortiEDR Central Manager through API calls." Therefore, the most accurate cause is that the account being used in Postman does not have the Rest API permission enabled.
Option A is incorrect because the request uses GET against a list endpoint, and an unsupported method would not normally be represented by this user-authentication failure. Option B is not supported by the exhibit or guide wording; the guide describes enabling REST API access per user. Option D is incorrect because first- login password reset is not the direct cause of this REST API authorization failure. The guide separately discusses password reset and password policy behavior, but that is not what the API error indicates.
問題 #26
......
在IT行業中工作的人們現在最想參加的考試好像是Fortinet的認證考試吧。作為被廣泛認證的考試,Fortinet的考試越來越受大家的歡迎。其中,NSE6_EDR_AD-7.0認證考試就是最重要的一個考試。這個考試的認證資格可以證明你擁有很高的技能。但是,和考試的重要性一樣,這個考試也是非常難的。要通过考试是有些难,但是不用担心。PDFExamDumps可以帮助你通过NSE6_EDR_AD-7.0考试。
NSE6_EDR_AD-7.0考試資訊: https://www.pdfexamdumps.com/NSE6_EDR_AD-7.0_valid-braindumps.html