Pre-Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Fortinet NSE6_EDR_AD-7.0 - Fortinet NSE 6 - FortiEDR 7.0 Administrator

Page: 1 / 1
Total 33 questions

Refer to the Exhibit:

Based on the FortiEDR status output shown in the exhibit, what are two reasons for the degraded state? (Choose two answers)

A.

The endpoint has windows firewall enabled.

B.

The collector is installed with an incorrect registration password.

C.

The collector is installed with an incorrect port number.

D.

The endpoint cannot reach the central manager.

What action does an on-premises reputation server take when it receives a hash request that is not found in its local database? (Choose one answer)

A.

Ignores them until manually updated

B.

Stores them locally and waits for endpoint input

C.

Requests the missing hashes from the cloud reputation service

D.

Automatically blocks applications with unknown hashes

Which two criteria are required for integrating FortiEDR with the Fortinet Security Fabric? (Choose two answers)

A.

Central manager connected to FCS

B.

A Forensics add-on license

C.

A valid API user with access to connectors

D.

Core with core-only functionality

Refer to the exhibit:

You are asked to block applications based on hash attributes. Which two factors must you consider when applying the hash value? (Choose two answers)

A.

Hashes must be line-separated.

B.

Hashes must be used with at least one attribute, such as a filename or path.

C.

Hashes must be unique to each application.

D.

Hashes must follow supported formats.

An employee leaves the company and no longer has access to the FortiEDR system. You must ensure GDPR compliance regarding the employee’s personal data stored in FortiEDR. Which two data types must be removed to meet GDPR requirements? (Choose two answers)

A.

Device and user name

B.

Installed applications

C.

Installed OS name

D.

IP address and MAC address

Refer to the Exhibit:

Based on the event shown in the exhibit, which two statements about the event are true? (Choose two answers)

A.

Playbooks are configured for this event.

B.

The policy is in simulation mode.

C.

The device is moved to isolation.

D.

The event has been blocked.

Refer to the exhibits.

The application policy logs and application details are shown. Collector C8092231196 is a member of the Finance group. In this scenario, what must you do to block the FileZilla application? (Choose one answer)

A.

Assign the Simulation Communication Control Policy to the DBA group.

B.

Deny the application in the Finance policy.

C.

Assign the Finance policy to the DBA group.

D.

Assign the Finance policy to a broader collector group, such as the Default Collector Group.

Refer to Exhibit.

Based on the Postman output shown in the exhibit, why is the user receiving an unauthorized error? (Choose one answer)

A.

The central manager is rejecting the request because of an unsupported HTTP method.

B.

API access is disabled on the central manager.

C.

The user account does not have the REST API role assigned.

D.

FortiEDR requires a password reset the first time a user logs in.

A playbook is configured with two actions: terminate process and isolate device. The terminate process action fails because the process is protected by Windows. What is the expected behavior for the second action, isolate device? (Choose one answer)

A.

The playbook execution pauses and requires administrator intervention.

B.

The playbook generates a notification email and execution stops.

C.

The playbook execution stops because the action fails.

D.

The playbook continues and executes the second action.