Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Fortinet logo

FortinetNSE 6 - FortiDDoS Administrator

Domain 4Objective 2

Analyze Logs, Reports, and Traffic Data NSE6-FORTIDDOS-ADMINISTRATOR Practice Questions (Page 1)

Part of the Monitoring, Logging, and Analysis domain, which accounts for 10-20% of the NSE6-FORTIDDOS-ADMINISTRATOR exam.

26questions here
6free pages
7concepts
10-20%of the exam

Questions 1–5

  1. 1expert · hard

    A FortiDDoS administrator is troubleshooting an ongoing attack. The Drops widget shows a high number of 'anomaly' drops, but the traffic graph shows only a moderate increase in traffic. The logs show that the attack is using a mix of TCP SYN and UDP packets. The administrator needs to determine if the anomaly drops are due to rate-based thresholds or protocol anomalies. What is the most effective way to differentiate between these two causes?

    Select an answer first
  2. 2application · medium

    An analyst is reviewing a past DDoS incident. The logs show a spike in UDP traffic at 10:00, followed by a spike in TCP SYN traffic at 10:05. The event list shows a mitigation action at 10:06. The traffic graph shows a decline in UDP traffic after 10:06, but SYN traffic continues to rise until 10:10. What is the most coherent picture of the attack's progression?

    Select an answer first
  3. 3expert · hard

    A security team is preparing a post-attack report for a DDoS incident. They have access to the attack logs, traffic graphs, and mitigation event logs. They need to summarize the attack characteristics, the effectiveness of the mitigation, and the lessons learned. Which approach would provide the most comprehensive and accurate analysis?

    Select an answer first
  4. 4application · medium

    A FortiDDoS administrator is analyzing a report after a DDoS attack. The traffic graph shows a gradual increase in traffic over 30 minutes, a plateau for 10 minutes, then a sharp decline to normal levels. The logs show mitigation actions were triggered during the plateau. Which attack phases are represented in this graph?

    Select an answer first
  5. 5foundation · easy

    During which phase of a DDoS attack does traffic return to normal levels after mitigation actions have taken effect?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Fortinet. “NSE6-FORTIDDOS-ADMINISTRATOR” is a trademark of its owner, used for identification only.