FortinetNSE 6 - FortiDDoS Administrator
Domain 4Objective 2
Analyze Logs, Reports, and Traffic Data NSE6-FORTIDDOS-ADMINISTRATOR Practice Questions (Page 3)
Part of the Monitoring, Logging, and Analysis domain, which accounts for 10-20% of the NSE6-FORTIDDOS-ADMINISTRATOR exam.
26questions here
6free pages
7concepts
10-20%of the exam
Questions 11–15
- 11
In a DDoS attack timeline, which phase is characterized by the attacker launching the initial flood of traffic?
Select an answer first - 12
An analyst is examining a traffic graph that shows a sudden spike in ICMP echo requests, followed by a spike in TCP SYN packets. The drop counters show a high number of 'rate-based' drops. What is the most likely interpretation of this data?
Select an answer first - 13
A post-attack report shows that the traffic graph had a sharp spike, followed by a plateau, and then a gradual decline. The logs show that mitigation was triggered during the plateau. What does this pattern indicate about the attack and the response?
Select an answer first - 14
When reviewing statistics graphs, which pattern is most indicative of a volumetric DDoS attack?
Select an answer first - 15
A security analyst is reviewing a DDoS incident that occurred over a weekend. The logs show that the attack started at 02:00 and ended at 05:00. The traffic graph shows a spike at 02:00, a plateau from 02:30 to 04:30, and a decline to normal at 05:00. The event list shows mitigation actions at 02:15, 03:00, and 04:00. The analyst needs to determine if the mitigation was effective and if there were any gaps in the response. What is the most accurate assessment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Fortinet. “NSE6-FORTIDDOS-ADMINISTRATOR” is a trademark of its owner, used for identification only.