
Fortinet NSE 6 - FortiNDR Cloud Analyst
The Fortinet NSE 6 - FortiNDR Cloud Analyst certification validates your ability to configure, operate, and troubleshoot FortiNDR Cloud to detect and investigate security incidents. Designed for network and security professionals, this credential proves hands-on expertise in incident analysis, threat hunting, and integration with third-party products. Earning it demonstrates that you can turn FortiNDR Cloud telemetry into decisive, well-scoped responses.
235 practice questions · Updated 2026-07-30
NSE6-FORTINDR-CLOUD-ANALYST Curriculum
Every domain, objective, and concept the NSE6-FORTINDR-CLOUD-ANALYST exam measures.
- Fortinet FortiNDR offerings
- FortiNDR Cloud SaaS offering
- Back-end concepts
- Entity information extraction
- Enrichment
- Detection matching and intelligence correlation
- Data storage
- Features of the front end
- Portal management
- Use cases: display mode, subscription provisioning, annotation provisioning
- FortiNDR Cloud sensor overview
- Sensor types
- Sensor data collection
- Sensor registration process
- Metadata production
- Event types generated by sensors
- Sensor use cases
- MITRE ATT&CK detections
- Frameworks integration
- Protocol definitions
- Flow event fields
- DNS event fields
- HTTP event fields
- SSL event fields
- SMB event fields
- DCE/RPC event fields
- Security implications of event types
- Flow event use cases
- IQL purpose and use cases
- IQL syntax structure
- Entity search capabilities
- IQL search capabilities
- Regex syntax in IQL
- SMTP syntax in IQL
- IN and LIKE syntax in IQL
- Global map output
- Detector details
- Severity and confidence levels
- Resolution options
- Impact scoping tools
- Behavioral observations
- Investigation stages
- IOC investigation use cases
- New detector creation
- Run lists
- Detection tuning
- Search settings configuration
- Context gathering techniques
- OSINT integration usage
- VirusTotal integration
- External entity analysis
- File hash investigation
- Timeline creation and navigation
- Tactic change identification
- Packet capture analysis
- Resolution type interpretation
- Outbreak investigation workflow
- Detection investigation use cases
- FortiNDR Cloud connector overview
- Connector setup and configuration
- FortiEDR panel integration
- Host isolation via FortiEDR
- FortiNDR Cloud API authentication
- FortiNDR Cloud API endpoints and functions
- API use cases in investigations
- Threat hunting concepts and models
- TTP-based threat hunting
- Ransomware hunting
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for NSE6-FORTINDR-CLOUD-ANALYST, so none is invented.