
FortinetNSE 6 - FortiNDR Cloud Analyst
Domain 3Objective 1
Analyze Detections and Behavioral Observations NSE6-FORTINDR-CLOUD-ANALYST Practice Questions (Page 1)
Part of the Detection domain, which accounts for 15-25% of the NSE6-FORTINDR-CLOUD-ANALYST exam.
31questions here
7free pages
7concepts
15-25%of the exam
Questions 1–5
- 1
What type of information is typically shown in the impact scoping view of a detection?
Select an answer first - 2
In FortiNDR Cloud, when reviewing a detection, which metadata field identifies the specific rule or model that generated the alert?
Select an answer first - 3
An analyst is reviewing a detection that was triggered by a network sensor. The detector details show that the detection type is 'Signature' and the source is 'Network Sensor'. The analyst needs to determine which hosts are affected. What should the analyst do?
Select an answer first - 4
What is the primary purpose of using indicators of compromise (IOCs) in an investigation?
Select an answer first - 5
A detection indicates that a malicious file was downloaded on a host in the marketing department. The analyst needs to determine the full scope of the infection, including any lateral movement. The analyst has access to network logs, endpoint data, and threat intelligence. What is the most efficient approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Fortinet. “NSE6-FORTINDR-CLOUD-ANALYST” is a trademark of its owner, used for identification only.