
FortinetNSE 6 - FortiNDR Cloud Analyst
Domain 3Objective 1
Analyze Detections and Behavioral Observations NSE6-FORTINDR-CLOUD-ANALYST Practice Questions (Page 3)
Part of the Detection domain, which accounts for 15-25% of the NSE6-FORTINDR-CLOUD-ANALYST exam.
31questions here
7free pages
7concepts
15-25%of the exam
Questions 11–15
- 11
During an investigation, an analyst confirms that a detection was triggered by a legitimate administrative script that runs nightly. The script is expected and has been approved by the IT team. What resolution action should the analyst take?
Select an answer first - 12
An analyst is investigating a detection that indicates a malware infection on a single workstation. The analyst has confirmed the malware is present and has identified the file path. The workstation is used by a remote employee who is currently online. The analyst must choose a resolution action that minimizes disruption while containing the threat. What should the analyst do?
Select an answer first - 13
A detection with high severity and high confidence indicates that a specific user account has been compromised. The analyst needs to determine which network segments the user has accessed recently. What tool or feature should the analyst use?
Select an answer first - 14
Which of the following is an example of a behavioral observation in a detection?
Select an answer first - 15
An analyst is reviewing a detection that shows a sequence of events: a user received a phishing email, clicked a link, and then a suspicious process executed. The analyst needs to understand the full chain of activity. What should the analyst do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Fortinet. “NSE6-FORTINDR-CLOUD-ANALYST” is a trademark of its owner, used for identification only.