
FortinetNSE 6 - FortiNDR Cloud Analyst
Domain 3Objective 1
Analyze Detections and Behavioral Observations NSE6-FORTINDR-CLOUD-ANALYST Practice Questions (Page 5)
Part of the Detection domain, which accounts for 15-25% of the NSE6-FORTINDR-CLOUD-ANALYST exam.
31questions here
7free pages
7concepts
15-25%of the exam
Questions 21–25
- 21
Which detector metadata attribute indicates whether the detection was generated by a signature-based rule or by an anomaly-based model?
Select an answer first - 22
Which stage of an investigation involves determining the appropriate resolution action?
Select an answer first - 23
An analyst is investigating a detection and has identified the affected host, the user, and the malicious file. The analyst has also confirmed that the file is malicious. What is the next step in the investigation stages?
Select an answer first - 24
An analyst is reviewing two detections: Detection A has a severity of 'Critical' and a confidence of 90. Detection B has a severity of 'High' and a confidence of 95. The analyst can only investigate one at a time. Which detection should the analyst prioritize?
Select an answer first - 25
A detection includes an IOC of a suspicious domain. The analyst wants to determine if any other hosts in the environment have communicated with this domain. What should the analyst do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Fortinet. “NSE6-FORTINDR-CLOUD-ANALYST” is a trademark of its owner, used for identification only.