
FortinetNSE 6 - FortiNDR Cloud Analyst
Domain 2Objective 1
Explain Event Types and Fields NSE6-FORTINDR-CLOUD-ANALYST Practice Questions (Page 1)
Part of the Events and Queries domain, which accounts for 25-35% of the NSE6-FORTINDR-CLOUD-ANALYST exam.
31questions here
7free pages
9concepts
25-35%of the exam
Questions 1–5
- 1
An analyst is investigating a host that is accessing a file share on a server. The analyst needs to determine if the host is reading or writing files. Which SMB event fields should the analyst examine to determine the type of access?
Select an answer first - 2
An analyst is investigating a potential privilege escalation attack that uses DCE/RPC to remotely execute commands. The analyst needs to identify the specific RPC interface and operation being called. Which DCE/RPC event fields should the analyst examine?
Select an answer first - 3
An analyst is investigating a potential data exfiltration via DNS tunneling. The analyst needs to identify the domain name being queried and the IP address that responded. Which fields in a DNS event should the analyst focus on?
Select an answer first - 4
Which FortiNDR Cloud event type is most relevant when analyzing a potential brute-force attack against a Windows file share, where the attacker is attempting multiple authentication attempts over the SMB protocol?
Select an answer first - 5
An analyst is reviewing a network capture and sees a connection to a server on port 445. The analyst needs to determine if this connection is related to file sharing or remote administration. Which event type should the analyst pivot to for this determination?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Fortinet. “NSE6-FORTINDR-CLOUD-ANALYST” is a trademark of its owner, used for identification only.