Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Fortinet logo

FortinetNSE 6 - FortiNDR Cloud Analyst

Domain 2Objective 1

Explain Event Types and Fields NSE6-FORTINDR-CLOUD-ANALYST Practice Questions (Page 3)

Part of the Events and Queries domain, which accounts for 25-35% of the NSE6-FORTINDR-CLOUD-ANALYST exam.

31questions here
7free pages
9concepts
25-35%of the exam

Questions 11–15

  1. 11foundation · easy

    In a FortiNDR Cloud DCE/RPC event, which field identifies the specific remote procedure that was invoked on the target host?

    Select an answer first
  2. 12foundation · easy

    Why are DNS events particularly valuable for detecting command-and-control (C2) communication in FortiNDR Cloud?

    Select an answer first
  3. 13foundation · easy

    In a FortiNDR Cloud SSL event, which field contains the version of the TLS protocol used in the handshake, such as TLS 1.2 or TLS 1.3?

    Select an answer first
  4. 14foundation · easy

    Which SSL event field would an analyst use to identify the domain name that the TLS certificate was issued to?

    Select an answer first
  5. 15expert · hard

    An analyst is investigating a host that is communicating with a known C2 server. The analyst observes that the host is making DNS queries to a domain that resolves to the C2 IP, and then establishing a connection to that IP on port 443. The analyst wants to determine if the C2 traffic is encrypted. Which event types should the analyst correlate to make this determination?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Fortinet. “NSE6-FORTINDR-CLOUD-ANALYST” is a trademark of its owner, used for identification only.