
FortinetNSE 6 - FortiNDR Cloud Analyst
Domain 2Objective 1
Explain Event Types and Fields NSE6-FORTINDR-CLOUD-ANALYST Practice Questions (Page 4)
Part of the Events and Queries domain, which accounts for 25-35% of the NSE6-FORTINDR-CLOUD-ANALYST exam.
31questions here
7free pages
9concepts
25-35%of the exam
Questions 16–20
- 16
Which HTTP event field would an analyst examine to identify the type of client software (e.g., browser or bot) that made the request?
Select an answer first - 17
A security analyst wants to identify all internal hosts that communicated with a known malicious external IP address over the past 24 hours. Which Flow event field would be most useful for this analysis?
Select an answer first - 18
Which DNS event field would indicate whether the query was for an IPv4 address (A record) or an IPv6 address (AAAA record)?
Select an answer first - 19
In a FortiNDR Cloud Flow event, which field would you examine to determine the application protocol used in the session, such as HTTP or SSH?
Select an answer first - 20
Which metadata sub-field is typically associated with a Flow event to indicate the direction of the traffic relative to the monitored network boundary?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Fortinet. “NSE6-FORTINDR-CLOUD-ANALYST” is a trademark of its owner, used for identification only.