Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Fortinet logo

FortinetNSE 6 - FortiNDR Cloud Analyst

Domain 2Objective 1

Explain Event Types and Fields NSE6-FORTINDR-CLOUD-ANALYST Practice Questions (Page 5)

Part of the Events and Queries domain, which accounts for 25-35% of the NSE6-FORTINDR-CLOUD-ANALYST exam.

31questions here
7free pages
9concepts
25-35%of the exam

Questions 21–25

  1. 21foundation · easy

    Which SMB event field indicates the specific file or directory that was accessed on the share?

    Select an answer first
  2. 22application · medium

    An analyst is investigating a potential ransomware outbreak that is spreading via SMB. The analyst needs to identify the specific file shares being accessed and the files being written. Which SMB event fields should the analyst focus on?

    Select an answer first
  3. 23foundation · easy

    In a FortiNDR Cloud SMB event, which field contains the name of the Windows user account attempting to access the file share?

    Select an answer first
  4. 24application · medium

    An analyst is investigating a web server that is receiving a high volume of POST requests. The analyst needs to determine if the requests are part of a brute-force attack. Which HTTP event fields should the analyst examine to identify the source of the requests and the target?

    Select an answer first
  5. 25foundation · easy

    In a FortiNDR Cloud DNS event, which field contains the domain name that was queried by the client?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Fortinet. “NSE6-FORTINDR-CLOUD-ANALYST” is a trademark of its owner, used for identification only.