
FortinetNSE 6 - FortiNDR Cloud Analyst
Domain 3Objective 2
Implement Detectors NSE6-FORTINDR-CLOUD-ANALYST Practice Questions (Page 2)
Part of the Detection domain, which accounts for 15-25% of the NSE6-FORTINDR-CLOUD-ANALYST exam.
22questions here
5free pages
3concepts
15-25%of the exam
Questions 6–10
- 6
A university's IT team manages a detector for 'Credential Harvesting' that currently monitors all student lab machines. After a security review, they need to exclude a specific research lab (10.20.30.0/24) where legitimate credential-caching software is used, causing false positives. What is the most appropriate way to exclude this subnet from the detector?
Select an answer first - 7
A security analyst is tuning a detector for 'Brute Force' that monitors a set of 200 IPs. The detector is currently generating 50 alerts per day, but only 5 are confirmed as real brute-force attacks. The analyst wants to reduce the false positive rate while keeping the true positive rate high. What is the most effective tuning action?
Select an answer first - 8
A government agency needs to create a detector for 'Data Staging' that monitors a specific set of classified workstations. The analyst wants to ensure the detector is clearly identifiable and has appropriate initial settings. What should the analyst include when creating the detector?
Select an answer first - 9
A managed security service provider (MSSP) monitors multiple clients. After deploying a new detector for 'DNS Tunneling', the analyst notices a high volume of alerts from a client that uses a legitimate DNS-based load-balancing service. The alerts are overwhelming the SOC. What should the analyst do to reduce false positives while maintaining detection of actual DNS tunneling?
Select an answer first - 10
A multinational company has a detector for 'Data Exfiltration' that monitors all employee workstations. The compliance team requires that the detector NOT monitor workstations in the EU due to data residency regulations, but the security team wants to maintain monitoring for all other regions. The current run list contains all employee IPs. What is the most appropriate action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Fortinet. “NSE6-FORTINDR-CLOUD-ANALYST” is a trademark of its owner, used for identification only.