
FortinetNSE 6 - FortiNDR Cloud Analyst
Domain 3Objective 2
Implement Detectors NSE6-FORTINDR-CLOUD-ANALYST Practice Questions (Page 3)
Part of the Detection domain, which accounts for 15-25% of the NSE6-FORTINDR-CLOUD-ANALYST exam.
22questions here
5free pages
3concepts
15-25%of the exam
Questions 11–15
- 11
A security team needs to create a detector for 'Insider Threat' that monitors a specific set of privileged users (10.1.1.0/24). The team wants to minimize false positives by only alerting on unusual behavior. During creation, which combination of settings best achieves this goal?
Select an answer first - 12
A logistics company has a detector for 'Command & Control' that monitors a set of 100 IPs. A new office is opened with 15 new workstations that need to be monitored. What is the most efficient way to include the new workstations in the detector?
Select an answer first - 13
What is the function of a run list in FortiNDR Cloud detectors?
Select an answer first - 14
When creating a new detector in FortiNDR Cloud, which fields are required to be defined during the initial setup?
Select an answer first - 15
A security analyst at a hospital network needs to detect unusual outbound data transfers from the finance department's workstations. The finance team uses a dedicated subnet (10.10.5.0/24) with 40 static IPs. The analyst creates a new detector but wants to ensure it only monitors the finance workstations and not the rest of the hospital network. What should the analyst configure first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Fortinet. “NSE6-FORTINDR-CLOUD-ANALYST” is a trademark of its owner, used for identification only.