Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Fortinet logo

FortinetNSE 6 - FortiNDR Cloud Analyst

Domain 4Objective 3

Perform Threat Hunting Activities NSE6-FORTINDR-CLOUD-ANALYST Practice Questions (Page 2)

Part of the Investigations and Integrations domain, which accounts for 20-30% of the NSE6-FORTINDR-CLOUD-ANALYST exam.

21questions here
5free pages
3concepts
20-30%of the exam

Questions 6–10

  1. 6foundation · easy

    In TTP-based threat hunting, which component of the TTP framework refers to the specific method or tool an adversary uses to achieve a tactical objective?

    Select an answer first
  2. 7expert · hard

    A threat hunter is using the Pyramid of Pain to evaluate the effectiveness of their detection capabilities. The hunter finds that they can easily block known malicious IPs and domains, but they struggle to detect the adversary's TTPs. Which improvement would have the most impact on increasing the adversary's cost?

    Select an answer first
  3. 8expert · hard

    A security team is hunting for ransomware that may be using a 'double extortion' tactic, where data is exfiltrated before encryption. The team has limited resources and must prioritize their hunting efforts. Which hunting approach would be most effective to detect this threat early?

    Select an answer first
  4. 9foundation · easy

    Which threat hunting model is used to illustrate the increasing difficulty for an adversary when defenders can deny them the use of specific indicators, such as hashes, IP addresses, and domain names?

    Select an answer first
  5. 10application · medium

    A threat hunter is planning a hunt for a suspected advanced persistent threat (APT) that is known to use living-off-the-land binaries (LOLBins) for execution. Which hunting approach would be most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Fortinet. “NSE6-FORTINDR-CLOUD-ANALYST” is a trademark of its owner, used for identification only.