Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Fortinet logo

FortinetNSE 6 - FortiNDR Cloud Analyst

Domain 4Objective 3

Perform Threat Hunting Activities NSE6-FORTINDR-CLOUD-ANALYST Practice Questions (Page 3)

Part of the Investigations and Integrations domain, which accounts for 20-30% of the NSE6-FORTINDR-CLOUD-ANALYST exam.

21questions here
5free pages
3concepts
20-30%of the exam

Questions 11–15

  1. 11application · medium

    A security analyst is reviewing a series of alerts about a user account that has been sending large volumes of email to internal recipients. The emails contain links to a file-sharing site. The analyst notices that the user recently clicked a link in a phishing email. Which threat hunting approach would be most effective to determine if this is a coordinated campaign targeting other users?

    Select an answer first
  2. 12expert · hard

    A threat hunter is investigating a series of alerts that show a user account has been used to log in from multiple geographic locations within a short time frame. The user is a high-privilege administrator. The hunter must determine if this is a compromised account or a legitimate use of a VPN. Which approach would be most effective?

    Select an answer first
  3. 13foundation · easy

    A threat hunter is planning a proactive search for malicious activity. Which approach is characterized by forming a hypothesis based on observed anomalies or threat intelligence, then actively searching for evidence to confirm or refute that hypothesis?

    Select an answer first
  4. 14application · medium

    A threat hunter is investigating a potential ransomware incident. The hunter observes that a process is attempting to access the Windows registry key HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest. Which ransomware behavior does this indicate?

    Select an answer first
  5. 15foundation · easy

    During a ransomware investigation, a threat hunter observes a large number of files being renamed with a new extension and a ransom note being dropped in multiple directories. Which ransomware behavior is this most indicative of?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Fortinet. “NSE6-FORTINDR-CLOUD-ANALYST” is a trademark of its owner, used for identification only.