
FortinetNSE 6 - FortiNDR Cloud Analyst
Domain 4Objective 3
Perform Threat Hunting Activities NSE6-FORTINDR-CLOUD-ANALYST Practice Questions (Page 3)
Part of the Investigations and Integrations domain, which accounts for 20-30% of the NSE6-FORTINDR-CLOUD-ANALYST exam.
21questions here
5free pages
3concepts
20-30%of the exam
Questions 11–15
- 11
A security analyst is reviewing a series of alerts about a user account that has been sending large volumes of email to internal recipients. The emails contain links to a file-sharing site. The analyst notices that the user recently clicked a link in a phishing email. Which threat hunting approach would be most effective to determine if this is a coordinated campaign targeting other users?
Select an answer first - 12
A threat hunter is investigating a series of alerts that show a user account has been used to log in from multiple geographic locations within a short time frame. The user is a high-privilege administrator. The hunter must determine if this is a compromised account or a legitimate use of a VPN. Which approach would be most effective?
Select an answer first - 13
A threat hunter is planning a proactive search for malicious activity. Which approach is characterized by forming a hypothesis based on observed anomalies or threat intelligence, then actively searching for evidence to confirm or refute that hypothesis?
Select an answer first - 14
A threat hunter is investigating a potential ransomware incident. The hunter observes that a process is attempting to access the Windows registry key HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest. Which ransomware behavior does this indicate?
Select an answer first - 15
During a ransomware investigation, a threat hunter observes a large number of files being renamed with a new extension and a ransom note being dropped in multiple directories. Which ransomware behavior is this most indicative of?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Fortinet. “NSE6-FORTINDR-CLOUD-ANALYST” is a trademark of its owner, used for identification only.