Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Fortinet logo

FortinetNSE 6 - FortiNDR Cloud Analyst

Domain 4Objective 3

Perform Threat Hunting Activities NSE6-FORTINDR-CLOUD-ANALYST Practice Questions (Page 4)

Part of the Investigations and Integrations domain, which accounts for 20-30% of the NSE6-FORTINDR-CLOUD-ANALYST exam.

21questions here
5free pages
3concepts
20-30%of the exam

Questions 16–20

  1. 16application · medium

    A threat hunter is analyzing a series of alerts involving a workstation that is making repeated connections to a known malicious IP address on port 443. The workstation is also sending large amounts of data to that IP. Which hypothesis would be most appropriate to guide further hunting?

    Select an answer first
  2. 17expert · hard

    A threat hunter is investigating a potential supply chain attack where a legitimate software update was trojanized. The hunter has identified a malicious DLL that is being loaded by a signed executable. Which hunting approach would be most effective to determine the scope of the compromise?

    Select an answer first
  3. 18expert · hard

    A threat hunter is analyzing an alert that shows a process using a named pipe to communicate with another process on the same host. The hunter suspects this is a sign of lateral movement or malware communication. Which hunting technique would be most effective to confirm the malicious nature of this activity?

    Select an answer first
  4. 19application · medium

    A security team is hunting for ransomware that may have been deployed via a malicious macro in a Word document. Which combination of indicators would be most indicative of this attack chain?

    Select an answer first
  5. 20foundation · easy

    Which of the following is a common indicator of ransomware activity that a threat hunter should look for in network traffic?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Fortinet. “NSE6-FORTINDR-CLOUD-ANALYST” is a trademark of its owner, used for identification only.