Fortinet NSE6_EDR_AD-7.0 Prüfungsthemen:
| Abschnitt | Gewichtung | Ziele |
|---|---|---|
| Thema 1: Erkennung von Bedrohungen und Reaktion darauf | 20 % | - Erfassung forensischer Daten - Arbeitsabläufe bei der Reaktion auf Vorfälle - Echtzeit-Blockierung von Bedrohungen - Analyse und Untersuchung von Ereignissen - Automatisierte Beseitigung von Bedrohungen |
| Thema 2: Installation und Konfiguration von FortiEDR | 25 % | - Bereitstellung der Verwaltungsplattform - Voraussetzungen und Planung vor der Installation - Installationsverfahren für den Collector-Agent - Erstkonfiguration und Lizenzierung - Einrichtung des Kommunikationsmanagers |
| Thema 3: Verwaltung und Wartung | 10 % | - Benutzerverwaltung und rollenbasierter Zugriff - Verwaltung von Aktualisierungen und Patches - Verwaltung und Export von Protokolldaten - Verfahren zur Datensicherung und Wiederherstellung - Systemüberwachung und Diagnose |
| Thema 4: Richtlinienverwaltung und Sicherheitsprofile | 25 % | - Übersicht über die vordefinierten Sicherheitsrichtlinien - Zuweisung und Ausrichtung von Richtlinien - Konfiguration von Ausnahmen - Erstellung und Anpassung individueller Richtlinien - Regeln zur Anwendungssteuerung |
| Thema 5: FortiEDR Architektur und Komponenten | 20 % | - Übersicht über die zentrale Architektur von FortiEDR - Komponenten und Funktionsweise des Collector-Agents - Kommunikationsmanager und Cloud-Verwaltungskonsole - Architektur der Verwaltungsplattform |
Fortinet NSE 6 - FortiEDR 7.0 Administrator NSE6_EDR_AD-7.0 Prüfungsfragen mit Lösungen
1. You added three new applications to FortiEDR using only the Path attribute. What are two expected outcomes of this configuration? (Choose two answers)
A) These applications will be disabled until explicitly enabled.
B) These applications will be blocked only if the file name also matches.
C) All instances of these applications will be blocked, regardless of location.
D) Only applications in the specified directory paths will be blocked.
2. Refer to the exhibit.
What observation can you make about the ConnectivityTestAppNew.exe incident? (Choose one answer)
A) A rule assigned action is set to block but the policy is in simulation mode.
B) The incident was handled automatically by the communication control policy.
C) The incident was archived from the console unhandled.
D) The incident has not been handled by a console administrator.
3. A collector triggers a suspicious security incident that is initially flagged as potentially malicious. The environment is connected to the FortiEDR Cloud Service (FCS) for classification. How does FCS process the event for accurate classification? (Choose one answer)
A) By relying solely on the FortiGate firewall policies
B) By comparing the event against only local signatures
C) By correlating collector logs only
D) By data processing, comprehensive automated analysis, and comprehensive manual analysis
4. Refer to the exhibit.
Based on the event shown in the exhibit, which two statements about the event are true? (Choose two answers)
A) The event is marked as Handled.
B) FCS classified the event as malicious.
C) TestApplication.exe is sophisticated malware.
D) The user was able to launch TestApplication.exe.
Fragen und Antworten:
| 1. Frage Antwort: A,D | 2. Frage Antwort: D | 3. Frage Antwort: D | 4. Frage Antwort: B,D |






1046 Kundenbewertungen

