Pre-Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmaspas7

Easiest Solution 2 Pass Your Certification Exams

NSE6_EDR_AD-7.0 Fortinet NSE 6 - FortiEDR 7.0 Administrator Free Practice Exam Questions (2026 Updated)

Prepare effectively for your Fortinet NSE6_EDR_AD-7.0 Fortinet NSE 6 - FortiEDR 7.0 Administrator certification with our extensive collection of free, high-quality practice questions. Each question is designed to mirror the actual exam format and objectives, complete with comprehensive answers and detailed explanations. Our materials are regularly updated for 2026, ensuring you have the most current resources to build confidence and succeed on your first attempt.

Page: 1 / 1
Total 33 questions

Refer to the Exhibit:

Based on the incident details shown in the exhibit, which two statements about this incident are true? (Choose two answers)

A.

The destination IP address is blocked by FortiGate.

B.

The incident occurred on only one device.

C.

The incident is classified by the FortiEDR Core.

D.

The incident has already been fully handled.

Refer to the Exhibit:

Based on the FortiEDR status output shown in the exhibit, what are two reasons for the degraded state? (Choose two answers)

A.

The endpoint has windows firewall enabled.

B.

The collector is installed with an incorrect registration password.

C.

The collector is installed with an incorrect port number.

D.

The endpoint cannot reach the central manager.

Within the FortiEDR architecture, which component needs JumpBox capabilities to enable authenticated and controlled communication with FortiAnalyzer? (Choose one answer)

A.

Core

B.

Central manager

C.

Aggregator

D.

Reputation Server

You discovered that a newly installed collector does not display on the Inventory tab in the central manager. Which two troubleshooting steps must you perform? (Choose two answers)

A.

Verify that the central manager can resolve the collector hostname through DNS.

B.

Verify that TCP ports 8081 and 555 are open between the collector and the central manager.

C.

Check whether the FortiEDR services are running on the collector device.

D.

Export and review the collector logs from the Central Manager for connection errors.

Refer to Exhibit.

Based on the Postman output shown in the exhibit, why is the user receiving an unauthorized error? (Choose one answer)

A.

The central manager is rejecting the request because of an unsupported HTTP method.

B.

API access is disabled on the central manager.

C.

The user account does not have the REST API role assigned.

D.

FortiEDR requires a password reset the first time a user logs in.

Which two statements correctly describe the IoT probing process on FortiEDR? (Choose two answers)

A.

Collectors running on servers are always used for IoT probing.

B.

It identifies nearby devices by retrieving details such as hostname and IP address.

C.

Only healthy collectors participate in IoT probing.

D.

It captures all traffic from neighboring devices for deep packet inspection.

A collector triggers a suspicious security incident that is initially flagged as potentially malicious. The environment is connected to the FortiEDR Cloud Service (FCS) for classification. How does FCS process the event for accurate classification? (Choose one answer)

A.

By data processing, comprehensive automated analysis, and comprehensive manual analysis

B.

By relying solely on the FortiGate firewall policies

C.

By comparing the event against only local signatures

D.

By correlating collector logs only

Refer to the exhibit:

You configured an execution prevention exclusion with both File Name = app.exe and Path = C:\Tools. What will FortiEDR do? (Choose one answer)

A.

Exclude only signed versions of app.exe.

B.

Exclude only app.exe when it is running from C:\Tools.

C.

Exclude app.exe whenever it appears.

D.

Exclude all files in C:\Tools.

Refer to the exhibit.

Based on the exhibit, which two observations are true? (Choose two answers)

A.

FortiEDR has classified this as suspicious.

B.

This incident has been resolved.

C.

FCS has classified this as malicious.

D.

EDR has never encountered this malware before.

Page: 1 / 1
Total 33 questions
Copyright © 2014-2026 Solution2Pass. All Rights Reserved