Pre-Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > Fortinet > NSE 6 Network Security Specialist > NSE6_EDR_AD-7.0

NSE6_EDR_AD-7.0 Fortinet NSE 6 - FortiEDR 7.0 Administrator Question and Answers

Question # 4

Refer to the Exhibit:

Based on the event shown in the exhibit, which two statements about the event are true? (Choose two answers)

A.

Playbooks are configured for this event.

B.

The policy is in simulation mode.

C.

The device is moved to isolation.

D.

The event has been blocked.

Full Access
Question # 5

An employee leaves the company and no longer has access to the FortiEDR system. You must ensure GDPR compliance regarding the employee’s personal data stored in FortiEDR. Which two data types must be removed to meet GDPR requirements? (Choose two answers)

A.

Device and user name

B.

Installed applications

C.

Installed OS name

D.

IP address and MAC address

Full Access
Question # 6

You added three new applications to FortiEDR using only the Path attribute. What are two expected outcomes of this configuration? (Choose two answers)

A.

These applications will be disabled until explicitly enabled.

B.

Only applications in the specified directory paths will be blocked.

C.

These applications will be blocked only if the file name also matches.

D.

All instances of these applications will be blocked, regardless of location.

Full Access
Question # 7

Refer to the exhibit.

What observation can you make about the ConnectivityTestAppNew.exe incident? (Choose one answer)

A.

A rule assigned action is set to block but the policy is in simulation mode.

B.

The incident has not been handled by a console administrator.

C.

The incident was archived from the console unhandled.

D.

The incident was handled automatically by the communication control policy.

Full Access
Question # 8

Refer to the exhibit.

Based on the event shown in the exhibit, which two statements about the event are true? (Choose two answers)

A.

The event is marked as Handled.

B.

FCS classified the event as malicious.

C.

The user was able to launch TestApplication.exe.

D.

TestApplication.exe is sophisticated malware.

Full Access
Question # 9

A company requires a global communication policy for a FortiEDR multi-tenant environment. Which recommendation must you make? (Choose one answer)

A.

Create a separate communication control policy for each organization.

B.

Create a new communication control policy and apply it to multiple organizations.

C.

Create a new communication control policy and delegate it to other organizations.

D.

Create a new communication control policy and assign it globally to all organizations.

Full Access