Fortinet NSE 6 - FortiEDR 7.0 Administrator 온라인 연습
최종 업데이트 시간: 2026년04월21일
당신은 온라인 연습 문제를 통해 Fortinet NSE6_EDR_AD-7.0 시험지식에 대해 자신이 어떻게 알고 있는지 파악한 후 시험 참가 신청 여부를 결정할 수 있다.
시험을 100% 합격하고 시험 준비 시간을 35% 절약하기를 바라며 NSE6_EDR_AD-7.0 덤프 (최신 실제 시험 문제)를 사용 선택하여 현재 최신 34개의 시험 문제와 답을 포함하십시오.
정답:
Explanation:
The central manager is responsible for integrating FortiEDR with external systems such as FortiAnalyzer. When secure and controlled communication is required through a JumpBox, the central manager uses this capability to authenticate and relay communication with FortiAnalyzer for logging, event sharing, and integration purposes.

정답:
Explanation:
When defining a process exclusion using multiple attributes, FortiEDR requires all specified attributes to match for the exclusion to apply. Since both the file name and the path are configured, the exclusion applies only when the process named app.exe is executed from the specified directory C:\Tools.

정답:
Explanation:
Active ACI evidence indicates that adversaries are currently exploiting or targeting the vulnerability in real-world attacks. This makes the threat more immediate and actionable than a vulnerability with a higher severity score but no known adversary activity. Therefore, the application with active adversary targeting should be prioritized for response.

정답: A.D
Explanation:
The exception entry shows it was created and updated by FortinetCloud Services, indicating that Fortinet support enabled the automated FCS playbook that generated the exception. The description explicitly states that the file is classified as good on the device C8092231196, meaning the exception applies specifically to that device rather than globally.
정답:
Explanation:
When an application is defined using the Path attribute, the rule applies only to executables located in the specified directory path. FortiEDR identifies applications using attributes such as file name and path, so the block applies only when the executable file name also matches within that defined path.

정답:
Explanation:
The incident status in the incident handler view is clearly marked as Unhandled. This indicates that no console administrator has taken action to investigate, resolve, or close the incident from the FortiEDR management console.

정답:
Explanation:
The query searches for network activity where the remote port is 3389, which corresponds to RDP traffic. The query is configured as a scheduled threat hunting query with a suspicious classification and runs repeatedly at a defined interval.
When the query condition is matched, FortiEDR generates a security event for that activity, resulting in a security incident being created when the device attempts an RDP connection.

정답:
Explanation:
The event view shows the process TestApplication.exe with status Running, indicating the application was successfully launched on the endpoint. The classification label indicates the event is marked as malicious and the classification source is FortinetCloud Services, confirming that FCS performed the malicious classification.

정답: 
Explanation:
Add applications to the application control manager.
Create a new application group.
Enable the blocklist rule on the application control policy.
To implement an application block policy, the applications must first be defined in the application control manager so FortiEDR can identify them. After defining the applications, they are organized into an application group that can be referenced by policies. Finally, the blocklist rule is enabled in the application control policy to enforce blocking of the defined applications on endpoints.
정답:
Explanation:
The collector must have FortiEDR services running to establish communication with the central manager. If the services are not running, the collector cannot register or appear in the Inventory tab. Communication between the collector and the central manager also requires specific ports to be open, including TCP ports 8081 and 555, which are used for management and communication between the components