Fortinet NSE6_EDR_AD-7.0 Exam Overview:
| Certification Vendor: | Fortinet |
| Exam Name: | Fortinet NSE 6 - FortiEDR 7.0 Administrator |
| Exam Number: | NSE6_EDR_AD-7.0 |
| Exam Price: | $200 USD |
| Available Languages: | English |
| Real Exam Qty: | 30–35 |
| Related Certifications: | Fortinet Certified Solution Specialist (FCSS) - Secure Access Service Edge (SASE) |
| Exam Duration: | 70 minutes |
| Exam Format: | Multiple choice, Multiple response, Scenario-based questions |
| Passing Score: | Pass/Fail (cut score set by Fortinet) |
| Certificate Validity Period: | 2 years |
| Recommended Training: | FortiEDR 7.0 Administration Guide FortiEDR 7.0 Administrator Training Course |
| Exam Registration: | Pearson VUE |
| Sample Questions: | Fortinet NSE6_EDR_AD-7.0 Sample Questions |
| Exam Way: | Online proctored or onsite at Pearson VUE test centers |
| Pre Condition: | Basic knowledge of network security, endpoint protection concepts, and familiarity with Fortinet security solutions; no mandatory prerequisites |
| Official Syllabus URL: | https://training.fortinet.com/local/staticpage/view.php?page=fortiedr_administrator_exam |
Fortinet NSE6_EDR_AD-7.0 Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Topic 1: Integration and Security Fabric | 15% | - Fortinet Security Fabric integration - FortiXDR deployment and configuration |
| Topic 2: Events, Forensics, and Threat Hunting | 25% | - Threat hunting profiles and queries - Security event and alert analysis - Threat hunting data interpretation - Forensic analysis and incident investigation |
| Topic 3: FortiEDR System Architecture and Deployment | 25% | - Architecture and technical positioning - Installation and deployment process - Multi-tenancy deployment - API-based management operations - Inventory management and system tools |
| Topic 4: Security Settings and Policies | 25% | - Security policies configuration - Communication control policies - Fortinet Cloud Service (FCS) integration - Playbooks creation and management |
| Topic 5: Monitoring and Troubleshooting | 10% | - Log and alert troubleshooting - System monitoring and health checks - Performance and issue diagnosis |
Fortinet NSE 6 - FortiEDR 7.0 Administrator Sample Questions:
1. Refer to the exhibits.
You are attempting to move a collector into the High Security Collector Group for isolation but encounter an error in the API request as shown in the exhibit. To successfully isolate the collector, which API parameter must you correct? (Choose one answer)
A) Set the target collector group parameter to Engineering group.
B) Update the authorization credentials in the API header.
C) Set the organization parameter to Default.
D) Change the HTTP method in the request from PUT to POST.
2. Refer to the Exhibit:
Based on the investigation view shown in the exhibit, which two statements about this event are true? (Choose two answers)
A) The exfiltration prevention policy blocked this event.
B) The device has been isolated.
C) The raw data is displayed in the stacks view.
D) An exception was created for this incident.
3. Refer to the exhibit:
You configured an execution prevention exclusion with both File Name = app.exe and Path = C:\Tools. What will FortiEDR do? (Choose one answer)
A) Exclude all files in C:\Tools.
B) Exclude app.exe whenever it appears.
C) Exclude only signed versions of app.exe.
D) Exclude only app.exe when it is running from C:\Tools.
4. Refer to the exhibit.
Based on the threat hunting event details shown in the exhibit, which two statements about the event are true?
(Choose two answers)
A) There are no MITRE details available for this event.
B) The PING.EXE process was blocked.
C) The user fortinet has executed a ping command.
D) The activity event is associated with the file action.
Solutions:
| Question # 1 Answer: C | Question # 2 Answer: C,D | Question # 3 Answer: D | Question # 4 Answer: C,D |
We're so confident of our products that we provide no hassle product exchange.


By Moira

