Pre-Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free Fortinet NSE6_EDR_AD-7.0 Practice Exam with Questions & Answers

Questions 1

A playbook is configured with two actions: terminate process and isolate device. The terminate process action fails because the process is protected by Windows. What is the expected behavior for the second action, isolate device? (Choose one answer)

Options:
A.

The playbook execution pauses and requires administrator intervention.

B.

The playbook generates a notification email and execution stops.

C.

The playbook execution stops because the action fails.

D.

The playbook continues and executes the second action.

Fortinet NSE6_EDR_AD-7.0 Premium Access
Questions 2

Which two statements correctly describe the IoT probing process on FortiEDR? (Choose two answers)

Options:
A.

Collectors running on servers are always used for IoT probing.

B.

It identifies nearby devices by retrieving details such as hostname and IP address.

C.

Only healthy collectors participate in IoT probing.

D.

It captures all traffic from neighboring devices for deep packet inspection.

Questions 3

Refer to the Exhibit:

NSE6_EDR_AD-7.0 Question 3

Based on the FortiEDR status output shown in the exhibit, what are two reasons for the degraded state? (Choose two answers)

Options:
A.

The endpoint has windows firewall enabled.

B.

The collector is installed with an incorrect registration password.

C.

The collector is installed with an incorrect port number.

D.

The endpoint cannot reach the central manager.

Questions 4

Refer to the Exhibit:

NSE6_EDR_AD-7.0 Question 4

A FortiEDR analyst is prioritizing response efforts. One application has a vulnerability score of Critical but an Unknown ACI rating, while another has a Medium vulnerability score with active ACI evidence of adversary targeting. Which application must be addressed first? (Choose one answer)

Options:
A.

Both applications should be treated equally because patching is necessary.

B.

The application with the Critical vulnerability score should be addressed first.

C.

The decision depends only on asset criticality, not scores.

D.

The application with the Medium vulnerability score and ACI evidence should be addressed first.

Questions 5

A company requires a global communication policy for a FortiEDR multi-tenant environment. Which recommendation must you make? (Choose one answer)

Options:
A.

Create a separate communication control policy for each organization.

B.

Create a new communication control policy and apply it to multiple organizations.

C.

Create a new communication control policy and delegate it to other organizations.

D.

Create a new communication control policy and assign it globally to all organizations.

Questions 6

A collector attempts to access a known malicious website. FortiEDR is configured for eXtended detection with FortiAnalyzer. What two roles does Fortinet Cloud Services (FCS) perform in this process? (Choose two answers)

Options:
A.

FCS sends a log record to FortiAnalyzer.

B.

FCS sends OS metadata to the FortiEDR manager.

C.

FCS correlates and analyzes the collected logs.

D.

FCS identifies if a malicious event has taken place and reports the detection incident.

Questions 7

What action does an on-premises reputation server take when it receives a hash request that is not found in its local database? (Choose one answer)

Options:
A.

Ignores them until manually updated

B.

Stores them locally and waits for endpoint input

C.

Requests the missing hashes from the cloud reputation service

D.

Automatically blocks applications with unknown hashes

Questions 8

Refer to the exhibit.

NSE6_EDR_AD-7.0 Question 8

What observation can you make about the ConnectivityTestAppNew.exe incident? (Choose one answer)

Options:
A.

A rule assigned action is set to block but the policy is in simulation mode.

B.

The incident has not been handled by a console administrator.

C.

The incident was archived from the console unhandled.

D.

The incident was handled automatically by the communication control policy.

Questions 9

You are asked to configure a query to run every 15 minutes, automatically searching for specific registry modifications across all endpoints. Which FortiEDR feature must you configure? (Choose one answer)

Options:
A.

A communication control rule with a 15-minute delay

B.

A manual query linked to a policy override

C.

A scheduled query defined within a threat hunting profile

D.

A new playbook trigger based on the registry change event

Exam Code: NSE6_EDR_AD-7.0
Certification Provider: Fortinet
Exam Name: Fortinet NSE 6 - FortiEDR 7.0 Administrator
Last Update: Apr 30, 2026
Questions: 33
PDF + Testing Engine
$164.99
$49.5
Testing Engine
$124.99
$37.5
PDF (Q&A)
$104.99
$31.5

Fortinet Related Exams

How to pass Fortinet NSE6_FAC-6.1 - Fortinet NSE 6 - FortiAuthenticator 6.1 Exam
How to pass Fortinet NSE6_FWF-6.4 - Fortinet NSE 6 - Secure Wireless LAN 6.4 Exam
How to pass Fortinet NSE6_FML-6.4 - Fortinet NSE 6 - FortiMail 6.4 Exam
How to pass Fortinet NSE6_FNC-9.1 - Fortinet NSE 6 - FortiNAC 9.1 Exam
How to pass Fortinet NSE6_FAD-6.2 - Fortinet NSE 6 - FortiADC 6.2 Exam
How to pass Fortinet NSE6_FWB-6.4 - Fortinet NSE 6 - FortiWeb 6.4 Exam
How to pass Fortinet NSE6_WCS-7.0 - Fortinet NSE 6 - Cloud Security 7.0 for AWS Exam
How to pass Fortinet NSE6_FAC-6.4 - Fortinet NSE 6 - FortiAuthenticator 6.4 Exam
How to pass Fortinet NSE6_FML-7.2 - Fortinet NSE 6 - FortiMail 7.2 Exam
How to pass Fortinet NSE6_FAZ-7.2 - Fortinet NSE 6 - FortiAnalyzer 7.2 Administrator Exam
How to pass Fortinet NSE6_FSW-7.2 - NSE6_FSW-7.2 - Fortinet NSE 6 - FortiSwitch 7.2 Exam
How to pass Fortinet NSE6_FNC-7.2 - Fortinet NSE 6 - FortiNAC 7.2 Exam
How to pass Fortinet NSE6_FSR-7.3 - Fortinet NSE 6 - FortiSOAR 7.3 Administrator Exam
How to pass Fortinet NSE6_OTS_AR-7.6 - Fortinet NSE 6 - OT Security 7.6 Architect Exam

Fortinet Free Exams

Fortinet Free Exams
Access free Fortinet exam study guides and practice tests at Examstrack. Ensure your success with top-notch preparation resources at Examstrack.