Fortinet NSE6_EDR_AD-7.0 Exam Prep
Fortinet NSE 6 - FortiEDR 7.0 Administrator (Page 3 )

Updated On: 5-Oct-2026

SINGLE CHOICE
Your organization has deployed FortiEDR 7.0 across 500 endpoints distributed across three geographical regions, each with its own security team. You need to implement a multi-tenancy structure that allows each regional team to manage their endpoints independently while maintaining centralized visibility at the corporate level.
Which approach best satisfies these requirements?

  1. Configure three separate FortiEDR instances, one per region, and use API integrations to aggregate events into a central dashboard
  2. Create three child organizations (tenants) within the primary FortiEDR organization, assign regional administrators to each tenant, and configure role-based access control (RBAC) to restrict visibility
  3. Deploy FortiEDR in a single-instance mode and use Security Fabric to segment traffic between regions
  4. Implement three separate admin accounts within a single FortiEDR instance and use IP-based access restrictions to isolate regional data

Answer(s): B

Explanation:

FortiEDR 7.0 multi-tenancy supports creating child organizations under a parent organization, which allows for complete administrative and data isolation while maintaining hierarchical reporting. Each child organization (tenant) functions as a separate administrative domain with its own policies, users, and visibility controls, while the parent organization retains the ability to view all child organization data and metrics. This design satisfies both independent management and centralized visibility requirements.
The other options fail because: deploying separate instances eliminates centralized control; Security Fabric is designed for cross-product integration, not organizational segmentation; and IP-based restrictions do not provide proper multi-tenancy isolation or RBAC enforcement.



SINGLE CHOICE
You are configuring a communication control policy in FortiEDR to restrict lateral movement within your network. You need to prevent endpoints from establishing outbound connections to known command-an--control (C2) servers while still allowing legitimate business traffic.
Which policy component should you configure to define the destination restrictions?

  1. Create a network access rule and assign it to the Exploit Prevention module
  2. Define a destination-based rule within the communication control policy using IP address, domain, or port criteria
  3. Configure a firewall rule in the Security Fabric connector to block C2 traffic at the network perimeter only
  4. Use the Forensics module to retroactively block C2 connections after they are detected

Answer(s): B

Explanation:

Communication control policies in FortiEDR allow you to define granular rules that restrict outbound connections based on destination criteria including IP addresses, domain names, and ports. These rules are enforced at the endpoint level, preventing connections before they are established, which is critical for blocking C2 communications.
The other options are incorrect because: Exploit Prevention is for memory-based attacks, not network restrictions; Security Fabric rules operate at the network perimeter and do not enforce endpoint-level communication controls; and Forensics is for post-event investigation, not real-time prevention.



SINGLE CHOICE
While investigating a suspected data exfiltration incident, you use FortiEDR's threat hunting capabilities to search for endpoints that accessed sensitive files in your data repository. You have configured a scheduled query to run daily and send alerts when the threshold of file access events exceeds 50 per hour. The next morning, you receive an alert but notice the query has returned results for endpoints that legitimately access these files as part of normal backup operations.
What should you do to refine your threat hunting profile?

  1. Disable the scheduled query and switch to manual threat hunting only
  2. Increase the threshold to 100 events per hour to reduce false positives
  3. Refine the query to exclude backup service accounts or processes in the profile conditions to reduce false positives while maintaining detection sensitivity
  4. Escalate all alerts to your SIEM platform for external validation

Answer(s): C

Explanation:

Threat hunting profiles in FortiEDR 7.0 allow you to define exclusion conditions and process/account filters within the query logic. Refining the profile to exclude known benign activities—such as backup service accounts or legitimate administrative processes—significantly reduces false positives while preserving the ability to detect actual anomalies. This is the proper tuning approach for scheduled queries.
The other options are suboptimal because: disabling scheduled queries eliminates continuous monitoring; simply raising the threshold may miss genuine threats; and while SIEM integration is valuable, it does not address the root cause of false positives at the detection layer.



SINGLE CHOICE
You are deploying FortiXDR alongside your FortiEDR 7.0 infrastructure to provide extended detection and response across multiple Fortinet products. During the integration setup, you need to configure how FortiEDR will correlate security events with data from your FortiGate firewall and FortiProxy.
Which integration method does FortiXDR use to collect and correlate events from these products?

  1. FortiXDR uses log forwarding syslog receivers to collect raw logs, then performs correlation using machine learning models
  2. FortiEDR pushes events to FortiXDR via REST API calls in real-time, and FortiXDR correlates only FortiEDR events
  3. FortiXDR requires direct agent installation on FortiGate and FortiProxy appliances to collect internal telemetry
  4. Events are correlated exclusively within each product's local instance, and FortiXDR acts only as a reporting aggregator

Answer(s): A

Explanation:

FortiXDR integrates with FortiEDR and other Fortinet products by collecting events and logs through standard log ingestion methods (including syslog, API integrations, and connectors). FortiXDR then performs correlation analysis across the ingested events from multiple products to identify complex, multi-stage attack patterns that would not be evident within a single product's visibility.
The other options are incorrect because: FortiXDR does not rely solely on machine learning correlation without human-tunable rules; FortiEDR events are one input among many, not the only data source; agent installation on appliances is not required for log collection; and FortiXDR's value lies in cross-product correlation, not just aggregation.



FILL IN THE BLANK
You are troubleshooting a FortiEDR 7.0 installation where the Fortinet Cloud Service (FCS) connection is failing, and endpoints are unable to receive threat intelligence updates. You check the diagnostic logs and notice that outbound HTTPS traffic on port 443 is being blocked by your perimeter firewall. After allowing this traffic, you need to verify that the endpoint agents can successfully connect to FCS.
What command or diagnostic tool should you use on an endpoint to verify that the FortiEDR agent is able to communicate with the Fortinet Cloud Service?

  1. forticlient-info or fectl status

Answer(s): A

Explanation:

In FortiEDR 7.0, the endpoint agent status and connectivity can be verified using command-line tools such as forticlient-info (on Windows) or fectl status (on Linux systems). These tools display the current agent status, including FCS connectivity, and will show whether the cloud service connection is active and recent update timestamps.
While netstat or tcpdump could show network connectivity, they do not provide FortiEDR-specific agent status. The FortiEDR management console also displays endpoint status, but the question asks for an endpoint-level verification tool. Administrative event logs or syslog may contain connection errors, but the dedicated diagnostic commands are the proper way to verify agent health and FCS connectivity.



Viewing page 3 of 9
Viewing questions 11 - 15 out of 34 questions


Post your Comments and Discuss Fortinet NSE6_EDR_AD-7.0 exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!