Fortinet NSE6_EDR_AD-7.0 Exam Overview:
| Certification Vendor: | Fortinet |
| Exam Name: | Fortinet NSE 6 - FortiEDR 7.0 Administrator |
| Exam Number: | NSE6_EDR_AD-7.0 |
| Exam Format: | Multiple choice, Multiple response, Scenario-based questions |
| Real Exam Qty: | 30–35 |
| Related Certifications: | Fortinet Certified Solution Specialist (FCSS) - Secure Access Service Edge (SASE) |
| Exam Price: | $200 USD |
| Certificate Validity Period: | 2 years |
| Passing Score: | Pass/Fail (cut score set by Fortinet) |
| Exam Duration: | 70 minutes |
| Available Languages: | English |
| Recommended Training: | FortiEDR 7.0 Administration Guide FortiEDR 7.0 Administrator Training Course |
| Exam Registration: | Pearson VUE |
| Sample Questions: | Fortinet NSE6_EDR_AD-7.0 Sample Questions |
| Exam Way: | Online proctored or onsite at Pearson VUE test centers |
| Pre Condition: | Basic knowledge of network security, endpoint protection concepts, and familiarity with Fortinet security solutions; no mandatory prerequisites |
| Official Syllabus URL: | https://training.fortinet.com/local/staticpage/view.php?page=fortiedr_administrator_exam |
Fortinet NSE6_EDR_AD-7.0 Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Topic 1: Integration and Security Fabric | 15% | - FortiXDR deployment and configuration - Fortinet Security Fabric integration |
| Topic 2: Events, Forensics, and Threat Hunting | 25% | - Forensic analysis and incident investigation - Security event and alert analysis - Threat hunting profiles and queries - Threat hunting data interpretation |
| Topic 3: FortiEDR System Architecture and Deployment | 25% | - Installation and deployment process - Inventory management and system tools - API-based management operations - Multi-tenancy deployment - Architecture and technical positioning |
| Topic 4: Security Settings and Policies | 25% | - Playbooks creation and management - Security policies configuration - Fortinet Cloud Service (FCS) integration - Communication control policies |
| Topic 5: Monitoring and Troubleshooting | 10% | - System monitoring and health checks - Log and alert troubleshooting - Performance and issue diagnosis |
Fortinet NSE 6 - FortiEDR 7.0 Administrator Sample Questions:
1. Within the FortiEDR architecture, which component needs JumpBox capabilities to enable authenticated and controlled communication with FortiAnalyzer? (Choose one answer)
A) Central manager
B) Aggregator
C) Reputation Server
D) Core
2. You are asked to create a playbook to isolate a device with a collector. Which action category does isolating a device with a collector fall under? (Choose one answer)
A) Notifications
B) Investigation
C) Custom
D) Remediation
3. Refer to the Exhibit:
A FortiEDR analyst is prioritizing response efforts. One application has a vulnerability score of Critical but an Unknown ACI rating, while another has a Medium vulnerability score with active ACI evidence of adversary targeting. Which application must be addressed first? (Choose one answer)
A) The application with the Critical vulnerability score should be addressed first.
B) The application with the Medium vulnerability score and ACI evidence should be addressed first.
C) Both applications should be treated equally because patching is necessary.
D) The decision depends only on asset criticality, not scores.
4. Refer to the exhibit.
Based on the event shown in the exhibit, which two statements about the event are true? (Choose two answers)
A) FCS classified the event as malicious.
B) The event is marked as Handled.
C) The user was able to launch TestApplication.exe.
D) TestApplication.exe is sophisticated malware.
Solutions:
| Question # 1 Answer: D | Question # 2 Answer: B | Question # 3 Answer: B | Question # 4 Answer: A,C |

We're so confident of our products that we provide no hassle product exchange.


By Queena


