Search Header Logo

EDR example

Authored by Hector Cuello

Computers

Professional Development

EDR example
AI

AI Actions

Add similar questions

Adjust reading levels

Convert to real-world scenario

Translate activity

More...

    Content View

    Student View

20 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

What is true about classifications assigned by Fortinet Cloud Service (FCS)?

FCS revises the classification of the core based on its database.

The core only assigns a classification if FCS is not available.

FCS is responsible for all classifications.

The core is responsible for all classifications if FCS playbooks are disabled.

2.

MULTIPLE SELECT QUESTION

2 mins • 1 pt

Media Image

Based on the forensics data shown in the exhibit, which two statements are true? (Choose two.)

The device cannot be remediated.

The execution prevention policy has blocked this event.

The event was blocked because the certificate is unsigned.

Device C8092231196 has been isolated.

3.

MULTIPLE SELECT QUESTION

2 mins • 1 pt

Media Image

Based on the event shown in the exhibit, which two statements about the event are true? (Choose two.)

The NGAV policy has blocked TestApplication.exe.

FCS classified the event as malicious.

TestApplication.exe is sophisticated malware.

The user was able to launch TestApplication.exe.

4.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

How does FortiEDR implement post-infection protection?

By insurance against ransomware

By preventing data exfiltration or encryption even after a breach occurs

By real-time filtering to prevent malware from executing

By using methods used by traditional EDR

5.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which scripting language is supported by the FortiEDR action manager?

TCL

Bash

Perl

Python

6.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which security policy has all of its rules disabled by default?

Exfiltration Prevention

Execution Prevention

Device Control

Ransomware Prevention

7.

MULTIPLE SELECT QUESTION

2 mins • 1 pt

Media Image

Based on the event shown in the exhibit, which two statements about the event are true? (Choose two.)

The policy is in simulation mode.

The device is moved to isolation.

The event has been blocked.

Playbooks is configured for this event.

Access all questions and much more by creating a free account

Create resources

Host any resource

Get auto-graded reports

Google

Continue with Google

Email

Continue with Email

Classlink

Continue with Classlink

Clever

Continue with Clever

or continue with

Microsoft

Microsoft

Apple

Apple

Others

Others

Already have an account?