Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

FORTIEDR

Total questions: 44

Worksheet time: 27mins

Name
Class
Date
1.

What is the purpose of the Threat Hunting feature?

a)

Delete any file from any collector in the organization

b)

Find and delete all instances of a known malicious file or hash in the organization

c)

Identify all instances of a known malicious file or hash and notify affected users

d)

Execute playbooks to isolate affected collectors in the organization

2.

A FortiEDR security event is causing a performance issue with a third-parry application. What must you do first about the event?

a)

Contact Fortinet support

b)

Terminate the process and uninstall the third-party application

c)

Immediately create an exception

d)

Investigate the event to verify whether or not the application is safe

3.

Which two types of remote authentication does the FortiEDR management console support?(Choose two.)

a)

Radius

b)

SAML

c)

TACACS

d)

LDAP

4.

How does FortiEDR implement post-infection protection?

a)

By preventing data exfiltration or encryption even after a breach occurs

b)

  By using methods used by traditional EDR

c)

By insurance against ransomware

d)

By real-time filtering to prevent malware from executing

5.

What is the benefit of using file hash along with the file name in a threat hunting repository search?

a)

It helps to make sure the hash is really a malware

b)

It helps to check the malware even if the malware variant uses a different file name

c)

It helps to find if some instances of the hash are actually associated with a different file

d)

It helps locate a file as threat hunting only allows hash search

6.

An administrator needs to restrict access to the ADMINISTRATION tab in the central manager for a specific account. What role should the administrator assign to this account?

a)

ADMIN

b)

USER

c)

LOCAL ADMIN

d)

REST API

7.

Which connectors can you use for the FortiEDR automated incident response? (Choose two.)

a)

FortiNAC

b)

FortiGate

c)

FortiSiem

d)

FortiSandbox

8.

What is true about classifications assigned by Fortinet Cloud Service(FCS)?

a)

The core is responsible for all classifications if FCS playbooks are disabled

b)

The core only assigns a classification if FCS is not available

c)

FCS revises the classification of the core based on its database

d)

FCS is responsible for all classifications

9.

A company requires a global communication policy for a FortiEDR multi-tenant environment. How can the administrator achieve this?

a)

An administrator creates a new communication control policy and shares it with other organizations

b)

A local administrator creates new a communication control policy and shares it with other organizations

c)

A local administrator creates a new communication control policy and assigns it globally to all organizations

d)

An administrator creates a new communication control policy for each organization

10.

Which two statements are true about the remediation function in the threat hunting module? (Choose two.)

a)

The file is removed from the affected collectors

b)

The threat hunting module sends the user a notification to delete the file

c)

The file is quarantined

d)

The threat hunting module deletes files from collectors that are currently online.

11.

The FortiEDR core classified an event as inconclusive, but a few seconds later FCS revised the classification to malicious. What playbook actions ate applied to the event?

a)

Playbook actions applied to inconclusive events

b)

Playbook actions applied to handled events

c)

Playbook actions applied to suspicious events

d)

Playbook actions applied to malicious events

12.

Which threat hunting profile is the most resource intensive?

a)

  Comprehensive

b)

Inventory

c)

Default

d)

Standard Collection

13.

FortiXDR relies on which feature as part of its automated extended response?

a)

Playbooks

b)

  Security Policies

c)

Forensic

d)

Communication Control

14.

What is the role of a collector in the communication control policy?

a)

A collector blocks unsafe applications from running

b)

A collector is used to change the reputation score of any application that collector runs

c)

A collector records applications that communicate externally

d)

A collector can quarantine unsafe applications from communicating

15.

An administrator finds a third party free software on a user's computer mat does not appear in me application list in the communication control console Which two statements are true about this situation? (Choose two)

a)

The application is allowed in all communication control policies

b)

The application is ignored as the reputation score is acceptable by the security policy

c)

The application has not made any connection attempts

d)

The application is blocked by the security policies

16.

Which scripting language is supported by the FortiEDR action managed?

a)

TCL

b)

Python

c)

Perl

d)

Bash

17.

Which FortiEDR component is required to find malicious files on the entire network of an organization?

a)

FortiEDR Aggregator

b)

FortiEDR Central Manager

c)

  FortiEDR Threat Hunting Repository

d)

FortiEDR Core

18.

Which security policy has all of its rules disabled by default?

a)

Device Control

b)

Ransomware Prevention

c)

Execution Prevention

d)

Exfiltration Prevention

19.

Which two statements about the FortiEDR solution are true? (Choose two.)

a)

It provides pre-infection and post-infection protection

b)

It is Windows OS only

c)

It provides central management

d)

It provides pant-to-point protection

20.

with respect to operating fortiedr, what does proactive risk mitigation refer to ?

a)

automatically blocking users from installing unauthorized applications

b)

automatically blocking endpoints from communicating to network resources

c)

automatically blocking applications from communicating if they have a poor reputation or CVE score

d)

automatically blocking communication from all applications unless they are specifically enabled

21.

Which fortiedr protection uses NGAV functionality?

a)

incident response

b)

pre-infection

c)

risk mitigation

d)

post-infection

22.

Which three steps does FortiXDR perform to find and prevent cyberattacks?

a)

Extended analysis

b)

Extended Detection

c)

Extended discovery

d)

Extended investigation

e)

extended response

23.

which statements is true about the flow analyzer view in forensics?

a)

it displays a graphic flow diagram

b)

two events can be compared side by side

c)

it shows details about processes and sub processes

d)

the stack memory of specific device can be retrieved

24.

a company requires a global exception for a fortiedr multi tenant environment how can the administrator achieve this ?

a)

the local administrator can create a new exception and share it with other organizations

b)

a user account can create a new exception and share it with other organizations

c)

the administrator can create a new exception and assign it globally to all organizations

d)

the admintrator can create a new exception policy for each organization hosted on fortiedr

25.

which two investigation issues requires a full memory dump of the fortiedrcollector ?

a)

system hang issue

b)

third party application issues

c)

system crash issue

d)

collector and core connectivity issue events

26.

how does the fortiedr approach compare to the traditional EDR?

a)

FortiEDR blocks threats in real time eliminating the response gap

b)

traditional EDR is faster

c)

there is no difference in response time

d)

FortiEDR requires less staff

27.

which two events can tigger fortiedr ngav policy violations?

a)

when a malicious file attempts to communicate externally

b)

when a malicious file executed

c)

when a malicious file is read

d)

when a malicious file attempts to access data

28.

which two types of traffic are allowed while the device is in isolation mode

a)

outgoing ssh connections

b)

http sessions

c)

icmp sessions

d)

incoming RDP connections

29.

which fortiedr component must have jumpbox functionality to connect with fortianalyzer

a)

collector

b)

core

c)

central manager

d)

aggregator

30.

when installing a fortiedr collector why is a registration password for collectors needed

a)

to restrict installation and uninstallation of collectors

b)

to verify fortinet support request

c)

to restrict access to the management console

d)

to verify new group assignment

31.

an administrator finds that a newty installed collector does not display on the inventory tab in the central manager what two troubleshooting steps must the administrator perform

a)

export the collector logs from the central manager

b)

verify the central manager has connectivity to FCS

c)

verify TCP port 8081 and 555 are open

d)

check if the fortiedr services are running on the collector device

32.

which two criteria are requirements of integrating fortiedr into the fortinet security fabric

a)

core with core only functionality

b)

a forensics add on license

c)

central manager connected to FCS

d)

A valid APi user with access to connectors

33.

what is true about the payroll manager exe eventa

a)

an event has not been handled by a console admin

b)

an event has been deleted

c)

a rule assigned action is get to block but the policy is in simulation mode

d)

an event has been handled by the communication control policy

34.

based on the event exception shown in the exhibit which two statements about the exception are true

a)

FCS playbook is enable by fortinet support

b)

the system owner can modify the trigger rules parameters

c)

the exception is applied only on device C8092231196

d)

a partial exception is applied to this event

35.

based on postman outputshown in the exhibit why is the user getting an unathorized

a)

postman cannot reach the central manager

b)

api access is disabled on the central manager

c)

the user has been assigned admin and rest api roles

d)

fortiedr requires a password reset the first time a user logs in

36.

the exhibits show the collector state and active connections the collector is unable to connect to aggregator ip address 10.160.6.100 using default port based on the netstat command outout what must you do to resolve the connectivity issue

a)

reinstall collector agent and use port 555

b)

reinstall collector agent and use port 443

c)

reinstall collector agent and use port 6514

d)

reinstall collector agent and use port 8081

37.
a)

an exception has been created for this event

b)

the device has been isolated

c)

the exfiltration prevention policy been blocked this event

d)

the forensics data displayed in the stacks view

38.
a)

the policy is in simulation mode

b)

the device is moved to isolation

c)

the event has been block

d)

playbooks is configured for this event

39.

the exhibits show application policy logs and application details collector C8092231196 is a member of the finance group what must an administrator do to block the filezilla application

a)

deny application in finance policy

b)

assign finance policy to dba group

c)

assign finance policy to default collector group

d)

assing simulation communication control policy to dba group

40.

based on the threat hunting event details shown in the exhibit which two statements about the event are true

a)

the activity event is associated with the file action

b)

the user fortinet has executed a ping command

c)

the ping exe process was blocked

d)

there are no mitre details available for this event

41.

based on the event shown in the exhibit which two statements about the event are true

a)

the ngav policy has blocked testapplication exe

b)

fcs classified the event as malicious

c)

testapplication.exe is sophisticated malware

d)

the user was able to launch testapplication.exe

42.
a)

the device cannot be remediated

b)

the execution prevention policy has blocked this event

c)

the event was blocked because the certificate is unsigned

d)

device c8092231196 has been isolated

43.

based on the threat hunting query shown in the exhibit, which of the following is true

a)

a security event will be triggered when the device attempts a rdp connection

b)

this query is included in other organizations

c)

the query will only check for network category

d)

rdp connections will be blocked and classfied as suspicious

44.

based on the fortiedr status output shown in the exhibit which two statements about the fortiedr collector are true

a)

the collector device has windows firewall enabled

b)

the collector has been installed with an incorrect port number

c)

the collector has been installed with an incorrect resgistration password

d)

the collector device cannot reach the central manager