View all questions & answers for the NSE 6 - FortiEDR 7.0 Administrator Exam Materials exam
NSE 6 - FortiEDR 7.0 Administrator Exam Materials-Question 4 Discussion
Comments
Selected Answers: A
https://community.fortinet.com/t5/Blogs/How-Threat-hunters-Can-Create-Scheduled-Queries-and-Custom/ba-p/238197
• No action will be done in this query because there is not a playbook configured and associated to it (playbooks could be associated to do actions) = No blocking
https://community.fortinet.com/t5/FortiEDR/Technical-Tip-FortiEDR-threat-hunting-overview-and-best/ta-p/421672
• The “Custom Query” option is not selected which means it is not visible to all organizations.
Administration Guide FortiEDR 7.2.1 p139 : https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/50bc9e02-d6cb-11f0-8b43-d2943efe5b2f/FortiEDR-7.2.1-Administration_Guide.pdf
Selected Answers: A
“Schedule queries to automate threat detection.”
“If a query matches a threat in the defined schedule, an event appears on the Incidents tab.”
“If a query matches a threat in the defined schedule, an event appears on the Incidents tab, and FortiEDR generates email and Syslog notifications.”
Refer to the exhibit. Based on the exhibit, which statement about this threat hunting query is true? (Choose one answer)
Brave-Dump Clients Votes