View all questions & answers for the NSE 6 - FortiEDR 7.0 Administrator Exam Materials exam


NSE 6 - FortiEDR 7.0 Administrator Exam Materials-Question 39 Discussion
Comment Image Comment Image Comment Image

An organization wants to implement an eXtended detection policy using FortiEDR. You are asked to enable threat hunting events collection for a specific group of devices. Which two event types should you enable in the collection profile? (Choose two answers)

  • A. Socket Connect
  • B. Process Creation
  • C. Registry Modification
  • D. Network Actions
Correct Answer: A,B

Brave-Dump Clients Votes

AB 100%

Comments



IBS 2026-07-06 17:15:28

Selected Answers: A, B


A and B, page 240
https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/50bc9e02-d6cb-11f0-8b43-d2943efe5b2f/FortiEDR-7.2.1-Administration_Guide.pdf
  • Brave-Dumps.com Admin 2026-07-11 23:01:30
    Exactly, thank you.


Brave-Dumps.com Admin 2026-07-11 23:01:14

Selected Answers: A, B


Correct answers: A and B

Fortinet requires the following Threat Hunting event types for devices using an eXtended Detection policy:

Socket Connect
Process Creation
File Create
File Detected

Therefore, from the available options, select:

A. Socket Connect
B. Process Creation