● NSE 6 - FortiDLP 26 Administrator Exam Materials

NSE6_DLP_AD-26: Fortinet NSE 6 - FortiDLP 26 Administrator Exam Materials





Question #1
Comment Image Comment Image Comment Image

Refer to the exhibit.

Which two steps can be taken to fix the browser issue? (Choose two answers)

  • A. Restart the browser on the node.
  • B. Restart the FortiDLP agent service on the node.
  • C. Set Private browsing to Allow in the agent configuration.
  • D. Reinstall the FortiDLP browser extension on Chrome
Question #2
Comment Image Comment Image Comment Image

The user is using an unauthorized browser and sees the display message shown above.

Why can't the user proceed? (Choose one answer)

  • A. Must click the mandatory link.
  • B. Must enter at least 512 characters as the reason for violation.
  • C. Must provide a better reason for policy violation.
  • D. Must acknowledge only after clicking the mandatory link.
Question #3
Comment Image Comment Image Comment Image

Refer to the exhibits.

The administrator sees an issue where an event is being generated, but does not match the sequence rule that they created for it to raise an incident.

What could be the issue? (Choose one answer)

  • A. The sequence rule must be published for it to take effect.
  • B. The event's risk score must match or be lower than the sequence rule's risk score.
  • C. The sequence rule must be enabled for it to take effect.
  • D. The event indicator does not match the mandatory configured stage.
Question #4
Comment Image Comment Image Comment Image

Refer to the exhibit.

FortiAnalyzer is receiving events is shown. (Choose one answer)

  • A. How does FortiDLP send events to FortiAnalyzer?
  • B. Through event streaming using webhooks.
  • C. Through event streaming using the service API.
  • D. Through FortiAnalyzer connector.
  • E. Through incident email notifications.
Question #5
Comment Image Comment Image Comment Image

Which two factors differentiate FortiDLP from legacy DLP solutions? (Choose two answers)

  • A. FortiDLP provides single alerts but not sequenced alerts which are possible through legacy DLP solutions.
  • B. FortiDLP provides in-depth insights into SaaS and GenAI solutions as opposed to limited visibility by legacy DLP solutions.
  • C. FortiDLP gathers forensics in the form of files, screenshots, and fingerprinting as opposed to only file forensics by legacy DLP.
  • D. FortiDLP doesn't require policies to be applied for visibility into user data.
Question #6
Comment Image Comment Image Comment Image

Refer to the exhibits.

An analyst was alerted about an incident raised by the FortiDLP console. (Choose one answer)

  • A. Upon review, what can the analyst conclude about the incident?
  • B. The incident covers four stages of the MITRE ATT&CK framework.
  • C. The events detected are monitoring only GenAI SaaS applications.
  • D. You are seeing multiple occurrences of a user trying to download from an unsanctioned drive.
  • E. This is a clustered incident.
Question #7
Comment Image Comment Image Comment Image

Refer to the exhibits.

On the FortiDLP console, an adminstrator sees this color-coded status of one of the nodes.
What does it indicate? (Choose one answer)

  • A. A healthy component that is in a transitory state.
  • B. An unhealthy component that requires attention.
  • C. An unhealthy component because it was suppressed.
  • D. A healthy component that is not generating events, but doing so as expected.
Question #8
Comment Image Comment Image Comment Image

Which three ways you can integrate users with the FortiDLP console? (Choose two answers)

  • A. Using a CSV import
  • B. Using the LDAP sync tool
  • C. Using API
  • D. Using webhooks
  • E. Using Entra ID
Question #9
Comment Image Comment Image Comment Image

Which two actions occur when the FortiDLP console requests a debug bundle and the endpoint agent is offline? (Choose two answers)

  • A. The request never expires, and the action is executed once the agent is back online.
  • B. Same request action is executed only after the agent comes back online.
  • C. If the agent does not reconnect in 30 days, the request expires.
  • D. A new request must be initiated after the agent comes back online.
Question #10
Comment Image Comment Image Comment Image

How does FortiDLP baseline user behavior? (Choose one answer)

  • A. FortiDLP requires creating a new agent configuration for baselining user behavior.
  • B. FortiDLP requires base agent configuration for baselining user behavior starting from day one.
  • C. FortiDLP requires agent configuration with web monitoring set to enabled for baselining user behavior.
  • D. FortiDLP requires policies to be set in addition to agent configuration for baselining user behavior.