Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet NSE6_EDR_AD-7.0 Exam - Topic 2 Question 6 Discussion

Refer to the exhibit.Based on the exhibit, which two observations are true? (Choose two answers)
C) FCS has classified this as malicious. and D) EDR has never encountered this malware before.
A) FortiEDR has classified this as suspicious.
B) This incident has been resolved.

Fortinet NSE6_EDR_AD-7.0 Exam - Topic 2 Question 6 Discussion

Actual exam question for Fortinet's NSE6_EDR_AD-7.0 exam
Question #: 6
Topic #: 2
[All NSE6_EDR_AD-7.0 Questions]

Refer to the exhibit.

Based on the exhibit, which two observations are true? (Choose two answers)

Show Suggested Answer Hide Answer
Suggested Answer: C, D

The correct answers are C and D.

The exhibit shows the incident classification as Malicious. In the Activity Audit, the entry from FortinetCloudServices states: ''Classification change: Malicious'' and also says the file is classified as malicious. This directly proves that FCS classified the event as malicious. The FortiEDR guide explains that the audit history shows the chronology for classifying the security event and displays details when FortiEDR Cloud Service (FCS) reclassifies a security event after its initial classification by the Core.

The exhibit also states that the file was ''Detected as Unknown malware.'' This supports option D in the exam wording: FortiEDR/FCS has classified the file as malicious, but it is being identified as unknown malware, meaning it was not recognized as a known malware family/signature at the time of classification. The guide explains that FCS enhances classification using data enrichment, automated and manual analysis, file analysis, sandboxing, machine learning flow analysis, commonality analysis, crowdsourced data deduction, and other methods, so ''unknown malware'' can still be classified malicious by FCS.

Option A is wrong because the exhibit shows Malicious, not Suspicious. Option B is wrong because the incident status is Unhandled, not resolved or handled.

=========


Contribute your Thoughts:

0/2000 characters
Lauran
3 days ago
C) FCS has classified this as malicious, for sure!
upvoted 0 times
...
Latrice
8 days ago
B) This incident has been resolved, right?
upvoted 0 times
...
Joaquin
13 days ago
Wait, how can we be sure about that?
upvoted 0 times
...
Reiko
18 days ago
Totally agree, that makes sense!
upvoted 0 times
...
Charlene
24 days ago
A) FortiEDR has classified this as suspicious.
upvoted 0 times
...
Christa
29 days ago
D seems unlikely because I feel like EDR usually has some history with malware. I might be overthinking it though.
upvoted 0 times
...
Jesusita
1 month ago
C sounds familiar, but I can't recall if FCS always classifies things as malicious. I might be mixing it up with another question.
upvoted 0 times
...
Reita
1 month ago
I remember a practice question where we had to identify if an incident was resolved or not. I feel like B could be a possibility, but I need to double-check the exhibit.
upvoted 0 times
...
Carma
1 month ago
I think A might be correct since it mentions that FortiEDR classified it as suspicious, but I'm not entirely sure.
upvoted 0 times
...

Save Cancel