Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet NSE6_EDR_AD-7.0 Exam - Topic 2 Question 7 Discussion

You are asked to configure a query to run every 15 minutes, automatically searching for specific registry modifications across all endpoints. Which FortiEDR feature must you configure? (Choose one answer)
C) A scheduled query defined within a threat hunting profile
A) A communication control rule with a 15-minute delay
B) A manual query linked to a policy override
D) A new playbook trigger based on the registry change event

Fortinet NSE6_EDR_AD-7.0 Exam - Topic 2 Question 7 Discussion

Actual exam question for Fortinet's NSE6_EDR_AD-7.0 exam
Question #: 7
Topic #: 2
[All NSE6_EDR_AD-7.0 Questions]

You are asked to configure a query to run every 15 minutes, automatically searching for specific registry modifications across all endpoints. Which FortiEDR feature must you configure? (Choose one answer)

Show Suggested Answer Hide Answer
Suggested Answer: C

The correct answer is C.

The FortiEDR guide explains that Threat Hunting searches across endpoint activity events, including registry activity. It states that Threat Hunting can search based on attributes of files, registry keys and values, network, processes, event log, and activity event types. This fits the requirement to search for specific registry modifications across endpoints.

The guide also explains that after filtering activity events, the query can be saved and defined as a Scheduled Query. It says: ''Scheduled Query: Mark this option to automate the process of detecting threats so that this query is run automatically according to the schedule that you define.'' It also states that a security event is automatically created in the Incidents tab when matches are detected, and notifications can be sent through email, Syslog, and other configured methods.

The guide further states that the Repeat Every/On options define the frequency and schedule when the query runs. Therefore, a 15-minute recurring query is handled through the Scheduled Query capability in Threat Hunting, not Communication Control, policy override, or a manual Playbook trigger.

Strictly speaking, the guide calls this a scheduled query under Threat Hunting saved queries, not a ''communication control rule'' or ''manual query.'' Option C is the intended answer.

=========


Contribute your Thoughts:

0/2000 characters

Currently there are no comments in this discussion, be the first to comment!


Save Cancel