Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet NSE6_EDR_AD-7.0 Exam - Topic 5 Question 5 Discussion

Refer to the exhibit:You configured an execution prevention exclusion with both File Name = app.exe and Path = C:\Tools. What will FortiEDR do? (Choose one answer)
B) Exclude only app.exe when it is running from C:\Tools.
A) Exclude only signed versions of app.exe.
C) Exclude app.exe whenever it appears.
D) Exclude all files in C:\Tools.

Fortinet NSE6_EDR_AD-7.0 Exam - Topic 5 Question 5 Discussion

Actual exam question for Fortinet's NSE6_EDR_AD-7.0 exam
Question #: 5
Topic #: 5
[All NSE6_EDR_AD-7.0 Questions]

Refer to the exhibit:

You configured an execution prevention exclusion with both File Name = app.exe and Path = C:\Tools. What will FortiEDR do? (Choose one answer)

Show Suggested Answer Hide Answer
Suggested Answer: B

The correct answer is B. Exclude only app.exe when it is running from C:Tools.

The FortiEDR 7.0.0 Administration Guide explains that the Exclusion Manager is used to define which processes, files, or domains are excluded from Security Policies monitoring. For Process Exclusions, FortiEDR does not inspect actions performed by specific processes, and those processes are identified by the attributes defined by the administrator.

The guide further explains that process/source attributes can include File Name, Path, Hash, and Signer. It also states that when an exclusion contains multiple conditions, an AND relationship exists between the conditions. If an OR relationship is required, a separate exclusion must be created.

In this exhibit, both conditions are selected:

File Name = app.exe

Path = C:Tools

Because FortiEDR applies an AND relationship between multiple exclusion conditions, the exclusion applies only when both conditions match. Therefore, FortiEDR excludes app.exe only when it is located/running from C:Tools.

Option A is wrong because no Signer condition is selected. Option C is wrong because that would apply if only the file name were used broadly. Option D is wrong because FortiEDR is not excluding every file in C:Tools; it is excluding the process that matches both the file name and path conditions.


Contribute your Thoughts:

0/2000 characters
Veta
3 days ago
D is not right, it’s just about app.exe, not all files.
upvoted 0 times
...
Beata
8 days ago
Wait, are we sure about that? Seems too broad.
upvoted 0 times
...
Zita
13 days ago
Definitely C, that makes the most sense!
upvoted 0 times
...
Niesha
18 days ago
I think it's B, only from C:\Tools.
upvoted 0 times
...
Theodora
24 days ago
C) Exclude app.exe whenever it appears.
upvoted 0 times
...
Tess
29 days ago
I feel like it might be A, but I can't recall if signed versions are specifically mentioned in this context.
upvoted 0 times
...
Roy
1 month ago
I'm a bit confused about the path versus the file name. Does the path limit the exclusion to just that directory?
upvoted 0 times
...
Bo
1 month ago
I remember a similar question about file exclusions, and I think it was about excluding all instances of a file, so maybe it's C?
upvoted 0 times
...
Elli
1 month ago
I think the exclusion applies only to app.exe when it's running from C:\Tools, but I'm not entirely sure.
upvoted 0 times
...

Save Cancel