- 33 Actual Exam Questions
- Compatible with all Devices
- Printable Format
- No Download Limits
- 90 Days Free Updates
Get All Fortinet NSE 6 - FortiEDR 7.0 Administrator Exam Questions with Validated Answers
| Vendor: | Fortinet |
|---|---|
| Exam Code: | NSE6_EDR_AD-7.0 |
| Exam Name: | Fortinet NSE 6 - FortiEDR 7.0 Administrator |
| Exam Questions: | 33 |
| Last Updated: | August 24, 2026 |
| Related Certifications: | NSE 6, NSE 6: SASE |
| Exam Tags: |
Looking for a hassle-free way to pass the Fortinet NSE 6 - FortiEDR 7.0 Administrator exam? DumpsProvider provides the most reliable Dumps Questions and Answers, designed by Fortinet certified experts to help you succeed in record time. Available in both PDF and Online Practice Test formats, our study materials cover every major exam topic, making it possible for you to pass potentially within just one day!
DumpsProvider is a leading provider of high-quality exam dumps, trusted by professionals worldwide. Our Fortinet NSE6_EDR_AD-7.0 exam questions give you the knowledge and confidence needed to succeed on the first attempt.
Train with our Fortinet NSE6_EDR_AD-7.0 exam practice tests, which simulate the actual exam environment. This real-test experience helps you get familiar with the format and timing of the exam, ensuring you're 100% prepared for exam day.
Your success is our commitment! That's why DumpsProvider offers a 100% money-back guarantee. If you don’t pass the Fortinet NSE6_EDR_AD-7.0 exam, we’ll refund your payment within 24 hours no questions asked.
Don’t waste time with unreliable exam prep resources. Get started with DumpsProvider’s Fortinet NSE6_EDR_AD-7.0 exam dumps today and achieve your certification effortlessly!
You find third-party software on a user's computer that does not appear in the application list on the communication control console. Which two statements are true about this situation? (Choose two answers)
The best answers are A and D, but be careful: A is directly verified by the guide; D is the only remaining statement that can be true in policy context, but it is weaker than A.
The FortiEDR 7.0.0 Administration Guide states that the Communication Control tab identifies communicating applications detected in the organization. More specifically, the Applications page lists ''all communicating applications detected in your organization that have ever attempted to communicate.'' Therefore, if software exists on a user's computer but does not appear in the Communication Control application list, the most direct explanation is that it has not attempted external communication.
The guide also explains that FortiEDR Communication Control reduces the scope of administration because Security/IT only needs to handle applications that communicate externally. It also states that non-authorized applications can still execute, and only their outgoing communication is prevented. This confirms that the Communication Control application list is not a full software inventory; it is a list of applications that have communicated or attempted communication.
Option B is not correct. If an application were blocked due to FortiEDR security-policy enforcement after a connection attempt, FortiEDR would generate security-event visibility in the Incidents workflow, not simply hide the application from Communication Control. FortiEDR Collectors send communication-related data for Communication Control, and security events are sent for enforcement/monitoring purposes.
Option C is also wrong. Reputation score affects policy decisions and application risk evaluation, but it does not cause an application to be ignored or excluded from the application list. The guide says each application in the Applications page shows a reputation indicator, which proves reputation is displayed for listed applications rather than used to hide them.
For option D, if the application has never attempted communication, Communication Control has no observed communication event to list. In exam logic, this can be interpreted as the application is not currently being denied by Communication Control policies. However, the stronger technical truth is this: Communication Control does not list installed software; it lists applications that have attempted to communicate.
=========
Which two criteria are required for integrating FortiEDR with the Fortinet Security Fabric? (Choose two answers)
The correct answers are A and C.
For Fortinet Security Fabric correlation through FortiAnalyzer or FortiAnalyzer Cloud, the FortiEDR guide states that FortiEDR can integrate with FortiAnalyzer/FortiAnalyzer Cloud ''to correlate data between FortiEDR and the Fortinet Security Fabric and issue eXtended detection alerts.'' To complete this, you must configure an eXtended Detection Source connector and enable eXtended Detection rules and FortiEDR Threat Hunting event collection.
The prerequisites include connectivity from the FortiEDR Central Manager to Fortinet Cloud Services (FCS). The same prerequisite list also requires either a FortiAnalyzer administrator account with JSON API access enabled or, for FortiAnalyzer Cloud, a valid FortiCloud API user with read/write access to the FortiAnalyzer Cloud portal.
Option B is wrong because a Forensics add-on license is not listed as a requirement for this integration. Option D is badly worded and not correct. A Jumpbox with connectivity to FortiAnalyzer is required, and the guide points to FortiEDR Core setup for Jumpbox configuration, but the answer option says Core with core-only functionality, which is not the stated requirement.
=========
Refer to the exhibit:

You are asked to block applications based on hash attributes. Which two factors must you consider when applying the hash value? (Choose two answers)
The FortiEDR 7.0.0 Administration Guide states that when manually adding applications to be blocked, you can define the application using Hash or using any combination of File Name / Path / Signer attributes. This means hashes can be used independently and do not require filename, path, or signer attributes.
The guide also states that each hash is a unique identifier of an individual application, and the exhibit itself shows the hash field note: ''SHA-1 or SHA-2 or MD5.'' Therefore, the hash must use a supported hash format, making D correct.
For multiple hash entries, the uploaded guide text says they must be comma separated, while the exhibit note says ''You can enter multiple hashes comma separated.'' So the technically exact guide wording supports comma separation, not line separation. However, given your answer choices, A is clearly trying to test the requirement that multiple hashes must be separated correctly. The option wording says ''line-separated,'' which is not exact against the guide; the better wording would be comma-separated. Since no ''comma-separated'' option is provided, A is the intended separation-related answer, but the wording is flawed.
Option B is definitely wrong because hash mode is an alternative to attributes. Option C is also not the best answer because, although each hash uniquely identifies a file/application variant, the operational requirement is not that ''hashes must be unique to each application'' in the way the option implies. Hashes may represent different variants of the same application.
You are troubleshooting a FortiEDR 7.0 installation where the Fortinet Cloud Service (FCS) connection is failing, and endpoints are unable to receive threat intelligence updates. You check the diagnostic logs and notice that outbound HTTPS traffic on port 443 is being blocked by your perimeter firewall. After allowing this traffic, you need to verify that the endpoint agents can successfully connect to FCS. What command or diagnostic tool should you use on an endpoint to verify that the FortiEDR agent is able to communicate with the Fortinet Cloud Service?
In FortiEDR 7.0, the endpoint agent status and connectivity can be verified using command-line tools such as forticlient-info (on Windows) or fectl status (on Linux systems). These tools display the current agent status, including FCS connectivity, and will show whether the cloud service connection is active and recent update timestamps.
While netstat or tcpdump could show network connectivity, they do not provide FortiEDR-specific agent status. The FortiEDR management console also displays endpoint status, but the question asks for an endpoint-level verification tool. Administrative event logs or syslog may contain connection errors, but the dedicated diagnostic commands are the proper way to verify agent health and FCS connectivity.
Refer to the Exhibit:

Based on the investigation view shown in the exhibit, which two statements about this event are true? (Choose two answers)
The correct answers are A and C.
The exhibit shows a green checkmark in the Exception column for the filezilla.exe event. In FortiEDR, an exception means a whitelist has been created for a specific flow/security-event pattern. The guide states that exceptions limit enforcement of a rule and that after an exception is defined, identical new events are no longer triggered. It also explains that past security events display an icon indicating that an exception has been defined for them.
The exhibit also shows the event flow ending in filezilla.exe with a red highlighted activity and a blocked symbol. In the Incidents/Investigation workflow, FortiEDR represents blocked policy violations as security events, and the guide explains that FortiEDR can enforce policy by blocking malicious connection establishment requests to prevent exfiltration. It also states that Block means the malicious exfiltration or file-changing attempt was blocked.
Security & Privacy
Satisfied Customers
Committed Service
Money Back Guranteed