Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
Which two Python commands are supported when using FortiEDR Connect to directly access a protected device shell? (Choose two answers)
The correct answers are A. %upload_file and B. %ipconfig_all.
The FortiEDR 7.0.0 Administration Guide states that FortiEDR Connect opens a console that provides direct access to a FortiEDR-protected device through a remote shell connection. This allows administrators to respond to incidents, run commands and scripts, collect and download forensic data, and remediate threats. The guide also states that the FortiEDR Connect terminal has a prompt where commands can be typed, and the Help button displays the supported commands and their parameters.
The guide further confirms that FortiEDR Connect supports FortiEDR-specific commands, Windows command-line access through %cmd, and Python commands.
For the exact command list, Fortinet's official FortiEDR Connect technical tip lists the supported commands. In that list, %ipconfig_all is explicitly described as returning extended IP information, and %upload_file is explicitly described as uploading a file to the specified path. (Fortinet Community)
Options C. %psexec and D. %timestamp are not listed as supported FortiEDR Connect commands in the official Fortinet command list. Therefore, they must not be selected.
Refer to the exhibits.

The application policy logs and application details are shown. Collector C8092231196 is a member of the Finance group. In this scenario, what must you do to block the FileZilla application? (Choose one answer)
The correct answer is B. Deny the application in the Finance policy.
The FortiEDR 7.0.0 Administration Guide states that Communication Control policies define the actions to be taken for a given application or application version. It also states that each Communication Control policy applies to specific Collector Groups, and all devices that belong to those Collector Groups follow that policy. A Collector Group can be assigned to only one Communication Control policy.
In the exhibit, the Collector C8092231196 is stated to be a member of the Finance group. Therefore, to block FileZilla for that Collector, the application action must be set to Deny under the Finance policy, because that is the policy context that applies to the Collector's group.
The guide also explains that you can modify a policy action for an application/version so that the selected application is explicitly set to Allow or Deny for the relevant policy. When modified this way, the Application/Version Details area shows the action as manually changed and excluded from the original policy action.
Option A is wrong because assigning a Simulation Communication Control Policy to the DBA group does not affect a Collector in the Finance group. Option C is wrong because assigning the Finance policy to the DBA group would affect DBA Collectors, not the Finance Collector in the scenario. Option D is wrong because assigning the Finance policy to a broader group such as Default Collector Group is unnecessary and could over-broaden the policy impact. The precise action is to deny FileZilla in the policy that applies to the Collector's own group: Finance policy.
Refer to the exhibit.

What observation can you make about the ConnectivityTestAppNew.exe incident? (Choose one answer)
The correct answer is B.
In the exhibit, the incident status clearly shows Unhandled at the incident level and also on the event rows. The FortiEDR guide explains that every detected security event is initially marked as unread and unhandled, and these statuses help multiple FortiEDR Central Manager users track whether anyone has read and handled the message.
The guide also states that when a FortiEDR Central Manager user marks a security event as Handled, all users see it as handled. The process is performed by selecting the event and clicking Handle Incident or the flag icon, then saving the incident handling details.
So the valid observation from the exhibit is that the incident has not been handled by a console administrator.
Option A is not supported by the exhibit. There is no visible evidence that the policy is in Simulation mode. Option C is wrong because the incident is still visible, not archived or deleted. Option D is wrong because the status is explicitly Unhandled; it was not handled automatically by a Communication Control policy.
Refer to the Exhibit:

Based on the investigation view shown in the exhibit, which two statements about this event are true? (Choose two answers)
The correct answers are A and C.
The exhibit shows a green checkmark in the Exception column for the filezilla.exe event. In FortiEDR, an exception means a whitelist has been created for a specific flow/security-event pattern. The guide states that exceptions limit enforcement of a rule and that after an exception is defined, identical new events are no longer triggered. It also explains that past security events display an icon indicating that an exception has been defined for them.
The exhibit also shows the event flow ending in filezilla.exe with a red highlighted activity and a blocked symbol. In the Incidents/Investigation workflow, FortiEDR represents blocked policy violations as security events, and the guide explains that FortiEDR can enforce policy by blocking malicious connection establishment requests to prevent exfiltration. It also states that Block means the malicious exfiltration or file-changing attempt was blocked.
Which two criteria are required for integrating FortiEDR with the Fortinet Security Fabric? (Choose two answers)
The correct answers are A and C.
For Fortinet Security Fabric correlation through FortiAnalyzer or FortiAnalyzer Cloud, the FortiEDR guide states that FortiEDR can integrate with FortiAnalyzer/FortiAnalyzer Cloud ''to correlate data between FortiEDR and the Fortinet Security Fabric and issue eXtended detection alerts.'' To complete this, you must configure an eXtended Detection Source connector and enable eXtended Detection rules and FortiEDR Threat Hunting event collection.
The prerequisites include connectivity from the FortiEDR Central Manager to Fortinet Cloud Services (FCS). The same prerequisite list also requires either a FortiAnalyzer administrator account with JSON API access enabled or, for FortiAnalyzer Cloud, a valid FortiCloud API user with read/write access to the FortiAnalyzer Cloud portal.
Option B is wrong because a Forensics add-on license is not listed as a requirement for this integration. Option D is badly worded and not correct. A Jumpbox with connectivity to FortiAnalyzer is required, and the guide points to FortiEDR Core setup for Jumpbox configuration, but the answer option says Core with core-only functionality, which is not the stated requirement.
39 questions covering all exam domains, starting from $20
Exam domains verified against: Official Fortinet NSE6_EDR_AD-7.0 exam guide, last checked September 2026.
Understand FortiEDR architecture and technical positioning, including the Central Manager, Aggregator, and Core components. Master the installation process and perform FortiEDR inventory and system tools operations.
Sample question from this domain above: Q3
Configure communication control policies and security policies. Understand playbook configuration and Fortinet Cloud Service features for automated incident response.
Sample question from this domain above: Q2
Analyze security events and alerts in the Event Viewer. Configure threat hunting profiles and scheduled queries, then analyze threat hunting data to identify indicators of compromise.
Deploy FortiXDR integration and configure security fabric using FortiEDR to work with other Fortinet solutions. Understand how FortiEDR fits into the broader Fortinet Security Fabric architecture.
Sample question from this domain above: Q1
Perform FortiEDR troubleshooting and analyze alerts and logs to identify issues. Understand how to diagnose problems in the collector and central manager components.
Common questions about the exam itself