Fortinet NSE6_EDR_AD-7.0 Practice Exam Questions & Answers

5 Free Questions · Last reviewed: September 13, 2026 · Prepared & Reviewed by the ValidExamDumps Editorial Team

Exam Facts

Fortinet NSE6_EDR_AD-7.0 Exam Details

Key details for this exam, checked against the published exam outline

39 Practice Questions (Our Bank)
60 minutes Exam Duration
USD 200 Exam Fee
Exam Code
NSE6_EDR_AD-7.0
Full Name
Fortinet NSE 6 - FortiEDR 7.0 Administrator
Issuing Body
Fortinet
Question Format (Our Bank)
Multiple Choice
Delivery
Pearson VUE test center or OnVUE online proctored
Eligibility
No strict prerequisites, but Fortinet recommends 3 years of endpoint security experience and 1 year of network security experience
Practice Questions

Free NSE6_EDR_AD-7.0 Practice Questions

Each question shows the correct answer and an explanation of why it is right

VA
ValidExamDumps Editorial Team Every question and its answer is checked by our NSE6_EDR_AD-7.0 exam preparation team, who also write the explanation shown with each one. How we research and review these pages

Which two Python commands are supported when using FortiEDR Connect to directly access a protected device shell? (Choose two answers)

Correct Answer: A, B
Explanation

The correct answers are A. %upload_file and B. %ipconfig_all.

The FortiEDR 7.0.0 Administration Guide states that FortiEDR Connect opens a console that provides direct access to a FortiEDR-protected device through a remote shell connection. This allows administrators to respond to incidents, run commands and scripts, collect and download forensic data, and remediate threats. The guide also states that the FortiEDR Connect terminal has a prompt where commands can be typed, and the Help button displays the supported commands and their parameters.

The guide further confirms that FortiEDR Connect supports FortiEDR-specific commands, Windows command-line access through %cmd, and Python commands.

For the exact command list, Fortinet's official FortiEDR Connect technical tip lists the supported commands. In that list, %ipconfig_all is explicitly described as returning extended IP information, and %upload_file is explicitly described as uploading a file to the specified path. (Fortinet Community)

Options C. %psexec and D. %timestamp are not listed as supported FortiEDR Connect commands in the official Fortinet command list. Therefore, they must not be selected.

Refer to the exhibits.

The application policy logs and application details are shown. Collector C8092231196 is a member of the Finance group. In this scenario, what must you do to block the FileZilla application? (Choose one answer)

Correct Answer: B
Explanation

The correct answer is B. Deny the application in the Finance policy.

The FortiEDR 7.0.0 Administration Guide states that Communication Control policies define the actions to be taken for a given application or application version. It also states that each Communication Control policy applies to specific Collector Groups, and all devices that belong to those Collector Groups follow that policy. A Collector Group can be assigned to only one Communication Control policy.

In the exhibit, the Collector C8092231196 is stated to be a member of the Finance group. Therefore, to block FileZilla for that Collector, the application action must be set to Deny under the Finance policy, because that is the policy context that applies to the Collector's group.

The guide also explains that you can modify a policy action for an application/version so that the selected application is explicitly set to Allow or Deny for the relevant policy. When modified this way, the Application/Version Details area shows the action as manually changed and excluded from the original policy action.

Option A is wrong because assigning a Simulation Communication Control Policy to the DBA group does not affect a Collector in the Finance group. Option C is wrong because assigning the Finance policy to the DBA group would affect DBA Collectors, not the Finance Collector in the scenario. Option D is wrong because assigning the Finance policy to a broader group such as Default Collector Group is unnecessary and could over-broaden the policy impact. The precise action is to deny FileZilla in the policy that applies to the Collector's own group: Finance policy.

Refer to the exhibit.

What observation can you make about the ConnectivityTestAppNew.exe incident? (Choose one answer)

Correct Answer: B
Explanation

The correct answer is B.

In the exhibit, the incident status clearly shows Unhandled at the incident level and also on the event rows. The FortiEDR guide explains that every detected security event is initially marked as unread and unhandled, and these statuses help multiple FortiEDR Central Manager users track whether anyone has read and handled the message.

The guide also states that when a FortiEDR Central Manager user marks a security event as Handled, all users see it as handled. The process is performed by selecting the event and clicking Handle Incident or the flag icon, then saving the incident handling details.

So the valid observation from the exhibit is that the incident has not been handled by a console administrator.

Option A is not supported by the exhibit. There is no visible evidence that the policy is in Simulation mode. Option C is wrong because the incident is still visible, not archived or deleted. Option D is wrong because the status is explicitly Unhandled; it was not handled automatically by a Communication Control policy.

Refer to the Exhibit:

Based on the investigation view shown in the exhibit, which two statements about this event are true? (Choose two answers)

Correct Answer: A, C
Explanation

The correct answers are A and C.

The exhibit shows a green checkmark in the Exception column for the filezilla.exe event. In FortiEDR, an exception means a whitelist has been created for a specific flow/security-event pattern. The guide states that exceptions limit enforcement of a rule and that after an exception is defined, identical new events are no longer triggered. It also explains that past security events display an icon indicating that an exception has been defined for them.

The exhibit also shows the event flow ending in filezilla.exe with a red highlighted activity and a blocked symbol. In the Incidents/Investigation workflow, FortiEDR represents blocked policy violations as security events, and the guide explains that FortiEDR can enforce policy by blocking malicious connection establishment requests to prevent exfiltration. It also states that Block means the malicious exfiltration or file-changing attempt was blocked.

Which two criteria are required for integrating FortiEDR with the Fortinet Security Fabric? (Choose two answers)

Correct Answer: A, C
Explanation

The correct answers are A and C.

For Fortinet Security Fabric correlation through FortiAnalyzer or FortiAnalyzer Cloud, the FortiEDR guide states that FortiEDR can integrate with FortiAnalyzer/FortiAnalyzer Cloud ''to correlate data between FortiEDR and the Fortinet Security Fabric and issue eXtended detection alerts.'' To complete this, you must configure an eXtended Detection Source connector and enable eXtended Detection rules and FortiEDR Threat Hunting event collection.

The prerequisites include connectivity from the FortiEDR Central Manager to Fortinet Cloud Services (FCS). The same prerequisite list also requires either a FortiAnalyzer administrator account with JSON API access enabled or, for FortiAnalyzer Cloud, a valid FortiCloud API user with read/write access to the FortiAnalyzer Cloud portal.

Option B is wrong because a Forensics add-on license is not listed as a requirement for this integration. Option D is badly worded and not correct. A Jumpbox with connectivity to FortiAnalyzer is required, and the guide points to FortiEDR Core setup for Jumpbox configuration, but the answer option says Core with core-only functionality, which is not the stated requirement.

Get Full Access

39 questions covering all exam domains, starting from $20

Study Guide

What the Fortinet NSE6_EDR_AD-7.0 Exam Covers

Exam domains verified against: Official Fortinet NSE6_EDR_AD-7.0 exam guide, last checked September 2026.

Domain 1: FortiEDR system

Understand FortiEDR architecture and technical positioning, including the Central Manager, Aggregator, and Core components. Master the installation process and perform FortiEDR inventory and system tools operations.

Sample question from this domain above: Q3

Domain 2: FortiEDR security settings and policies

Configure communication control policies and security policies. Understand playbook configuration and Fortinet Cloud Service features for automated incident response.

Sample question from this domain above: Q2

Domain 3: Events, forensics, and threat hunting

Analyze security events and alerts in the Event Viewer. Configure threat hunting profiles and scheduled queries, then analyze threat hunting data to identify indicators of compromise.

Sample questions from this domain above: Q4Q5

Domain 4: FortiEDR integration

Deploy FortiXDR integration and configure security fabric using FortiEDR to work with other Fortinet solutions. Understand how FortiEDR fits into the broader Fortinet Security Fabric architecture.

Sample question from this domain above: Q1

Domain 5: FortiEDR troubleshooting

Perform FortiEDR troubleshooting and analyze alerts and logs to identify issues. Understand how to diagnose problems in the collector and central manager components.

FAQ

NSE6_EDR_AD-7.0 Exam FAQ

Common questions about the exam itself

What hands-on experience should I have before taking the NSE6_EDR_AD-7.0 exam?
Fortinet recommends at least three years working with endpoint security solutions and one year of network security experience. Hands-on experience with FortiEDR in production environments, including configuring policies, playbooks, and collectors, is essential for success on scenario-based questions.
How long does the NSE6_EDR_AD-7.0 exam take and how many questions are on it?
You have 60 minutes to answer 30 to 35 multiple-choice and multiple-select questions. That gives you roughly two minutes per question, so you need solid command of the material to move through it quickly.
What makes the NSE6_EDR_AD-7.0 exam difficult and what topics do candidates struggle with most?
Most questions are scenario-based rather than purely theoretical, asking how FortiEDR responds to attacks and incidents. Candidates often struggle with Security Fabric integration, understanding Prevention versus Detection modes, and the specific workflow steps required to configure and deploy FortiEDR components.
Which area of the NSE6_EDR_AD-7.0 syllabus requires the most study effort?
Playbook configuration, Event Viewer analysis, and threat hunting profiles tend to be the heaviest focus areas on the exam. You need to understand not just what these tools do, but how to apply them in real security incidents.
Is there an NSE 4 prerequisite I need before taking NSE6_EDR_AD-7.0?
There is no strict exam prerequisite, but to earn the NSE 6 SASE certification from this exam, you must hold an active NSE 4 FortiOS certification. This is a certification-level requirement, not an exam-level one.
How long does it typically take to prepare for the NSE6_EDR_AD-7.0 exam?
Most candidates need four to eight weeks of focused study, depending on their hands-on experience. If you already work with endpoint security solutions, you may prepare faster. The Fortinet self-paced training is free and covers the entire syllabus.
What do I need to know about exam day and retakes for NSE6_EDR_AD-7.0?
The exam is proctored through Pearson VUE either at a test center or online via OnVUE. Answers must be 100 percent correct for credit and no partial credit is given. If you do not pass, you can retake the exam by purchasing another exam voucher at USD 200 per attempt.
How long is the NSE6_EDR_AD-7.0 certification valid and what does renewal require?
Your NSE 6 certification is valid for two years from the date you pass the exam. To renew, you must pass any NSE 6 exam in the SASE track before the expiration date. Passing an NSE 7 or NSE 8 exam in the same track also automatically renews your NSE 6 certification.
What job role is the NSE6_EDR_AD-7.0 certification designed for?
This certification targets security professionals responsible for deploying, configuring, and managing FortiEDR solutions. It is aimed at endpoint security administrators, SOC analysts, and security engineers who manage endpoint detection and response across enterprise environments.
How does NSE6_EDR_AD-7.0 fit into the broader Fortinet certification path?
NSE6_EDR_AD-7.0 is one of multiple NSE 6 exams under the SASE certification track. You need to pass this exam plus one NSE 7 exam in the SASE track to earn the full NSE 6 SASE certification. This exam validates your FortiEDR specialist skills before advancing to NSE 7 architect-level topics.