NSE5_EDR5.0 Fortinet NSE 5 FortiEDR 5.0 Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

A cybersecurity analyst is monitoring FortiEDR alerts for a critical financial institution. The system flags three distinct behavioral anomalies on a single endpoint within a short timeframe: an unusual PowerShell script execution exhibiting no prior known signature, a newly established outbound network connection from that endpoint to an IP address outside the organization\'s whitelisted destinations and using an atypical port, and a previously unseen, unsigned process attempting to read from the system\'s registry hives and critical configuration files. Considering FortiEDR\'s capabilities in threat detection and response, what is the most comprehensive and effective immediate response strategy to mitigate this multi-faceted threat, assuming the goal is to contain the incident and eradicate the identified malicious activities?

Isolate the affected endpoint from the network, terminate all detected malicious processes, and initiate a deep forensic scan of the endpoint's file system and memory.
Immediately block the external IP address identified in the network connection and force a reboot of the affected endpoint to clear volatile memory.
Alert the security operations center to manually investigate the PowerShell script and the new process, while monitoring network traffic for further anomalies.
Quarantine all files associated with the detected PowerShell script and the unsigned process, and disable the network interface on the endpoint.

About the NSE5_EDR5.0 Fortinet NSE 5 FortiEDR 5.0 Certification

These free practice questions are designed to help you assess your readiness for the NSE5_EDR5.0 Fortinet NSE 5 FortiEDR 5.0 exam by Fortinet. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.