About the Exam

This exam evaluates applied knowledge of FortiEDR configuration, operation, and day-to-day administration, including operational scenarios, configuration extracts, and troubleshooting captures. It is intended for network and security professionals responsible for configuring and administering endpoint security solutions in an enterprise network security infrastructure. Passing demonstrates practical ability to work with FortiEDR at an administrative level and earns the corresponding exam badge.

Exam Topics

  • FortiEDR system20%
  • FortiEDR security settings and policies20%
  • Events, forensics, and threat hunting20%
  • FortiEDR integration20%
  • FortiEDR troubleshooting20%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated June 21, 2026 at 7:40 PM

Topic filter
Retired questions
Question sort

QuestionQ1

FortiEDR system

Which two statements accurately describe the IoT probing process in FortiEDR?

Choose two
  • A Collectors running on servers are always used for IoT probing.
  • B It identifies nearby devices by retrieving details such as hostname and IP address.
  • C Only healthy collectors participate in IoT probing.
  • D It captures all traffic from neighboring devices for deep packet inspection.
Explanation

FortiEDR IoT discovery probes nearby neighboring devices and obtains identifying details such as device or host name and IP address. Collectors that are degraded, disabled, or isolated are excluded from the IoT probing process; server-based Collectors are also excluded. Fortinet: IoT Device Discovery

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

FortiEDR system

What does an on-premises reputation server do when it receives a hash request that is absent from its local database?

  • A Automatically blocks applications with unknown hashes
  • B Ignores them until manually updated
  • C Requests the missing hashes from the cloud reputation service
  • D Stores them locally and waits for endpoint input
Explanation

When a file hash is not present in the on-premises TIE server database, the server queries the cloud-based McAfee GTI reputation service for that hash’s reputation and stores the available result.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

FortiEDR integration

A collector generates a suspicious security incident that is initially marked as potentially malicious.

The environment is connected to the FortiEDR Cloud Service (FCS) for classification.

How does FCS handle the event to classify it accurately?

  • A By comparing the event against only local signatures
  • B By correlating collector logs only
  • C By relying solely on the FortiGate firewall policies
  • D By data processing, comprehensive automated analysis, and comprehensive manual analysis
Explanation

FortiEDR Cloud Service enriches event data and performs deep analysis and investigation through automated and manual processes to determine the final, accurate security-event classification. FortiEDR Administration Guide

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

FortiEDR security settings and policies

An employee leaves the company and no longer has access to the FortiEDR system. You must ensure GDPR compliance for the employee’s personal data stored in FortiEDR.

Which two data types must be removed to satisfy GDPR requirements?

Choose two
  • A Installed applications
  • B Installed OS name
  • C Device and user name
  • D IP address and MAC address
Explanation

FortiEDR GDPR personal-data handling requires removal of all employee/user device-name and user-name data, as well as IP-address and MAC-address data. Installed applications and the installed OS name are not among the specified required data types.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

FortiEDR security settings and policies

You discover third-party software on a user’s computer that is not shown in the application list on the communication control console.

Which two statements are true in this situation?

Choose two
  • A The application has not made any connection attempts.
  • B The application is allowed in all communication control policies.
  • C The application is ignored because its reputation score is acceptable to the security policy.
  • D The application is blocked by the security policies.
Explanation

FortiEDR Communication Control maps applications that communicate externally, so an application absent from the application list has not made connection attempts. Applications without a specific communication-control entry are allowed by the communication-control policies; an acceptable reputation score is not the reason an application is absent from the list.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

That's the end of the preview

It's free

100% of the questions are free for all users.
No strings attached.

Topics covered
FortiEDR systemFortiEDR security settings and policiesEvents, forensics, and threat huntingFortiEDR integrationFortiEDR troubleshooting
Know a question that should be here? Contribute to this exam
Back home