Fortinet · NSE6_FEDR-6.0
Validates the ability to deploy, configure, and manage Fortinet's FortiEDR endpoint detection and response solution. Covers FortiEDR system architecture, security policies, threat hunting, forensics analysis, integration, and troubleshooting.
Practice Questions
600
≈ 10 practice exams
Duration
70 minutes
Passing Score
Pass/Fail
Difficulty
SpecialtyLast Updated
May 2026
Use this NSE6_FEDR-6.0 practice exam to prepare for Fortinet NSE 6 - FortiEDR Administrator (NSE6_FEDR-6.0) with realistic questions, detailed explanations, and focused study modes. The practice bank includes 600 questions for Fortinet NSE6_FEDR-6.0, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to recurring topics such as FortiEDR System Architecture, Security Settings and Policies, Events, Forensics, and Threat Hunting, FortiEDR Integration, and Troubleshooting. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The Fortinet NSE 6 - FortiEDR Administrator (NSE6_FEDR-6.0) certification validates a candidate's applied knowledge of Fortinet's FortiEDR endpoint detection and response platform. The exam assesses the ability to deploy, configure, and operationally manage FortiEDR across enterprise environments, covering the full administrative lifecycle from system architecture and installation through security policy creation, forensic investigation, and active threat hunting. It is part of the broader NSE 6 Network Security Specialist certification track, which requires passing any four NSE 6 exams to earn the designation.
The certification is specifically grounded in real-world administrative tasks. Questions are presented as operational scenarios, configuration extracts, and troubleshooting captures rather than purely theoretical questions, ensuring that certified professionals can apply FortiEDR capabilities in practical enterprise security contexts. Topics span FortiEDR's core pillars: system architecture and inventory management, communication control and security policies, forensics and threat hunting workflows, integration with the Fortinet Security Fabric and FortiXDR, and systematic troubleshooting of endpoint events and alerts.
This certification is designed for network and security professionals who are responsible for the configuration, administration, and day-to-day operation of endpoint security solutions within enterprise network security infrastructures. Typical roles include security operations center (SOC) analysts, endpoint security administrators, and network security engineers who work directly with EDR platforms and need to demonstrate validated expertise with the FortiEDR product.
Candidates who manage or plan to manage FortiEDR deployments—including those handling multi-tenancy environments, playbook configuration, and integration with broader security ecosystems—are the primary audience. Professionals pursuing the NSE 6 Network Security Specialist designation or the NSE Certified Specialist - SASE pathway will also find this exam directly relevant to their certification goals.
Fortinet does not impose strict formal prerequisites for sitting the NSE6_FEDR-6.0 exam, but strongly recommends that candidates bring substantial hands-on experience before attempting it. Specifically, Fortinet advises at least three years of experience working with endpoint security solutions, one year of experience in network security, and one year of practical experience with next-generation antivirus (NGAV) solutions or an Endpoint Management Server (EMS).
In terms of recommended preparation, Fortinet advises completing the FortiEDR Administrator course and its associated hands-on labs. Reviewing the FortiEDR Installation and Administration Guide is also strongly encouraged. Candidates should be comfortable navigating the FortiEDR management console, including the Dashboard, Event Viewer, Forensics tab, Threat Hunting module, Communication Control, Security Policies, Playbooks, Inventory, and Administration sections before sitting for the exam.
The exam consists of 30–35 questions to be completed within a 70-minute time limit, delivered in English. Questions are presented in multiple-choice and multiple-select formats and are designed around applied scenarios including operational situations, configuration extracts, and troubleshooting captures. For multiple-select questions, all answers must be correct to receive credit—no partial credit is awarded.
The exam is scored on a pass/fail basis, and candidates receive a score report through their Pearson VUE account upon completion. Fortinet does not publicly disclose the exact numerical passing threshold. The exam is administered through Pearson VUE, available at authorized testing centers or via the OnVUE online proctoring service. The exam fee is approximately $200 USD. NSE 6 certifications, including this exam, are valid for two years from the date of completion.
Earning the Fortinet NSE 6 FortiEDR Administrator certification positions professionals as validated specialists in endpoint detection and response, a discipline that has become a core requirement in modern enterprise security operations. As organizations increasingly prioritize EDR and XDR capabilities to counter advanced threats, administrators who can demonstrate hands-on FortiEDR expertise are in demand for roles such as SOC analyst, endpoint security engineer, security operations administrator, and cybersecurity consultant. The NSE 6 designation also contributes toward the Fortinet NSE Certified Specialist - SASE pathway, adding further career differentiation.
Within the Fortinet ecosystem, NSE 6 specialists typically command higher compensation than non-certified peers, with security operations roles in enterprise environments commonly ranging from $85,000 to $130,000 USD annually depending on region and broader experience. The certification complements other Fortinet credentials such as the NSE 4 (FortiGate Administrator) and NSE 5 (FortiManager/FortiAnalyzer), and pairs naturally with vendor-neutral EDR and incident response certifications for professionals building a comprehensive security operations skill set.
5 sample questions with answers and explanations. The full bank has 600 questions, enough for 10 full-length practice exams.
Preview — answers shown1. A security analyst at Northwind Traders responds to a Critical-severity FortiEDR detection event and needs to identify which forensic data was automatically captured at the moment of detection without requiring any manual collection request. Which three items are included in the data that FortiEDR automatically collects at detection time? (Select three!)
Multiple correct answersExplanation
FortiEDR automatically captures a rich forensic dataset at the instant a detection event occurs, requiring no analyst action. Process metadata — including name, path, PID, parent PID, and command-line arguments — is collected automatically as it is fundamental to reconstructing the attack chain and identifying process injection or masquerading. File metadata for the suspicious file, including SHA-256 hash, size, timestamps, and signature status, is automatically captured for immediate threat intelligence correlation and classification. Active network connections at the time of detection, including destination IPs and ports, are automatically recorded to identify command-and-control communication or active exfiltration. A full binary dump of physical RAM is not automatically collected — on-demand memory snapshots are available but must be explicitly requested. Windows Event Log exports and full registry hive exports are also on-demand forensic actions that require explicit analyst initiation and are not performed automatically at detection time.
2. Adatum Corporation's security team wants FortiEDR Collectors to send all connection decision requests to the Core for deep analysis of OS stack data, thread information, and process details before any connection is allowed or blocked, giving the Core centralized enforcement authority. Which Collector operating mode must the administrator configure to achieve this behavior? (Select one!)
Explanation
Non-autonomous mode requires the Collector to send connection decision requests to the Core before establishing or blocking a connection. The Core then performs deep analysis of OS stack data, thread information, and process details before returning a verdict to the Collector. Autonomous mode is the default configuration where the Collector analyzes metadata locally and makes decisions independently without requiring Core approval, offering faster response times but less centralized visibility. Detection only mode detects and alerts but does not block any activity. Simulation mode logs what would have happened without enforcing any blocking action.
3. A FortiEDR administrator at Contoso reviews the Collector inventory and notices that several endpoints display a yellow status indicator. Which statement correctly describes what the yellow Degraded state indicates? (Select one!)
Explanation
The Degraded (yellow) state indicates that the Collector agent is connected and communicating with the Central Manager but has an operational issue, most commonly that the kernel-level driver has failed to load or has encountered an error. Without the kernel driver, the Collector cannot perform real-time kernel-level monitoring and prevention, significantly reducing the effectiveness of endpoint protection. This distinction is important because a Degraded Collector may appear connected but is not fully protecting the endpoint. Detection-Only mode is an administrator-configured policy setting and does not change the Collector's connection status color indicator - it remains green (Connected). License expiration causes reduced functionality but does not manifest as the yellow Degraded state specifically. Intermittent connectivity to the Aggregator would eventually result in the red Disconnected state, not the Degraded state.
4. A hospital IT team at Contoso is deploying FortiEDR Collectors to legacy Windows 7 workstations running specialized medical device control software that cannot be upgraded to a newer OS. The MSI installer fails silently on most Windows 7 machines. Which prerequisite is MOST LIKELY missing on these endpoints? (Select one!)
Explanation
Windows 7 requires Microsoft Knowledge Base update KB4474419 to add SHA-2 (SHA-256) code signing support. FortiEDR Collector binaries are digitally signed using SHA-2 certificates, which is the current security standard for executable code signing. Windows 7 out of the box supports only SHA-1 for driver and binary signature verification. Without KB4474419, Windows 7 cannot validate the SHA-2 signature on the FortiEDR Collector installer and will silently refuse to proceed, producing exactly the described symptom. This update is a documented and mandatory prerequisite for Windows 7 FortiEDR deployments. .NET Framework is not a runtime requirement for the FortiEDR Collector. Windows Management Framework 5.1 is a PowerShell dependency unrelated to installer execution. Disabling Windows Defender is unnecessary and would not resolve a code signing certificate verification failure.
5. A security architect at Tailspin Toys is designing a FortiEDR deployment for 12,000 endpoints distributed across three regional offices, each hosting approximately 4,000 endpoints. Which statement about Aggregator deployment is CORRECT for this environment? (Select one!)
Explanation
FortiEDR requires additional Aggregators when the total Collector count exceeds 10,000. With 12,000 endpoints, a minimum of two Aggregators is required to distribute the communication load. A single Aggregator can handle most deployments up to approximately 10,000 Collectors, but this deployment exceeds that threshold. Placing one Aggregator at each regional office is also a best practice to reduce WAN bandwidth consumption by keeping event traffic local before forwarding to the Core. The Aggregator does not perform threat analysis—that is exclusively the Core's function. The Aggregator is a pure communication proxy that handles registration, policy distribution, and event forwarding. While Aggregators are optional for very small deployments where Collectors can communicate directly with the Core, they are required at scale and strongly recommended for multi-site architectures to preserve bandwidth.
Fortinet NSE 5 - FortiWeb 8.0 Administrator
NSE5_FWB-8.0 · 596 questions
Fortinet NSE 6 - FortiAnalyzer 7.4 Administrator (FCP_FAZ_AD-7.4)
FCP_FAZ_AD-7.4 · 600 questions
Fortinet NSE 6 - FortiClient EMS 7.4 Administrator (FCP_FCT_AD-7.4)
FCP_FCT_AD-7.4 · 595 questions
Fortinet NSE 6 - FortiMail 7.4 Administrator
NSE6-FML · 600 questions
Fortinet NSE 6 - FortiSIEM 7.4 Analyst
NSE 6 · 600 questions
Fortinet NSE 6 - FortiSOAR 7.3 Administrator (NSE6_FSR-7.3)
NSE6_FSR-7.3 · 600 questions
$17.99
One-time access to this exam