Fortinet · NSE6_FEDR-6.0
Validates the ability to deploy, configure, and manage Fortinet's FortiEDR endpoint detection and response solution. Covers FortiEDR system architecture, security policies, threat hunting, forensics analysis, integration, and troubleshooting.
Practice Questions
600
≈ 10 practice exams
Duration
70 minutes
Passing Score
Pass/Fail
Difficulty
SpecialtyLast Updated
May 2026
Use this NSE6_FEDR-6.0 practice exam to prepare for Fortinet NSE 6 - FortiEDR Administrator (NSE6_FEDR-6.0) with realistic questions, detailed explanations, and focused study modes. The practice bank includes 600 questions for Fortinet NSE6_FEDR-6.0, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to recurring topics such as FortiEDR System Architecture, Security Settings and Policies, Events, Forensics, and Threat Hunting, FortiEDR Integration, and Troubleshooting. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The Fortinet NSE 6 - FortiEDR Administrator (NSE6_FEDR-6.0) certification validates a candidate's applied knowledge of Fortinet's FortiEDR endpoint detection and response platform. The exam assesses the ability to deploy, configure, and operationally manage FortiEDR across enterprise environments, covering the full administrative lifecycle from system architecture and installation through security policy creation, forensic investigation, and active threat hunting. It is part of the broader NSE 6 Network Security Specialist certification track, which requires passing any four NSE 6 exams to earn the designation.
The certification is specifically grounded in real-world administrative tasks. Questions are presented as operational scenarios, configuration extracts, and troubleshooting captures rather than purely theoretical questions, ensuring that certified professionals can apply FortiEDR capabilities in practical enterprise security contexts. Topics span FortiEDR's core pillars: system architecture and inventory management, communication control and security policies, forensics and threat hunting workflows, integration with the Fortinet Security Fabric and FortiXDR, and systematic troubleshooting of endpoint events and alerts.
This certification is designed for network and security professionals who are responsible for the configuration, administration, and day-to-day operation of endpoint security solutions within enterprise network security infrastructures. Typical roles include security operations center (SOC) analysts, endpoint security administrators, and network security engineers who work directly with EDR platforms and need to demonstrate validated expertise with the FortiEDR product.
Candidates who manage or plan to manage FortiEDR deployments—including those handling multi-tenancy environments, playbook configuration, and integration with broader security ecosystems—are the primary audience. Professionals pursuing the NSE 6 Network Security Specialist designation or the NSE Certified Specialist - SASE pathway will also find this exam directly relevant to their certification goals.
Fortinet does not impose strict formal prerequisites for sitting the NSE6_FEDR-6.0 exam, but strongly recommends that candidates bring substantial hands-on experience before attempting it. Specifically, Fortinet advises at least three years of experience working with endpoint security solutions, one year of experience in network security, and one year of practical experience with next-generation antivirus (NGAV) solutions or an Endpoint Management Server (EMS).
In terms of recommended preparation, Fortinet advises completing the FortiEDR Administrator course and its associated hands-on labs. Reviewing the FortiEDR Installation and Administration Guide is also strongly encouraged. Candidates should be comfortable navigating the FortiEDR management console, including the Dashboard, Event Viewer, Forensics tab, Threat Hunting module, Communication Control, Security Policies, Playbooks, Inventory, and Administration sections before sitting for the exam.
The exam consists of 30–35 questions to be completed within a 70-minute time limit, delivered in English. Questions are presented in multiple-choice and multiple-select formats and are designed around applied scenarios including operational situations, configuration extracts, and troubleshooting captures. For multiple-select questions, all answers must be correct to receive credit—no partial credit is awarded.
The exam is scored on a pass/fail basis, and candidates receive a score report through their Pearson VUE account upon completion. Fortinet does not publicly disclose the exact numerical passing threshold. The exam is administered through Pearson VUE, available at authorized testing centers or via the OnVUE online proctoring service. The exam fee is approximately $200 USD. NSE 6 certifications, including this exam, are valid for two years from the date of completion.
Earning the Fortinet NSE 6 FortiEDR Administrator certification positions professionals as validated specialists in endpoint detection and response, a discipline that has become a core requirement in modern enterprise security operations. As organizations increasingly prioritize EDR and XDR capabilities to counter advanced threats, administrators who can demonstrate hands-on FortiEDR expertise are in demand for roles such as SOC analyst, endpoint security engineer, security operations administrator, and cybersecurity consultant. The NSE 6 designation also contributes toward the Fortinet NSE Certified Specialist - SASE pathway, adding further career differentiation.
Within the Fortinet ecosystem, NSE 6 specialists typically command higher compensation than non-certified peers, with security operations roles in enterprise environments commonly ranging from $85,000 to $130,000 USD annually depending on region and broader experience. The certification complements other Fortinet credentials such as the NSE 4 (FortiGate Administrator) and NSE 5 (FortiManager/FortiAnalyzer), and pairs naturally with vendor-neutral EDR and incident response certifications for professionals building a comprehensive security operations skill set.
5 sample questions with answers and explanations. The full bank has 600 questions, enough for 10 full-length practice exams.
Preview — answers shown1. A security architect is reviewing the FortiEDR deployment documentation before presenting the architecture to executive leadership. Which FortiEDR component is the ONLY one that provides a web-based user interface and serves as the centralized management console for administrators? (Select one!)
Explanation
The Central Manager is explicitly described in official FortiEDR documentation as the only component with a user interface. It provides the HTTPS-based web console (accessible on TCP 443) for all administrative tasks including policy management, event viewing, forensic analysis, reporting, and RBAC configuration. The Core is a back-end analysis engine with no direct admin UI. The Aggregator is a communication proxy with no UI. The Collector is a silent endpoint agent running on monitored devices with no management interface.
2. A security engineer at Contoso is designing firewall rules for a new FortiEDR deployment. Collector agents on endpoint workstations must be able to send security events and heartbeat data to the Aggregator. Which TCP port must be permitted outbound from the endpoint Collectors to the Aggregator? (Select one!)
Explanation
Collector-to-Aggregator communication uses TCP 8081 by default for all security events, heartbeat traffic, and policy receipt. TCP 443 is used for the management console (HTTPS web UI) and for Core-to-Central Manager communication. TCP 8443 is an alternate management port used for Core-to-Central Manager management traffic. TCP 80 is not part of any FortiEDR communication flow. Blocking TCP 8081 between Collectors and the Aggregator severely degrades protection, as events cannot be forwarded for analysis and policy updates cannot be received. All Collector-to-Aggregator traffic on this port is encrypted using TLS and is initiated outbound-only from the Collector, meaning no inbound ports need to be opened on endpoint machines.
3. Tailspin operates in both the healthcare sector under HIPAA and the financial sector under SOX. The compliance team is configuring FortiEDR log retention periods and must satisfy both regulatory frameworks simultaneously with a single retention policy. Which retention period correctly satisfies both HIPAA and SOX requirements? (Select one!)
Explanation
To satisfy both HIPAA and SOX simultaneously, the organization must retain logs for the longest period required by either framework. HIPAA requires a minimum of 6 years of retention for security-related records and documentation. SOX requires 7 years of retention for audit records and financial reporting data. Since 7 years exceeds both the 6-year HIPAA minimum and meets the 7-year SOX requirement exactly, configuring a 7-year retention period satisfies both regulations with a single policy. Retaining logs for only 6 years would meet HIPAA but fall one year short of SOX's requirement. PCI DSS requires 1 year of total retention with at least 3 months immediately accessible, which is the shortest of the major frameworks and insufficient for HIPAA or SOX. Any organization subject to multiple regulatory frameworks must configure retention to meet the most stringent applicable requirement.
4. A sales engineer at Fabrikam is evaluating FortiEDR for a customer who requires threat hunting capabilities, automated playbook execution, forensic analysis, and MITRE ATT&CK technique mapping for their SOC team. Which FortiEDR license tier is the MINIMUM required to meet these requirements? (Select one!)
Explanation
The FortiEDR Protect and Respond license tier is the minimum tier that includes threat hunting, forensic analysis, automated playbooks, and MITRE ATT&CK technique mapping. The Discover tier provides only asset discovery, vulnerability assessment, and IoT device detection — no prevention or advanced response capabilities. The Protect tier adds pre-execution and post-execution prevention on top of Discover, but does NOT include threat hunting, forensics, or automated playbooks, which are the core capabilities the customer's SOC team specifically requires. MDR is an additional managed service tier that includes Fortinet's own SOC team performing monitoring and response on behalf of the customer — this exceeds the stated requirements and adds cost beyond what is needed. Protect and Respond is precisely scoped to deliver the advanced SOC investigation and automation features requested.
5. Northwind's security team is reviewing documentation on FortiSandbox integration verdicts. They want to identify which verdict types are returned specifically by FortiSandbox after dynamic file analysis, as distinct from Core engine verdicts. Which three of the following are valid FortiSandbox verdicts returned to FortiEDR? (Select three!)
Multiple correct answersExplanation
FortiSandbox returns five possible verdict types to FortiEDR after completing dynamic analysis: Clean, Low Risk, Medium Risk, High Risk, and Malicious. Of the options listed, Clean, High Risk, and Low Risk are all valid FortiSandbox verdicts. Unresolved and Inconclusive are Core engine verdicts that indicate analysis state — Unresolved means Core analysis is still pending, and Inconclusive means Core analysis completed but produced an ambiguous result. Suspicious is a Core engine classification verdict used for events that appear likely malicious but are not yet confirmed, not a FortiSandbox-specific result.
Fortinet NSE 5 - FortiWeb 8.0 Administrator
NSE5_FWB-8.0 · 596 questions
Fortinet NSE 6 - FortiAnalyzer 7.4 Administrator (FCP_FAZ_AD-7.4)
FCP_FAZ_AD-7.4 · 600 questions
Fortinet NSE 6 - FortiClient EMS 7.4 Administrator (FCP_FCT_AD-7.4)
FCP_FCT_AD-7.4 · 595 questions
Fortinet NSE 6 - FortiMail 7.4 Administrator
NSE6-FML · 600 questions
Fortinet NSE 6 - FortiSIEM 7.4 Analyst
NSE 6 · 600 questions
Fortinet NSE 6 - FortiSOAR 7.3 Administrator (NSE6_FSR-7.3)
NSE6_FSR-7.3 · 600 questions
$17.99
One-time access to this exam