NSE6_EDR_AD-7.0 practice question 6 of 10
During a forensics investigation of a detected ransomware incident on an endpoint, you review the timeline of events in the FortiEDR forensics module…
Choose your answer, then check it against the explanation.
During a forensics investigation of a detected ransomware incident on an endpoint, you review the timeline
of events in the FortiEDR forensics module and identify that a legitimate user account executed a suspicious
PowerShell script that began encrypting files 10 minutes later. You want to understand how the script was
delivered and executed. Which forensics analysis feature should you use to trace the execution chain and
identify the parent process that launched the malicious PowerShell command?
Question 6 of 10
Keep practicing
Take the free NSE6_EDR_AD-7.0 practice test
Ten exam-style questions with answers and explanations, plus the exam facts and study guides.
More questions
Other NSE6_EDR_AD-7.0 practice questions
- Question 1A collector attempts to access a known malicious website. FortiEDR is configured for eXte…
- Question 2Within the FortiEDR architecture, which component needs JumpBox capabilities to enable au…
- Question 3Which two Python commands are supported when using FortiEDR Connect to directly access a …
- Question 4An employee leaves the company and no longer has access to the FortiEDR system. You must …
- Question 7Your organization has deployed FortiEDR 7.0 across 500 endpoints distributed across three…
- Question 8You are asked to configure a query to run every 15 minutes, automatically searching for s…
