NSE 6
FortiEDR Administrator
Part of NSE 6: SASE
Time allowed: 60–70 minutes. Language: English. Product version: FortiEDR 7.0.
Independent study aid built from the public exam blueprint. Not affiliated with, authorized by, or endorsed by fortinet. Objectives are transcribed and mapped by hand, so this page may contain mistakes or may have fallen behind the vendor's current material: exam objectives, versions, numbering and availability all change without notice. Treat fortinet's own certification portal as the source of truth and verify against it before you book anything.
FortiEDR system
1.01 Explain FortiEDR architecture and technical positioning
Official manual: FortiEDR—Installation and Administration Guide 7.0 (latest) ↗1.02 Perform installation process
Official manual: FortiEDR—Installation and Administration Guide 7.0 (latest) ↗1.03 Perform FortiEDR inventory and use system tools
Official manual: FortiEDR—Installation and Administration Guide 7.0 (latest) ↗1.04 Deploy FortiEDR multi-tenancy
Official manual: FortiEDR—Installation and Administration Guide 7.0 (latest) ↗1.05 Use API to carry out FortiEDR management functions
Official manual: FortiEDR—Installation and Administration Guide 7.0 (latest) ↗
FortiEDR security settings and policies
2.01 Configure communication control policy
On this site: FortiEDR Policies, Communication Control, and PlaybooksOfficial manual: FortiEDR—Installation and Administration Guide 7.0 (latest) ↗2.02 Configure security policies
Official manual: FortiEDR—Installation and Administration Guide 7.0 (latest) ↗2.03 Configure playbooks
On this site: FortiEDR Policies, Communication Control, and PlaybooksOfficial manual: FortiEDR—Installation and Administration Guide 7.0 (latest) ↗2.04 Explain Fortinet Cloud Service (FCS)
Official manual: FortiEDR—Installation and Administration Guide 7.0 (latest) ↗
Events, forensics, and threat hunting
3.01 Analyze security events and alerts
Official manual: FortiEDR—Installation and Administration Guide 7.0 (latest) ↗3.02 Configure threat hunting profiles and scheduled queries
Official manual: FortiEDR—Installation and Administration Guide 7.0 (latest) ↗3.03 Analyze threat hunting data
Official manual: FortiEDR—Installation and Administration Guide 7.0 (latest) ↗3.04 Investigate security events using forensics analysis
Official manual: FortiEDR—Installation and Administration Guide 7.0 (latest) ↗
FortiEDR integration
4.01 Deploy FortiXDR
Official manual: FortiEDR—Installation and Administration Guide 7.0 (latest) ↗4.02 Configure security fabric using FortiEDR
Official manual: FortiEDR—Installation and Administration Guide 7.0 (latest) ↗
FortiEDR troubleshooting
5.01 Perform FortiEDR troubleshooting
Official manual: FortiEDR—Installation and Administration Guide 7.0 (latest) ↗5.02 Perform alert analysis on FortiEDR security events and logs
Official manual: FortiEDR—Installation and Administration Guide 7.0 (latest) ↗
Public sources, used in good faith
These guides are independent study aids built from publicly available material: published exam blueprints, official product documentation, and vendor training catalogues. Product names, exam codes, and trademarks belong to their owners and are used only to identify the subject being taught. This site is not affiliated with or endorsed by any vendor named here. If you hold rights in material published on this page and believe it should be removed or corrected, please send the exact URL and a short note on the issue through the contact page; requests are reviewed promptly and in good faith. Read the full disclaimer →