NSE 6
FortiNDR Cloud Analyst
Part of NSE 6: Security Operations
Time allowed: 65–75 minutes. Language: English. Product version: FortiNDR Cloud 26.
Independent study aid built from the public exam blueprint. Not affiliated with, authorized by, or endorsed by fortinet. Objectives are transcribed and mapped by hand, so this page may contain mistakes or may have fallen behind the vendor's current material: exam objectives, versions, numbering and availability all change without notice. Treat fortinet's own certification portal as the source of truth and verify against it before you book anything.
Architecture and system settings (15–25% of the exam)
1.01 Explain the FortiNDR Cloud architecture
1.02 Identify the FortiNDR Cloud sensors
Events and queries (25–35% of the exam)
2.01 Explain event types and fields
2.02 Configure IQL query to match security events
Detection (15–25% of the exam)
3.01 Analyze detections and behavioral observations
3.02 Implement detectors
Investigations and integrations (20–30% of the exam)
4.01 Perform investigations to detect threats
4.02 Explain how to integrate FortiNDR Cloud (API/connectors)
4.03 Perform threat hunting activities
Public sources, used in good faith
These guides are independent study aids built from publicly available material: published exam blueprints, official product documentation, and vendor training catalogues. Product names, exam codes, and trademarks belong to their owners and are used only to identify the subject being taught. This site is not affiliated with or endorsed by any vendor named here. If you hold rights in material published on this page and believe it should be removed or corrected, please send the exact URL and a short note on the issue through the contact page; requests are reviewed promptly and in good faith. Read the full disclaimer →