NSE7_SOC_AR-7.6 Exam Questions
52 real NSE7_SOC_AR-7.6 exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1FortiAnalyzer for SOC
Which statement describes automation stitch integration between FortiGate and FortiAnalyzer?
automation stitchFortiGate-FortiAnalyzer integrationevent handlernotification - Question #2FortiAnalyzer for SOC
Which three end user logs does FortiAnalyzer use to identify possible IOC compromised hosts? (Choose three.)
IOC detectioncompromised hostslog typesthreat intelligence - Question #3SOC Best Practices and Incident Response
Which role does a threat hunter play within a SOC?
SOC rolesthreat huntinganalyst responsibilities - Question #4SOC Best Practices and Incident Response
According to the National Institute of Standards and Technology (NIST) cybersecurity framework, incident handling activities can be divided into phases. In which incident handling...
NIST frameworkincident handling phasescontainmenthost quarantine - Question #5FortiAnalyzer for SOC
Which FortiAnalyzer connector can you use to run automation stitches9
FortiAnalyzer connectorsautomation stitchesFortiOS - Question #6FortiAnalyzer for SOC
Refer to the exhibits. What can you conclude from analyzing the data using the threat hunting module?
threat huntingDNS tunnelingdata exfiltrationMITRE ATT&CK - Question #7FortiAnalyzer for SOC
Refer to the exhibits. You configured a spearphishing event handler and the associated rule. However. FortiAnalyzer did not generate an event. When you check the FortiAnalyzer log...
event handlerFortiSandbox integrationdata selectorspearphishing detection - Question #8FortiAnalyzer for SOC
While monitoring your network, you discover that one FortiGate device is sending significantly more logs to FortiAnalyzer than all of the other FortiGate devices in the topology. A...
log quotaADOM managementlog forwardingstorage configuration - Question #9FortiAnalyzer for SOC
Refer to the Exhibit. An analyst wants to create an incident and generate a report whenever FortiAnalyzer generates a malicious attachment event based on FortiSandbox analysis. The...
playbook connectorFortiSandboxincident creationlocal connector - Question #10FortiAnalyzer for SOC
Your company is doing a security audit. To pass the audit, you must take an inventory of all software and applications running on all Windows devices. Which FortiAnalyzer connector...
FortiClient EMSsoftware inventoryWindows devicesFortiAnalyzer connector - Question #11FortiAnalyzer for SOC
Which two playbook triggers enable the use of trigger events in later tasks as trigger variables? (Choose two.)
playbook triggerstrigger variablesevent triggerincident trigger - Question #12FortiAnalyzer for SOC
Refer to the exhibit. You notice that the custom event handler you configured to detect SMTP reconnaissance activities is creating a large number of events. This is overwhelming yo...
event handler tuningtrigger countfalse positive reductionSMTP reconnaissance - Question #13FortiAnalyzer Deployment and Configuration
When configuring a FortiAnalyzer to act as a collector device, which two steps must you perform? (Choose two.)
collector modelog forwardingFabric authorizationFortiAnalyzer deployment - Question #14FortiAnalyzer for SOC
Refer to the exhibit. You are tasked with reviewing a new FortiAnalyzer deployment in a network with multiple registered logging devices. There is only one FortiAnalyzer in the top...
analytics-archive ratiodata policyFortiAnalyzer deploymentstorage configuration - Question #15FortiAnalyzer for SOC
Refer to the exhibit, which shows the partial output of the MITRE ATT&CK Enterprise matrix on FortiAnalyzer. Which two statements are true? (Choose two.)
MITRE ATT&CKT1071subtechniquesevent handlers - Question #16FortiAnalyzer for SOC
Refer to Exhibit. A SOC analyst is creating the Malicious File Detected playbook to run when FortiAnalyzer generates a malicious file event. The playbook must also update the incid...
playbook taskUpdate Incidentlocal connectormalicious file event - Question #17FortiAnalyzer for SOC
Refer to the exhibits. The DOS attack playbook is configured to create an incident when an event handler generates a denial-of-ser/ice (DoS) attack event. Why did the DOS attack pl...
playbook debuggingtask failuredata type mismatchincident creation - Question #18FortiAnalyzer Deployment and Configuration
Which two statements about the FortiAnalyzer Fabric topology are true? (Choose two.)
Fabric topologycollector modeanalyzer modelog forwarding - Question #19SOC Best Practices and Incident Response
Review the following incident report: The RAT provided the attackers with remote access and a foothold in the compromised system. Which two MITRE ATT&CK tactics does this incident...
MITRE ATT&CK tacticsInitial AccessPersistenceRAT malware - Question #20FortiAnalyzer for SOC
Refer to Exhibit. A SOC analyst is designing a playbook to filter for a high severity event and attach the event information to an incident. Which local connector action must the a...
playbook designAttach Data to Incidentlocal connectorevent filtering - Question #21FortiAnalyzer for SOC
Refer to the exhibit. Which two options describe how the Update Asset and Identity Database playbook is configured? (Choose two.)
playbook connectorslocal connectorFortiClient EMS connectorplaybook triggers - Question #22FortiAnalyzer for SOC
Refer to the exhibits. The Malicious File Detect playbook is configured to create an incident when an event handler generates a malicious file detection event. Why did the Maliciou...
playbook troubleshootingCreate Incident taskplaybook execution failureinput validation - Question #23FortiAnalyzer for SOC
Refer to the exhibit. Assume that all devices in the FortiAnalyzer Fabric are shown in the image. Which two statements about the FortiAnalyzer Fabric deployment are true? (Choose t...
FortiAnalyzer Fabricsupervisor nodeADOMsSecurity Fabric - Question #24FortiAnalyzer for SOC
Which two types of variables can you use in playbook tasks? (Choose two.)
playbook variablesinput variablesoutput variablesplaybook tasks - Question #25FortiAnalyzer for SOC
Refer to the exhibits. The FortiMail Sender Blocklist playbook is configured to take manual input and add those entries to the FortiMail abc. com domain-level block list. The playb...
playbook connectorsFortiMail connectorconnector credentialsblocklist management - Question #26FortiAnalyzer for SOC
Which two ways can you create an incident on FortiAnalyzer? (Choose two.)
incident creationevent handlersEvent MonitorFortiAnalyzer incidents - Question #27SOC Best Practices and Incident Response
Which statement best describes the MITRE ATT&CK framework?
MITRE ATT&CKtacticstechniquesthreat intelligence - Question #28FortiAnalyzer for SOC
Refer to the exhibits. Which observation about this FortiAnalyzer Fabric deployment architecture is true?
FortiAnalyzer Fabricsupervisor nodeautomation playbooksSOC team access - Question #29FortiAnalyzer for SOC
Which FortiAnalyzer feature uses the SIEM database for advance log analytics and monitoring?
SIEM databasethreat huntinglog analyticsFortiAnalyzer features - Question #30FortiAnalyzer for SOC
Refer to the exhibits. You configured a custom event handler and an associated rule to generate events whenever FortiMail detects spam emails. However, you notice that the event ha...
event handler ruleslog filteringFortiMailspam detection - Question #31FortiAnalyzer for SOC
When does FortiAnalyzer generate an event?
event generationevent handlerslog matchingFortiAnalyzer events - Question #32FortiAnalyzer for SOC
A customer wants FortiAnalyzer to run an automation stitch that executes a CLI command on FortiGate to block a predefined list of URLs, if a botnet command-and-control (C&C) server...
automation stitchevent handlerbotnet C&C detectionFortiGate CLI - Question #33SOC Best Practices and Incident Response
Which National Institute of Standards and Technology (NIST) incident handling phase involves removing malware and persistence mechanisms from a compromised host?
NIST incident handlingeradication phaseincident response phasesmalware removal - Question #34FortiAnalyzer for SOC
You are not able to view any incidents or events on FortiAnalyzer. What is the cause of this issue?
FortiAnalyzer collector modeincident visibilitydeployment modestroubleshooting - Question #35FortiAnalyzer for SOC
Refer to the exhibits. The Quarantine Endpoint by EMS playbook execution failed. What can you conclude from reviewing the playbook tasks and raw logs?
playbook troubleshootingendpoint quarantineFortiClient EMSincident attachment - Question #36Fortinet Security Operations Architecture
You are tasked with configuring automation to quarantine infected endpoints. Which two Fortinet SOC components can work together to fulfill this task? (Choose two.)
endpoint quarantineFortiAnalyzerFortiClient EMSSOC automation - Question #37FortiAnalyzer for SOC
Which two assets are available with the outbreak alert licensed feature on FortiAnalyzer? (Choose two.)
outbreak alertsFortiGuardcustom event handlersoutbreak reports - Question #38FortiAnalyzer for SOC
Which trigger type requires manual input to run a playbook?
playbook triggersON_DEMAND triggermanual inputplaybook execution - Question #39SOC Best Practices and Incident Response
Review the following incident report. Which two MITRE ATT&CK tactics are captured in this report? (Choose two.)
MITRE ATT&CKtacticsReconnaissanceincident analysis - Question #40FortiAnalyzer for SOC
You are managing 10 FortiAnalyzer devices in a FortiAnalyzer Fabric. In this scenario, what is a benefit of configuring a Fabric group?
FortiAnalyzer FabricFabric groupslog search filteringdevice management - Question #41FortiAnalyzer for SOC
Refer to the exhibits. Which connector and action on FortiAnalyzer can you use to add the entries show in the exhibits? Domain List: Domain abc.com:
FortiAnalyzer connectorsFortiMail connectorblocklistdomain list - Question #42FortiAnalyzer for SOC
Which connector on FortiAnalyzer is responsible for looking up indicators to get threat intelligence?
FortiAnalyzer connectorsFortiGuardthreat intelligenceindicator lookup - Question #43SOC Best Practices and Incident Response
Review the incident report. An attacker identified employee names, roles, and email patterns from public press releases, which were then used to craft tailored emails. The emails w...
MITRE ATT&CKreconnaissanceinitial accessspear phishing - Question #44SOC Best Practices and Incident Response
Which three are threat hunting activities? (Choose three answers)
threat huntinghypothesis generationthreat intelligence enrichmentpacket analysis - Question #45FortiSOAR Deployment and Configuration
Refer to the exhibit. How do you add a piece of evidence to the Action Logs Marked As Evidence area? (Choose one answer)
FortiSOAR war roomevidence managementaction logsplaybook output tagging - Question #46FortiSIEM Deployment and Configuration
Refer to the exhibits. Assume that the traffic flows are identical, except for the destination IP address. There is only one FortiGate in network address translation (NAT) mode in...
FortiSIEM incident analysisnetwork reconnaissanceNAT modetraffic flow analysis - Question #47FortiSOAR Deployment and Configuration
When you use a manual trigger to save user input as a variable, what is the correct Jinja expression to reference the variable? (Choose one answer)
FortiSOAR playbooksJinja expressionsmanual triggerplaybook variables - Question #48SOC Best Practices and Incident Response
Based on the Pyramid of Pain model, which two statements accurately describe the value of an indicator and how difficult it is for an adversary to change? (Choose two answers)
Pyramid of Painindicators of compromiseTTPsadversary cost - Question #49FortiSOAR Deployment and Configuration
Refer to the exhibits. You have a playbook that, depending on whether an analyst deems the alert to be a true positive, could reference a child playbook. You need to pass variables...
FortiSOAR playbooksparent-child playbooksparameter passingplaybook chaining - Question #50FortiSIEM Deployment and Configuration
Which three factors does the FortiSIEM rules engine use to determine the count when it evaluates the aggregate condition COUNT (Matched Events) on a specific subpattern? (Choose th...
FortiSIEM rules engineaggregate conditionscorrelation rulesGroup By attributes