nerdexam
Fortinet

NSE7_SOC_AR-7.6 · Question #16

Refer to Exhibit. A SOC analyst is creating the Malicious File Detected playbook to run when FortiAnalyzer generates a malicious file event. The playbook must also update the incident with the…

The correct answer is D. A local connector with the action Update Incident. After you retrieve the malicious‑file event via Get Events, the correct way to append that event payload into the newly created incident is to use the Attach Data to Incident action on the Local

FortiAnalyzer for SOC

Question

Refer to Exhibit. A SOC analyst is creating the Malicious File Detected playbook to run when FortiAnalyzer generates a malicious file event. The playbook must also update the incident with the malicious file event data. What must the next task in this playbook be?

Exhibit

NSE7_SOC_AR-7.6 question #16 exhibit

Options

  • AA local connector with the action Update Asset and Identity
  • BA local connector with the action Attach Data to Incident
  • CA local connector with the action Run Report
  • DA local connector with the action Update Incident

How the community answered

(63 responses)
  • A
    8% (5)
  • B
    3% (2)
  • C
    13% (8)
  • D
    76% (48)

Explanation

After you retrieve the malicious‑file event via Get Events, the correct way to append that event payload into the newly created incident is to use the Attach Data to Incident action on the Local

Topics

#playbook task#Update Incident#local connector#malicious file event

Community Discussion

No community discussion yet for this question.

Full NSE7_SOC_AR-7.6 Practice