NSE7_SOC_AR-7.6 · Question #16
Refer to Exhibit. A SOC analyst is creating the Malicious File Detected playbook to run when FortiAnalyzer generates a malicious file event. The playbook must also update the incident with the…
The correct answer is D. A local connector with the action Update Incident. After you retrieve the malicious‑file event via Get Events, the correct way to append that event payload into the newly created incident is to use the Attach Data to Incident action on the Local
Question
Refer to Exhibit. A SOC analyst is creating the Malicious File Detected playbook to run when FortiAnalyzer generates a malicious file event. The playbook must also update the incident with the malicious file event data. What must the next task in this playbook be?
Exhibit
Options
- AA local connector with the action Update Asset and Identity
- BA local connector with the action Attach Data to Incident
- CA local connector with the action Run Report
- DA local connector with the action Update Incident
How the community answered
(63 responses)- A8% (5)
- B3% (2)
- C13% (8)
- D76% (48)
Explanation
After you retrieve the malicious‑file event via Get Events, the correct way to append that event payload into the newly created incident is to use the Attach Data to Incident action on the Local
Topics
Community Discussion
No community discussion yet for this question.
