Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Fortinet NSE7_SOC_AR-7.6 - Fortinet NSE 7 - Security Operations 7.6 Architect

Page: 3 / 3
Total 91 questions

When configuring an Ingest Bulk Feed playbook step, which two restrictions must you consider? Choose two answers.

A.

It cannot use step output from a connector action.

B.

It is slower than the Create Record step.

C.

It will not trigger On Create triggers.

D.

It will not trigger On Update triggers.

Refer to the exhibit.

You created a threat hunting playbook to perform a search query using the FortiSIEM connector. However, when you run the playbook, you do not see any output. Which step must you take first in your troubleshooting process?

A.

Confirm that the event logs matching your criteria exist on FortiSIEM.

B.

Configure a Set Variable step to save the output.

C.

Confirm that the FortiSIEM connector is up.

D.

Check the documentation for the input and output for the action.

You suspect your organization has been a victim of numerous incidents carried out by the same threat actor. Which option allows you to group the incidents and track them? Choose one answer.

A.

Add a common tag to correlate them.

B.

Mark one incident as the parent and run a playbook to close the child incidents.

C.

Select those incidents and use the Merge function.

D.

Create a campaign and link related records to it.

Refer to the exhibit.

You want to configure a FortiSIEM rule that triggers when a FortiMail device reports at least 100 recipient verification failures for different email accounts in the domain acmecorp.net . What would you add or modify to accomplish this task? Choose one answer.

A.

Change the aggregate to COUNT(Distinct Mail Receiver) > = 100 .

B.

Add a filter for Mail Receiver > = 100 .

C.

Change the status attribute filter from Status CONTAIN FAIL to Status CUSTOM EXPRESSION FAIL > = 100 .

D.

Add a filter for Mail Receiver CONTAIN acmecorp.net .

Which of the following are critical when analyzing and managing events and incidents in a SOC? (Choose two answers)

A.

Accurate detection of threats

B.

Immediate escalation for all alerts

C.

Rapid identification of false positives

D.

Periodic system downtime for maintenance

Refer to Exhibit:

A SOC analyst is creating the Malicious File Detected playbook to run when FortiAnalyzer generates a malicious file event. The playbook must also update the incident with the malicious file event data.

What must the next task in this playbook be?

A.

A local connector with the action Update Asset and Identity

B.

A local connector with the action Attach Data to Incident

C.

A local connector with the action Run Report

D.

A local connector with the action Update Incident

Which two statements about the FortiAnalyzer Fabric topology are true? (Choose two.)

A.

Downstream collectors can forward logs to Fabric members.

B.

Logging devices must be registered to the supervisor.

C.

The supervisor uses an API to store logs, incidents, and events locally.

D.

Fabric members must be in analyzer mode.