Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Fortinet NSE7_SOC_AR-7.6 - Fortinet NSE 7 - Security Operations 7.6 Architect

Page: 1 / 3
Total 91 questions

Review the incident report. Shortly after being compromised, an infected host collected its own network configuration and connection details, then began sending low-volume connection attempts to multiple internal addresses to identify responding hosts. Which two MITRE ATT & CK techniques best describe this activity? Choose two answers.

A.

System Network Connections Discovery

B.

Network Sniffing

C.

Lateral Movement

D.

Active Scanning

You want to trigger an incident when multiple failed logins from the same host are followed by a successful login on that same host within 15 minutes. The rule must correlate all events by source IP address and user to ensure they belong to the same login sequence. Which three configurations achieve this goal? Choose three answers.

A.

Ensure both subpatterns have the same aggregate condition.

B.

Define a time window condition for each subpattern.

C.

Configure two subpatterns—one for failed logins and one for the successful login.

D.

Apply sequential logic using a FOLLOWED_BY operator between the subpatterns.

E.

Define the subpattern relationships and constraints.

You are using FortiSIEM analytics to reference the configuration management database (CMDB) event type categories with the following requirements:

    Attribute: Event Type

    Value: Group: Logon Success

Which operator must you use for the analytics search? Choose one answer.

A.

CONTAIN

B.

IN

C.

HAS

D.

IS

Which two playbook triggers enable the use of trigger events in later tasks as trigger variables? (Choose two.)

A.

EVENT

B.

INCIDENT

C.

ON SCHEDULE

D.

ON DEMAND

Using the default data ingestion wizard in FortiSOAR, place the incident handling workflow from FortiSIEM to FortiSOAR in the correct sequence. Select each workflow component in the left column, hold and drag it to a blank position in the column on the right. Place the four correct workflow components in order, placing the first step in the first position at the top of the column.

Refer to the Exhibit:

An analyst wants to create an incident and generate a report whenever FortiAnalyzer generates a malicious attachment event based on FortiSandbox analysis. The endpoint hosts are protected by FortiClient EMS integrated with FortiSandbox. All devices are logging to FortiAnalyzer.

Which connector must the analyst use in this playbook?

A.

FortiSandbox connector

B.

FortiClient EMS connector

C.

FortiMail connector

D.

Local connector

Refer to the exhibits.

You have a playbook that, depending on whether an analyst deems the alert to be a true positive, could reference a child playbook. You need to pass variables from the parent playbook to the child playbook.

Place the steps needed to accomplish this in the correct order.

Which two best practices should be followed when exporting playbooks in FortiAnalyzer? (Choose two answers)

A.

Disable playbooks before exporting them.

B.

Include the associated connector settings.

C.

Move playbooks between ADOMs rather than exporting playbooks and re-importing them.

D.

Ensure the exported playbook’s names do not exist in the target ADOM.

Refer to the exhibit.

A compromised PC establishes an SSH connection to an engineering build server, which then relays HTTPS traffic to reach servers that would otherwise have blocked access from the LAN. Which technique is used for this attack?

A.

Port knocking

B.

Exfiltration over C2 channel

C.

Man-in-the-middle (MITM)

D.

Protocol tunneling

Refer to the exhibit,

which shows the partial output of the MITRE ATT & CK Enterprise matrix on FortiAnalyzer.

Which two statements are true? (Choose two.)

A.

There are four techniques that fall under tactic T1071.

B.

There are four subtechniques that fall under technique T1071.

C.

There are event handlers that cover tactic T1071.

D.

There are 15 events associated with the tactic.