Pass the Fortinet Fortinet Certified Solution Specialist FCSS_SOC_AN-7.4 Questions and answers with CertsForce

Viewing page 1 out of 1 pages
Viewing questions 1-10 out of questions
Questions # 1:

Refer to Exhibit:

Question # 1

You are tasked with reviewing a new FortiAnalyzer deployment in a network with multiple registered logging devices. There is only one FortiAnalyzer in the topology.

Which potential problem do you observe?

Options:

A.

The disk space allocated is insufficient.


B.

The analytics-to-archive ratio is misconfigured.


C.

The analytics retention period is too long.


D.

The archive retention period is too long.


Expert Solution
Questions # 2:

According to the National Institute of Standards and Technology (NIST) cybersecurity framework, incident handling activities can be divided into phases.

In which incident handling phase do you quarantine a compromised host in order to prevent an adversary from using it as a stepping stone to the next phase of an attack?

Options:

A.

Containment


B.

Analysis


C.

Eradication


D.

Recovery


Expert Solution
Questions # 3:

Refer to the exhibit,

Question # 3

which shows the partial output of the MITRE ATT&CK Enterprise matrix on FortiAnalyzer.

Which two statements are true? (Choose two.)

Options:

A.

There are four techniques that fall under tactic T1071.


B.

There are four subtechniques that fall under technique T1071.


C.

There are event handlers that cover tactic T1071.


D.

There are 15 events associated with the tactic.


Expert Solution
Questions # 4:

Refer to the Exhibit:

Question # 4

An analyst wants to create an incident and generate a report whenever FortiAnalyzer generates a malicious attachment event based on FortiSandbox analysis. The endpoint hosts are protected by FortiClient EMS integrated with FortiSandbox. All devices are logging to FortiAnalyzer.

Which connector must the analyst use in this playbook?

Options:

A.

FortiSandbox connector


B.

FortiClient EMS connector


C.

FortiMail connector


D.

Local connector


Expert Solution
Questions # 5:

A customer wants FortiAnalyzer to run an automation stitch that executes a CLI command on FortiGate to block a predefined list of URLs, if a botnet command-and-control (C&C) server IP is detected.

Which FortiAnalyzer feature must you use to start this automation process?

Options:

A.

Playbook


B.

Data selector


C.

Event handler


D.

Connector


Expert Solution
Questions # 6:

Refer to Exhibit:

Question # 6

A SOC analyst is creating the Malicious File Detected playbook to run when FortiAnalyzer generates a malicious file event. The playbook must also update the incident with the malicious file event data.

What must the next task in this playbook be?

Options:

A.

A local connector with the action Update Asset and Identity


B.

A local connector with the action Attach Data to Incident


C.

A local connector with the action Run Report


D.

A local connector with the action Update Incident


Expert Solution
Questions # 7:

Refer to the exhibit.

Question # 7

Which two options describe how the Update Asset and Identity Database playbook is configured? (Choose two.)

Options:

A.

The playbook is using a local connector.


B.

The playbook is using a FortiMail connector.


C.

The playbook is using an on-demand trigger.


D.

The playbook is using a FortiClient EMS connector.


Expert Solution
Questions # 8:

When does FortiAnalyzer generate an event?

Options:

A.

When a log matches a filter in a data selector


B.

When a log matches an action in a connector


C.

When a log matches a rule in an event handler


D.

When a log matches a task in a playbook


Expert Solution
Questions # 9:

Refer to the exhibits.

Question # 9

The FortiMail Sender Blocklist playbook is configured to take manual input and add those entries to the FortiMail abc. com domain-level block list. The playbook is configured to use a FortiMail connector and the ADD_SENDER_TO_BLOCKLIST action.

Why is the FortiMail Sender Blocklist playbook execution failing7

Options:

A.

You must use the GET_EMAIL_STATISTICS action first to gather information about email messages.


B.

FortiMail is expecting a fully qualified domain name (FQDN).


C.

The client-side browser does not trust the FortiAnalzyer self-signed certificate.


D.

The connector credentials are incorrect


Expert Solution
Viewing page 1 out of 1 pages
Viewing questions 1-10 out of questions