Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Fortinet Fortinet Certified Professional Security Operations NSE7_SOC_AR-7.6 Questions and answers with CertsForce

Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions
Questions # 1:

Which three statements accurately describe step utilities in a playbook step? (Choose three answers)

Options:

A.

The Timeout step utility sets a maximum execution time for the step and terminates playbook execution if exceeded.


B.

The Loop step utility can only be used once in each playbook step.


C.

The Variables step utility stores the output of the step directly in the step itself.


D.

The Condition step utility behavior changes depending on if a loop exists for that step.


E.

The Mock Output step utility uses HTML format to simulate real outputs.


Expert Solution
Questions # 2:

Refer to the exhibit.

Question # 2

You created a new playbook and executed it as a test. However, it failed to run. You want to investigate, but you do not see details about the error. What is the reason for the lack of details?

Options:

A.

The connector is deactivated.


B.

The playbook logging level must be debug.


C.

The Ignore Error option is enabled.


D.

The user that executed the playbook does not have the necessary permissions.


Expert Solution
Questions # 3:

Which two phases are part of the FortiSOAR incident handling process but are not phases in the NIST 800-61 Revision 2 model? Choose two answers.

Options:

A.

Preparation


B.

Confirmation


C.

Detection


D.

Identification


Expert Solution
Questions # 4:

Review the incident report. Shortly after being compromised, an infected host collected its own network configuration and connection details, then began sending low-volume connection attempts to multiple internal addresses to identify responding hosts. Which two MITRE ATT & CK techniques best describe this activity? Choose two answers.

Options:

A.

System Network Connections Discovery


B.

Network Sniffing


C.

Lateral Movement


D.

Active Scanning


Expert Solution
Questions # 5:

Refer to the exhibit. What is the correct Jinja expression to filter the results to show only the MD5 hash values?

{{ [slot 1] | [slot 2] [slot 3].[slot 4] }}

Select the Jinja expression in the left column, hold and drag it to a blank position on the right. Place the four correct steps in order, placing the first step in the first slot.

Question # 5


Expert Solution
Questions # 6:

Refer to Exhibit:

A SOC analyst is designing a playbook to filter for a high severity event and attach the event information to an incident.

Which local connector action must the analyst use in this scenario?

Options:

A.

Get Events


B.

Update Incident


C.

Update Asset and Identity


D.

Attach Data to Incident


Expert Solution
Questions # 7:

Refer to the exhibits.

What can you conclude from analyzing the data using the threat hunting module?

Options:

A.

Spearphishing is being used to elicit sensitive information.


B.

DNS tunneling is being used to extract confidential data from the local network.


C.

Reconnaissance is being used to gather victim identity information from the mail server.


D.

FTP is being used as command-and-control (C & C) technique to mine for data.


Expert Solution
Questions # 8:

Refer to the Exhibit:

An analyst wants to create an incident and generate a report whenever FortiAnalyzer generates a malicious attachment event based on FortiSandbox analysis. The endpoint hosts are protected by FortiClient EMS integrated with FortiSandbox. All devices are logging to FortiAnalyzer.

Which connector must the analyst use in this playbook?

Options:

A.

FortiSandbox connector


B.

FortiClient EMS connector


C.

FortiMail connector


D.

Local connector


Expert Solution
Questions # 9:

According to the National Institute of Standards and Technology (NIST) cybersecurity framework, incident handling activities can be divided into phases.

In which incident handling phase do you quarantine a compromised host in order to prevent an adversary from using it as a stepping stone to the next phase of an attack?

Options:

A.

Containment


B.

Analysis


C.

Eradication


D.

Recovery


Expert Solution
Questions # 10:

An analyst prioritizes blocking IP addresses and domains from every phishing campaign. Based on the Pyramid of Pain model, which two statements accurately describe this approach? Choose two answers.

Options:

A.

It helps identify strategic weaknesses in adversary infrastructure.


B.

It imposes a high operational cost on adversaries when their attacks are detected.


C.

It focuses on observable network indicators rather than underlying attack methods.


D.

It relies on blocking indicators that adversaries can easily replace or rotate.


Expert Solution
Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions