Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Fortinet Fortinet Certified Professional Security Operations NSE7_SOC_AR-7.6 Questions and answers with CertsForce

Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions
Questions # 21:

Refer to the exhibits.

Question # 21

How is the investigation and remediation output generated on FortiSIEM? (Choose one answer)

Options:

A.

By exporting an incident


B.

By running an incident report


C.

By using FortiAI to summarize the incident


D.

By viewing the Context tab of an incident


Expert Solution
Questions # 22:

Review the incident report:

Packet captures show a host maintaining periodic TLS sessions that imitate normal HTTPS traffic but run on TCP 8443 to a single external host. An analyst flags the traffic as potential command-and-control. During the same period, the host issues frequent DNS queries with oversized TXT payloads to an attacker-controlled domain, transferring staged files.

Which two MITRE ATT & CK techniques best describe this activity? (Choose two answers)

Options:

A.

Non-Standard Port


B.

Exploitation of Remote Services


C.

Exfiltration Over Alternative Protocol


D.

Hide Artifacts


Expert Solution
Questions # 23:

Which role does a threat hunter play within a SOC?

Options:

A.

investigate and respond to a reported security incident


B.

Collect evidence and determine the impact of a suspected attack


C.

Search for hidden threats inside a network which may have eluded detection


D.

Monitor network logs to identify anomalous behavior


Expert Solution
Questions # 24:

Which two types of variables can you use in playbook tasks? (Choose two.)

Options:

A.

input


B.

Output


C.

Create


D.

Trigger


Expert Solution
Questions # 25:

Refer to the exhibit.

Which two options describe how the Update Asset and Identity Database playbook is configured? (Choose two.)

Options:

A.

The playbook is using a local connector.


B.

The playbook is using a FortiMail connector.


C.

The playbook is using an on-demand trigger.


D.

The playbook is using a FortiClient EMS connector.


Expert Solution
Questions # 26:

While monitoring your network, you discover that one FortiGate device is sending significantly more logs to FortiAnalyzer than all of the other FortiGate devices in the topology.

Additionally, the ADOM that the FortiGate devices are registered to consistently exceeds its quota.

What are two possible solutions? (Choose two.)

Options:

A.

Increase the storage space quota for the first FortiGate device.


B.

Create a separate ADOM for the first FortiGate device and configure a different set of storage policies.


C.

Reconfigure the first FortiGate device to reduce the number of logs it forwards to FortiAnalyzer.


D.

Configure data selectors to filter the data sent by the first FortiGate device.


Expert Solution
Questions # 27:

Your company is doing a security audit To pass the audit, you must take an inventory of all software and applications running on all Windows devices

Which FortiAnalyzer connector must you use?

Options:

A.

FortiClient EMS


B.

ServiceNow


C.

FortiCASB


D.

Local Host


Expert Solution
Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions