Weekend Sale - Special 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 75onlydt

NSE7_SOC_AR-7.6 Questions and Answers

Question # 6

Review the incident report:

An attacker identified employee names, roles, and email patterns from public press releases, which were then used to craft tailored emails.

The emails were directed to recipients to review an attached agenda using a link hosted off the corporate domain.

Which two MITRE ATT & CK tactics best fit this report? (Choose two answers)

A.

Reconnaissance

B.

Discovery

C.

Initial Access

D.

Defense Evasion

Full Access
Question # 7

Refer to Exhibit:

You are tasked with reviewing a new FortiAnalyzer deployment in a network with multiple registered logging devices. There is only one FortiAnalyzer in the topology.

Which potential problem do you observe?

A.

The disk space allocated is insufficient.

B.

The analytics-to-archive ratio is misconfigured.

C.

The analytics retention period is too long.

D.

The archive retention period is too long.

Full Access
Question # 8

Refer to the exhibit.

Question # 8

You created a threat hunting playbook to perform a search query using the FortiSIEM connector. However, when you run the playbook, you do not see any output. Which step must you take first in your troubleshooting process?

A.

Confirm that the event logs matching your criteria exist on FortiSIEM.

B.

Configure a Set Variable step to save the output.

C.

Confirm that the FortiSIEM connector is up.

D.

Check the documentation for the input and output for the action.

Full Access
Question # 9

Refer to the exhibits.

You configured a spearphishing event handler and the associated rule. However. FortiAnalyzer did not generate an event.

When you check the FortiAnalyzer log viewer, you confirm that FortiSandbox forwarded the appropriate logs, as shown in the raw log exhibit.

What configuration must you change on FortiAnalyzer in order for FortiAnalyzer to generate an event?

A.

In the Log Type field, change the selection to AntiVirus Log(malware).

B.

Configure a FortiSandbox data selector and add it tothe event handler.

C.

In the Log Filter by Text field, type the value: .5 ub t ype ma Iwa re..

D.

Change trigger condition by selecting. Within a group, the log field Malware Kame (mname > has 2 or more unique values.

Full Access
Question # 10

Refer to the exhibit. What is the correct Jinja expression to filter the results to show only the MD5 hash values?

{{ [slot 1] | [slot 2] [slot 3].[slot 4] }}

Select the Jinja expression in the left column, hold and drag it to a blank position on the right. Place the four correct steps in order, placing the first step in the first slot.

Question # 10

Full Access
Question # 11

Which two playbook triggers enable the use of trigger events in later tasks as trigger variables? (Choose two.)

A.

EVENT

B.

INCIDENT

C.

ON SCHEDULE

D.

ON DEMAND

Full Access
Question # 12

Refer to the exhibits.

The FortiMail Sender Blocklist playbook is configured to take manual input and add those entries to the FortiMail abc. com domain-level block list. The playbook is configured to use a FortiMail connector and the ADD_SENDER_TO_BLOCKLIST action.

Why is the FortiMail Sender Blocklist playbook execution failing7

A.

You must use the GET_EMAIL_STATISTICS action first to gather information about email messages.

B.

FortiMail is expecting a fully qualified domain name (FQDN).

C.

The client-side browser does not trust the FortiAnalzyer self-signed certificate.

D.

The connector credentials are incorrect

Full Access
Question # 13

Which three statements accurately describe step utilities in a playbook step? (Choose three answers)

A.

The Timeout step utility sets a maximum execution time for the step and terminates playbook execution if exceeded.

B.

The Loop step utility can only be used once in each playbook step.

C.

The Variables step utility stores the output of the step directly in the step itself.

D.

The Condition step utility behavior changes depending on if a loop exists for that step.

E.

The Mock Output step utility uses HTML format to simulate real outputs.

Full Access
Question # 14

You are designing a FortiSOAR hybrid multi-tenant deployment. The architecture must support remote tenant execution and automation inside segmented networks. Which three elements are true for this design? Choose three answers.

A.

The secure message exchange must be a dedicated instance instead of an embedded one.

B.

The FortiSOAR master cluster can host shared tenants, with strict data isolation between them.

C.

Each tenant or agent has a dedicated, access-controlled space on a secure message exchange for message routing.

D.

FortiSOAR tenant nodes or agents use TCP port 5671 to communicate with the secure message exchange.

E.

FortiSOAR agents are deployed on the master cluster to improve high availability (HA) performance.

Full Access
Question # 15

Which two statements accurately describe the process to create a new rule from a search using FortiSIEM analytics? Choose two answers.

A.

Raw event logs cannot be used for incident rule creation.

B.

The incident action is automatically configured based on the event type.

C.

All search filter rows are added into a single subpattern.

D.

The default aggregate condition will always be COUNT(Matched Events) > = 1 .

Full Access
Question # 16

Which two statements accurately describe the Custom API Endpoint playbook trigger? Choose two answers.

A.

It supports token-based, basic, and no authentication.

B.

One custom API endpoint can trigger multiple playbooks at the same time.

C.

It supports HTTP POST, GET, and PUT methods.

D.

An external system can initiate a playbook using an arbitrary endpoint on FortiSOAR.

Full Access
Question # 17

Refer to the exhibit.

Question # 17

How do you add a piece of evidence to the Action Logs Marked As Evidence area? (Choose one answer)

A.

By tagging output or a workspace comment with the keyword Evidence

B.

By linking an indicator to the war room

C.

By creating an evidence collection task and attaching a file

D.

By executing a playbook with the Save Execution Logs option enabled

Full Access
Question # 18

Refer to the exhibits.

Question # 18

You have a playbook that, depending on whether an analyst deems the alert to be a true positive, could reference a child playbook. You need to pass variables from the parent playbook to the child playbook.

Place the steps needed to accomplish this in the correct order.

Question # 18

Full Access
Question # 19

Exhibit:

Which observation about this FortiAnalyzer Fabric deployment architecture is true?

A.

The AMER HQ SOC team cannot run automation playbooks from the Fabric supervisor.

B.

The AMER HQ SOC team must configure high availability (HA) for the supervisor node.

C.

The EMEA SOC team has access to historical logs only.

D.

The APAC SOC team has access to FortiView and other reporting functions.

Full Access
Question # 20

Review the incident report. A fake HR login page was sent to several employees through email. The page copied the company’s branding and captured usernames and passwords. The attacker later used the stolen credentials to sign in through the company’s web VPN. Which two MITRE ATT & CK tactics best characterize this report? Choose two answers.

A.

Initial Access

B.

Command and Control

C.

Credential Access

D.

Defense Evasion

Full Access
Question # 21

Which three end user logs does FortiAnalyzer use to identify possible IOC compromised hosts? (Choose three.)

A.

Email filter logs

B.

DNS filter logs

C.

Application filter logs

D.

IPS logs

E.

Web filter logs

Full Access
Question # 22

Refer to the exhibit.

Question # 22

You are trying to find traffic flows to destinations that are in Europe or Asia, for hosts in the local LAN segment. However, the query returns no results. Assume these logs exist on FortiSIEM.

Which three mistakes can you see in the query shown in the exhibit? (Choose three answers)

A.

The null value cannot be used with the IS NOT operator.

B.

The time range must be Absolute for queries that use configuration management database (CMDB) groups.

C.

There are missing parentheses between the first row (Group: Europe) and the second row (Group: Asia).

D.

The Source IP row operator must be BETWEEN 10.0.0.0, 10.200.200.254.

E.

The logical operator for the first row (Group: Europe) must be OR.

Full Access
Question # 23

Refer to the exhibit,

which shows the partial output of the MITRE ATT & CK Enterprise matrix on FortiAnalyzer.

Which two statements are true? (Choose two.)

A.

There are four techniques that fall under tactic T1071.

B.

There are four subtechniques that fall under technique T1071.

C.

There are event handlers that cover tactic T1071.

D.

There are 15 events associated with the tactic.

Full Access
Question # 24

You want to automate a workflow on FortiSOAR so that whenever an incident is moved to the Aftermath phase, it is automatically set to status Resolved and assigned to a purple team specialist as incident lead to write an incident report. In addition, a manual task, assigned to the same specialist, will be created so they are aware of the pending work. Which three steps will accomplish this task? Choose three answers.

A.

Create a Find Record step to find matching incidents.

B.

Create a Condition step to assign both the incident and task to the specialist.

C.

Create a Manual Task step to assign the task to the specialist.

D.

Create an Update Record step to set the incident lead.

E.

Create an On Update trigger with a trigger condition that matches the Aftermath phase.

Full Access
Question # 25

You are using FortiSIEM analytics to reference the configuration management database (CMDB) event type categories with the following requirements:

    Attribute: Event Type

    Value: Group: Logon Success

Which operator must you use for the analytics search? Choose one answer.

A.

CONTAIN

B.

IN

C.

HAS

D.

IS

Full Access
Question # 26

A partner organization recently suffered a distributed denial-of-service (DDoS) attack, but the adversary’s identity and TTPs remain unknown. Your SOC has not received any relevant threat intelligence from the partner organization, but you are asked to determine whether similar activity could be happening in your environment. Which threat hunting action should you perform first? Choose one answer.

A.

Configure SIEM rules to alert when inbound traffic exceeds baseline thresholds.

B.

Use a packet analyzer to capture and review all traffic flows on critical devices.

C.

Develop a hunting hypothesis based on how DDoS can be executed against your network.

D.

Use threat intelligence to enrich the IP addresses of all external source IP addresses.

Full Access
Question # 27

A very long FortiSOAR playbook failed at step 30 because of an intermittent networking issue, which has now been resolved. You want to finish executing the playbook without repeating earlier steps or losing prior context. Which action should you take? Choose one answer.

A.

Use mock input for step 30 and re-run the playbook.

B.

Use the Load ENV JSON option in the Jinja Editor and then render the output.

C.

Use the Rerun From Last Failed Step option from the executed playbook logs.

D.

Add a connector from the trigger to step 30 directly and re-run the playbook.

Full Access