Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the Fortinet Certified Professional Security Operations NSE7_SOC_AR-7.6 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam NSE7_SOC_AR-7.6 Premium Access

View all detail and faqs for the NSE7_SOC_AR-7.6 exam


504 Students Passed

97% Average Score

91% Same Questions
Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions
Questions # 21:

Review the incident report. A fake HR login page was sent to several employees through email. The page copied the company’s branding and captured usernames and passwords. The attacker later used the stolen credentials to sign in through the company’s web VPN. Which two MITRE ATT & CK tactics best characterize this report? Choose two answers.

Options:

A.

Initial Access

B.

Command and Control

C.

Credential Access

D.

Defense Evasion

Questions # 22:

Refer to the exhibits.

You configured a spearphishing event handler and the associated rule. However. FortiAnalyzer did not generate an event.

When you check the FortiAnalyzer log viewer, you confirm that FortiSandbox forwarded the appropriate logs, as shown in the raw log exhibit.

What configuration must you change on FortiAnalyzer in order for FortiAnalyzer to generate an event?

Options:

A.

In the Log Type field, change the selection to AntiVirus Log(malware).

B.

Configure a FortiSandbox data selector and add it tothe event handler.

C.

In the Log Filter by Text field, type the value: .5 ub t ype ma Iwa re..

D.

Change trigger condition by selecting. Within a group, the log field Malware Kame (mname > has 2 or more unique values.

Questions # 23:

Which three end user logs does FortiAnalyzer use to identify possible IOC compromised hosts? (Choose three.)

Options:

A.

Email filter logs

B.

DNS filter logs

C.

Application filter logs

D.

IPS logs

E.

Web filter logs

Questions # 24:

Refer to Exhibit:

You are tasked with reviewing a new FortiAnalyzer deployment in a network with multiple registered logging devices. There is only one FortiAnalyzer in the topology.

Which potential problem do you observe?

Options:

A.

The disk space allocated is insufficient.

B.

The analytics-to-archive ratio is misconfigured.

C.

The analytics retention period is too long.

D.

The archive retention period is too long.

Questions # 25:

Refer to the exhibit.

Question # 25

You are trying to find traffic flows to destinations that are in Europe or Asia, for hosts in the local LAN segment. However, the query returns no results. Assume these logs exist on FortiSIEM.

Which three mistakes can you see in the query shown in the exhibit? (Choose three answers)

Options:

A.

The null value cannot be used with the IS NOT operator.

B.

The time range must be Absolute for queries that use configuration management database (CMDB) groups.

C.

There are missing parentheses between the first row (Group: Europe) and the second row (Group: Asia).

D.

The Source IP row operator must be BETWEEN 10.0.0.0, 10.200.200.254.

E.

The logical operator for the first row (Group: Europe) must be OR.

Questions # 26:

Refer to Exhibit:

A SOC analyst is creating the Malicious File Detected playbook to run when FortiAnalyzer generates a malicious file event. The playbook must also update the incident with the malicious file event data.

What must the next task in this playbook be?

Options:

A.

A local connector with the action Update Asset and Identity

B.

A local connector with the action Attach Data to Incident

C.

A local connector with the action Run Report

D.

A local connector with the action Update Incident

Questions # 27:

Refer to the exhibit.

Question # 27

You created a threat hunting playbook to perform a search query using the FortiSIEM connector. However, when you run the playbook, you do not see any output. Which step must you take first in your troubleshooting process?

Options:

A.

Confirm that the event logs matching your criteria exist on FortiSIEM.

B.

Configure a Set Variable step to save the output.

C.

Confirm that the FortiSIEM connector is up.

D.

Check the documentation for the input and output for the action.

Questions # 28:

Refer to this partial incident output:

Condition: if this pattern occurs within any 1800-second time window.

Host Interface Name: Red Hat VirtIO Ethernet Adapter

Recv Packet Errors: 0

Sent Packet Errors: 0

Recv Packet Discards: 37

Sent Packet Discards: 0

Recv Packet Error Pct: 0.00

Sent Packet Error Pct: 0.00

Recv Packet Discard Pct: 7.17

Sent Packet Discard Pct: 0.00

Avg Recv Interface Error: 0.00

Avg Sent Interface Error: 0.00

Avg Recv Interface Discard: 16.45

Avg Sent Interface Discard: 0.00

Which conclusion can you make about this incident? Choose one answer.

Options:

A.

It was triggered by a baseline profile incident rule.

B.

It was triggered from a FortiAI machine learning rule.

C.

It was triggered by a correlation rule.

D.

It was triggered by a lookup table.

Questions # 29:

You are designing a FortiSOAR hybrid multi-tenant deployment. The architecture must support remote tenant execution and automation inside segmented networks. Which three elements are true for this design? Choose three answers.

Options:

A.

The secure message exchange must be a dedicated instance instead of an embedded one.

B.

The FortiSOAR master cluster can host shared tenants, with strict data isolation between them.

C.

Each tenant or agent has a dedicated, access-controlled space on a secure message exchange for message routing.

D.

FortiSOAR tenant nodes or agents use TCP port 5671 to communicate with the secure message exchange.

E.

FortiSOAR agents are deployed on the master cluster to improve high availability (HA) performance.

Questions # 30:

Refer to the exhibit.

Question # 30

You configured a playbook named False Positive Close , and want to run it to verify if it works. However, when you click Execute and search for the playbook, you do not see it listed. Which two reasons could be the cause of the problem? (Choose two answers)

Options:

A.

The playbook must first be published using the Application Editor.

B.

Another instance of the playbook is currently executing.

C.

The Alerts module is not among the list of modules the playbook can execute on.

D.

The manual trigger is configured to require record input to run.

Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.