NSE7-SOC-AR-7-6: Fortinet NSE 7 - Security Operati… Practice Exam
QuestionQ1
SOAR Incident Handling and Threat Hunting
Save question
Refer to the exhibit.
You are attempting to find traffic flows to destinations in Europe or Asia for hosts in the local LAN segment. However, the query returns no results. Assume that these logs exist on FortiSIEM.
Which three mistakes are present in the query shown in the exhibit?
Choose three
AThe logical operator for the first row (Group: Europe) must be OR.
BThe null value cannot be used with the IS NOT operator.
CThe time range must be Absolute for queries that use configuration management database (CMDB) groups.
DThe Source IP row operator must be BETWEEN 10.0.0.0, 10.200.200.254.
EThere are missing parentheses between the first row (Group: Europe) and the second row (Group: Asia).
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ2
SOAR Incident Handling and Threat Hunting
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ3
SOAR Playbook Development
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ4
SOC Concepts and Frameworks
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ5
Detection Capabilities
0
Community Discussion
No comments yet. Be the first to start the discussion!
That's the end of the preview
It's free
100% of the questions are free for all users. No strings attached.
Which three of the following are threat-hunting activities?
Choose three
AGenerate a hypothesis.
BTune correlation rules.
CPerform packet analysis.
DAutomate workflows.
EEnrich records with threat intelligence.
When you configure an Ingest Bulk Feed playbook step, which two restrictions must be considered?
Choose two
AIt will not trigger On Create triggers.
BIt is slower than the Create Record step.
CIt will not trigger On Update triggers.
DIt cannot use step output from a connector action.
Based on the Pyramid of Pain model, which two statements correctly describe an indicator’s value and the difficulty an adversary faces in changing it?
Choose two
ATactics, techniques, and procedures are hard because adversaries must adapt their methods.
BTools are easy because often, multiple alternatives exist.
CIP addresses are easy because adversaries can spoof them or move them to new resources.
DArtifacts are easy because adversaries can alter file paths or registry keys.
You are setting up a new FortiSIEM rule to trigger incidents after receiving a specified number of either Fortigate-Traffic-Violation or Fortigate-Traffic-Denied event types. Although a single subpattern could accomplish this, you choose to create two separate subpatterns—one for each event type—and correlate them with the OR operator.
Which two benefits does this method provide?
Choose two
AEach subpattern can use a different group by condition.
BEach subpattern can use a different time window condition.
CEach subpattern can use a different aggregate condition.
DEach subpattern can trigger its own notification policy.
QuestionQ6
SOAR Incident Handling and Threat Hunting
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
SOC Concepts and Frameworks
QuestionQ8
SOAR Incident Handling and Threat Hunting
QuestionQ9
SOAR Playbook Development
QuestionQ10
Detection Capabilities
QuestionQ11
Detection Capabilities
QuestionQ12
SOC Concepts and Frameworks
QuestionQ13
Detection Capabilities
QuestionQ14
SOC Concepts and Frameworks
QuestionQ15
SOAR Incident Handling and Threat Hunting
QuestionQ16
SOAR Playbook Development
QuestionQ17
SOAR Incident Handling and Threat Hunting
QuestionQ18
SOAR Incident Handling and Threat Hunting
QuestionQ19
SOAR Playbook Development
QuestionQ20
SOAR Incident Handling and Threat Hunting
QuestionQ21
SOAR Incident Handling and Threat Hunting
QuestionQ22
SOAR Incident Handling and Threat Hunting
QuestionQ23
SOAR Incident Handling and Threat Hunting
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Refer to the exhibits.
You configured the FortiSIEM connector in FortiSOAR. However, when attempting to save the configuration, you receive the error shown in the exhibit. What are two possible causes?
Choose two
AThe Visibility option must be set to Public.
BFortiSOAR cannot reach FortiSIEM.
CThe organization should be Super.
DThe user credentials do not match FortiSIEM.
Review the incident report below.
A fraudulent HR login page was emailed to several employees. The page replicated the company’s branding and captured usernames and passwords. The attacker subsequently used the stolen credentials to sign in through the company's web VPN portal.
Which two MITRE ATT&CK tactics best characterize this report?
Choose two
ADefense Evasion
BCredential Access
CCommand and Control
DInitial Access
Refer to the exhibit.
You are investigating an open incident and want to add records from the custom Tickets module to the visual correlation widget. Assume that ticket records are already linked to the incident.
How can you accomplish this?
AEdit the incident template and add the Tickets module to the graph.
BDefine move module relationships under Correlation Settings.
CTag ticket records with the incident ID.
DIngest ticket records through a custom connector.
Refer to the exhibit.
A list of FortiSIEM connector actions is displayed. You want to build a FortiSOAR playbook that enables you to do the following:
Manually enter a range of IP addresses.
Use the connector action shown in the exhibit to retrieve, from the FortiSIEM configuration management database (CMDB), a list of devices in that IP-address range.
Create an asset record for each returned result, using the device IP address.
Which combination and sequence of step operations meets these requirements with the fewest necessary playbook steps?
A
Connector action, 2) Create record, 3) Update record
B
On create trigger, 2) Connector action, 3) Code snippet, 4) Create record
C
Manual trigger, 2) Connector action, 3) Create record
D
Manual trigger, 2) Set variable, 3) Connector action, 4) Create record, 5) Update record
You are using FortiSIEM analytics to refer to configuration management database (CMDB) event-type categories with these requirements:
Attribute: Event Type
Value: Group: Logon Success
Which operator must be used for the analytics search?
AIN
BCONTAIN
CIS
DHAS
Refer to the exhibit.
Based on the configuration displayed, which two settings are misconfigured?
Choose two
AThe time window should be lowered from 900 seconds to reduce false positives.
BThe subpattern relationships between FailedLogin and FailedLogin2 should be removed.
CA logical operator is missing in the SuccessLogin subpattern to evaluate the subpattern relationships.
DThe SuccessLogin subpattern is not correlated with any FailedLogin or FailedLogin2 attributes.
Refer to the exhibit.
Which approach most effectively reduces this organization's attack surface?
ARemove unused devices.
BEnable deep inspection on firewall policies.
CForward all firewall logs to the security information and event management (SIEM) system.
DImplement macrosegmentation.
You must create a nested query in FortiSIEM that meets these conditions:
Locate all devices discovered by any FortiSIEM Windows Agent.
From those devices, determine which have generated Windows Login Failure events.
Which two query components should be used for this nested query?
Choose two
AOuter Event Query
BInner CMDB Query
COuter CMDB Query
DInner Event Query
Refer to the exhibit.
A compromised PC creates an SSH connection to an engineering build server, which then relays HTTPS traffic to reach servers whose access from the LAN would otherwise be blocked.
Which technique is used in this attack?
APort knocking
BExfiltration over C2 channel
CMan-in-the-middle (MITM)
DProtocol tunneling
You created a war room and want to execute a connector action to check a domain’s reputation. You then need to save the output for your team to review, but the output is extensive and you want to restrict how much information is attached to the war room.
How can you accomplish this?
AFrom the returned output, select only the output keys you want.
BUse the Investigate tab to map only the fields you want.
CLower the playbook logging level before executing the connector.
DApply a workspace filter to show only relevant fields.
Refer to the exhibits.
A playbook can reference a child playbook depending on whether an analyst considers the alert a true positive. You need to pass variables from the parent playbook to the child playbook.
Place the required steps in the correct sequence.
Drag & Drop
Create a parameter in the child playbook.
Create a parameter in the parent playbook.
Map data to the parameter in the Reference a playbook step in the parent playbook.
Apply the parameter to the Disable User Account connector action.
Create a manual trigger and assign the user to a new variable.
Step 1
Step 2
Step 3
Which two phases belong to the FortiSOAR incident-handling process but are not phases in the NIST 800-61 Revision 2 model?
Choose two
ADetection
BConfirmation
CIdentification
DPreparation
Refer to the exhibits.
You have configured the FortiGate connector on FortiSOAR. You want to permit FortiSOAR (10.200.200.160) to perform actions on FortiGate (172.16.200.1), but the connection attempt fails. Assume the FortiGate connector is configured correctly on the FortiSOAR side.
Which two configurations are required on FortiGate?
Choose two
AHTTPS must be enabled on the FortiGate interface that FortiSOAR will communicate with.
BFortiSOAR IP address must be added under Trusted Hosts.
CThe administrator profile must have System read and write permissions.
DThe FortiGate interface role must be set to Custom API Endpoint.
You configured a new module named Users. Next, you want to set up a playbook that creates users from ingested data.
When new records are created, you want to ensure duplicate users do not overwrite existing user records or their fields. However, you also want the playbook to keep running when duplicates are encountered so that any non-duplicate records are still created.
Which two actions meet these requirements?
Choose two
AEnsure the Users module has record uniqueness conditions configured.
BConfigure the Execution Mode to run in parallel.
CUse the Do not create new record (keep existing intact) option in the Create Record step.
DUse the stop the create process option in the Create Record step.
You want to use the queue and shift management feature to automatically assign newly created low-priority tasks to members of the L1 queue. However, you cannot add the Tasks module to the Module Types list.
What is the issue?
AThe Tasks module is not supported by queue and shift management.
BThe Queueable option is disabled for the Tasks module.
CThere is a higher priority queue for the Tasks module.
DShift-based assignment is disabled.
Refer to the exhibit.
How can you add a piece of evidence to the Action Logs Marked As Evidence area?
ABy creating an evidence collection task and attaching a file
BBy linking an indicator to the war room
CBy tagging output or a workspace comment with the keyword Evidence
DBy executing a playbook with the Save Execution Logs option enabled
You configured a queue named L1 Analysts and created shifts covering morning, evening, and overnight periods, with two members assigned to each shift.
However, you found that ingested alerts are assigned to every queue member in round-robin order rather than only to users who are currently on shift.
What is the issue?
AThe shift lead needs to disable automatic shift handover.
BThe Queueable option is disabled for the alerts module.
CThe queue rules conflict with the user assignment rules.
DShift-based assignment is disabled.
A partner organization recently had sensitive data exfiltrated by a well-known adversary group. You are tasked with threat hunting to determine whether your organization is also affected.
Which action must you take first?
AUse threat intelligence to enrich the IP addresses of all destinations.
BReview the tactics, techniques, and procedures of the adversary.
CUse a packet analyzer to capture and review all traffic flows on critical devices.
DReview historical logs to establish a baseline for normal bandwidth usage.
Community Discussion