QuestionQ1
SOAR Incident Handling and Threat HuntingRefer to the exhibit.

You are attempting to find traffic flows to destinations in Europe or Asia for hosts in the local LAN segment. However, the query returns no results. Assume that these logs exist on FortiSIEM.
Which three mistakes are present in the query shown in the exhibit?
- A The logical operator for the first row (Group: Europe) must be OR.
- B The null value cannot be used with the IS NOT operator.
- C The time range must be Absolute for queries that use configuration management database (CMDB) groups.
- D The Source IP row operator must be BETWEEN 10.0.0.0, 10.200.200.254.
- E There are missing parentheses between the first row (Group: Europe) and the second row (Group: Asia).
QuestionQ2
SOAR Incident Handling and Threat HuntingWhich three of the following are threat-hunting activities?
- A Generate a hypothesis.
- B Tune correlation rules.
- C Perform packet analysis.
- D Automate workflows.
- E Enrich records with threat intelligence.
Community Discussion
QuestionQ3
SOAR Playbook DevelopmentWhen you configure an Ingest Bulk Feed playbook step, which two restrictions must be considered?
- A It will not trigger On Create triggers.
- B It is slower than the Create Record step.
- C It will not trigger On Update triggers.
- D It cannot use step output from a connector action.
Community Discussion
QuestionQ4
SOC Concepts and FrameworksBased on the Pyramid of Pain model, which two statements correctly describe an indicator’s value and the difficulty an adversary faces in changing it?
- A Tactics, techniques, and procedures are hard because adversaries must adapt their methods.
- B Tools are easy because often, multiple alternatives exist.
- C IP addresses are easy because adversaries can spoof them or move them to new resources.
- D Artifacts are easy because adversaries can alter file paths or registry keys.
Community Discussion
QuestionQ5
Detection CapabilitiesYou are setting up a new FortiSIEM rule to trigger incidents after receiving a specified number of either Fortigate-Traffic-Violation or Fortigate-Traffic-Denied event types. Although a single subpattern could accomplish this, you choose to create two separate subpatterns—one for each event type—and correlate them with the OR operator.
Which two benefits does this method provide?
- A Each subpattern can use a different group by condition.
- B Each subpattern can use a different time window condition.
- C Each subpattern can use a different aggregate condition.
- D Each subpattern can trigger its own notification policy.
Community Discussion
That's the end of the preview
It's free
100% of the questions are free for all users.
No strings attached.












Community Discussion