Fortinet FCSS_SOC_AN-7.4 - FCSS - Security Operations 7.4 Analyst Exam

Question #6 (Topic: Exam A)
Refer to the exhibit.

A SOC analyst is designing a playbook to filter for a high severity event and attach the event information to an incident.
Which local connector action must the analyst use in this scenario?
A. Update Asset and Identity B. Update Incident C. Get Events D. Attach Data to Incident
Answer: D
Question #7 (Topic: Exam A)
When does FortiAnalyzer generate an event?
A. When a log matches a filter in a data selector B. When a log matches a rule in an event handler C. When a log matches an action in a connector D. When a log matches a task in a playbook
Answer: B
Question #8 (Topic: Exam A)
Refer to the exhibit.

Which two options describe how the Update Asset and Identity Database playbook is configured? (Choose two.)
A. The playbook is using a FortiMail connector. B. The playbook is using a FortiClient EMS connector. C. The playbook is using a local connector. D. The playbook is using an on-demand trigger.
Answer: BC
Question #9 (Topic: Exam A)
When configuring a FortiAnalyzer to act as a collector device, which two steps must you perform? (Choose two.)
A. Configure Fabric authorization on the connecting interface. B. Enable log compression. C. Configure the data policy to focus on archiving. D. Configure log forwarding to a FortiAnalyzer in analyzer mode.
Answer: CD
Question #10 (Topic: Exam A)
Refer to the exhibit, which shows the partial output of the MITRE ATT&CK Enterprise matrix on FortiAnalyzer.

Which two statements are true? (Choose two.)
A. There are four techniques that fall under tactic T1071. B. There are 15 events associated with the tactic. C. There are four subtechniques that fall under technique T1071. D. There are event handlers that cover tactic T1071.
Answer: CD
Download Exam
Page: 2 / 6
Total 27 questions