Fortinet FCSS_SOC_AN-7.4 - FCSS - Security Operations 7.4 Analyst Exam

Question #11 (Topic: Exam A)
Which FortiAnalyzer connector can you use to run automation stitches?
A. FortiCASB B. FortiOS C. FortiMail D. Local
Answer: B
Question #12 (Topic: Exam A)
Which two playbook triggers enable the use of trigger events in later tasks as trigger variables? (Choose two.)
A. ON_DEMAND B. ON_SCHEDULE C. INCIDENT D. EVENT
Answer: CD
Question #13 (Topic: Exam A)
Your company is doing a security audit. To pass the audit, you must take an inventory of all software and applications running on all Windows devices.
Which FortiAnalyzer connector must you use?
A. Local Host B. FortiCASB C. FortiClient EMS D. ServiceNow
Answer: C
Question #14 (Topic: Exam A)
Refer to the exhibit.

Assume that all devices in the FortiAnalyzer Fabric are shown in the image.
Which two statements about the FortiAnalyzer Fabric deployment are true? (Choose two.)
A. FortiGate-B1 and FortiGate-B2 are in a Security Fabric. B. There is no collector in the topology. C. All FortiGate devices are directly registered to the supervisor. D. FAZ-SiteA has two ADOMs enabled.
Answer: BD
Question #15 (Topic: Exam A)
Refer to the exhibit.

A SOC analyst is creating the Malicious File Detected playbook to run when FortiAnalyzer generates a malicious file event. The playbook must also update the incident with the malicious file event data.
What must the next task in this playbook be?
A. A local connector with the action Run Report B. A local connector with the action Update Incident C. A local connector with the action Attach Data to Incident D. A local connector with the action Update Asset and Identity
Answer: C
Download Exam
Page: 3 / 6
Total 27 questions