Fortinet NSE7_SOC_AR-7.6 - Fortinet NSE 7 - Security Operations 7.6 Architect Exam
Page: 3 / 12
Total 57 questions
Question #11 (Topic: Exam A)
You are designing a FortiSOAR hybrid multi-tenant deployment. The architecture must support remote tenant execution and automation inside segmented networks.
Which three elements are true for this design? (Choose three.)
Which three elements are true for this design? (Choose three.)
A. The FortiSOAR master cluster can host shared tenants, with strict data isolation between them.
B. FortiSOAR tenant nodes or agents use TCP port 5671 to communicate with a secure message exchange.
C. FortiSOAR agents are deployed on the master cluster to improve high availability (HA) performance.
D. Each tenant or agent has a dedicated, access-controlled space on a secure message exchange for message routing.
E. The secure message exchange must be a dedicated instance instead of an embedded one.
Answer: ABD
Question #12 (Topic: Exam A)
Refer to the exhibit.

A compromised PC establishes an SSH connection to an engineering build server, which then relays HTTPS traffic to reach servers that would otherwise have blocked access from the LAN.
Which technique is used for this attack?

A compromised PC establishes an SSH connection to an engineering build server, which then relays HTTPS traffic to reach servers that would otherwise have blocked access from the LAN.
Which technique is used for this attack?
A. Port knocking
B. Exfiltration over C2 channel
C. Man-in-the-middle (MITM)
D. Protocol tunneling
Answer: D
Question #13 (Topic: Exam A)
Refer to the exhibits.


Assume that the traffic flows are identical, except for the destination IP address. There is only one FortiGate in network address translation (NAT) mode in this environment.
Based on the exhibits, which two conclusions can you make about this FortiSIEM incident? (Choose two.)


Assume that the traffic flows are identical, except for the destination IP address. There is only one FortiGate in network address translation (NAT) mode in this environment.
Based on the exhibits, which two conclusions can you make about this FortiSIEM incident? (Choose two.)
A. The destination hosts are not responding.
B. The client 10.200.3.219 is conducting active reconnaissance.
C. FortiGate is blocking the return flows.
D. FortiGate is not routing the packets to the destination hosts.
Answer: AB
Question #14 (Topic: Exam A)
You are using FortiSIEM analytics to reference the configuration management database (CMDB) event type categories with the following requirements:
Attribute: Event Type
Value: Group: Logon Success
Which operator must you use for the analytics search?
Attribute: Event Type
Value: Group: Logon Success
Which operator must you use for the analytics search?
A. IN
B. CONTAIN
C. IS
D. HAS
Answer: A
Question #15 (Topic: Exam A)
Refer to the exhibit.

You are trying to find traffic flows to destinations that are in Europe or Asia, for hosts in the local LAN segment. However, the query returns no results. Assume these logs exist on FortiSIEM.
Which three mistakes can you see in the query shown in the exhibit? (Choose three.)

You are trying to find traffic flows to destinations that are in Europe or Asia, for hosts in the local LAN segment. However, the query returns no results. Assume these logs exist on FortiSIEM.
Which three mistakes can you see in the query shown in the exhibit? (Choose three.)
A. The logical operator for the first row (Group: Europe) must be OR.
B. The null value cannot be used with the IS NOT operator.
C. The time range must be Absolute for queries that use configuration management database (CMDB) groups.
D. The Source IP row operator must be BETWEEN 10.0.0.0, 10.200.200.254.
E. There are missing parentheses between the first row (Group: Europe) and the second row (Group: Asia).
Answer: ADE