Weekend Sale - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70xmasdy

Welcome To DumpsPedia

NSE7_SOC_AR-7.6 Sample Questions Answers

Questions 4

You are trying to create a playbook that uses source data from ingestion to populate the description field of a task. You successfully saved the source data to a variable called ingestion_data . Now, you must parse the results and extract a list of indicators. Which Jinja expression can accomplish this task? Choose one answer.

Options:

A.

{{ vars.ingestion_data | json_query( " [?type== ' IOC ' ] " ) }}

B.

{{ vars.ingestion_data | to_nice_json | ipaddr | hwaddr | email | hash }}

C.

{{ vars.ingestion_data | type_debug }}

D.

{{ vars.ingestion_data | extract_artifacts }}

Buy Now
Questions 5

Refer to the exhibits.

The FortiMail Sender Blocklist playbook is configured to take manual input and add those entries to the FortiMail abc. com domain-level block list. The playbook is configured to use a FortiMail connector and the ADD_SENDER_TO_BLOCKLIST action.

Why is the FortiMail Sender Blocklist playbook execution failing7

Options:

A.

You must use the GET_EMAIL_STATISTICS action first to gather information about email messages.

B.

FortiMail is expecting a fully qualified domain name (FQDN).

C.

The client-side browser does not trust the FortiAnalzyer self-signed certificate.

D.

The connector credentials are incorrect

Buy Now
Questions 6

Match the FortiSIEM device type to its description. Select each FortiSIEM device type in the left column, hold and drag it to the blank space next to its corresponding description in the column on the right.

6

Options:

Buy Now
Questions 7

You created a war room and want to run a connector action to look up the reputation of a domain. Then, you need to save the output for your team to review. However, there is a lot of output, and you want to limit the amount of information attached to the war room. How do you accomplish this? Choose one answer.

Options:

A.

From the returned output, select only the output keys you want.

B.

Apply a workspace filter to show only relevant fields.

C.

Use the Investigate tab to map only the fields you want.

D.

Lower the playbook logging level before executing the connector.

Buy Now
Questions 8

Refer to the exhibit.

Assume that all devices in the FortiAnalyzer Fabric are shown in the image.

Which two statements about the FortiAnalyzer Fabric deployment are true? (Choose two.)

Options:

A.

FortiGate-B1 and FortiGate-B2 are in a Security Fabric.

B.

There is no collector in the topology.

C.

All FortiGate devices are directly registered to the supervisor.

D.

FAZ-SiteA has two ADOMs enabled.

Buy Now
Questions 9

Refer to the Exhibit:

An analyst wants to create an incident and generate a report whenever FortiAnalyzer generates a malicious attachment event based on FortiSandbox analysis. The endpoint hosts are protected by FortiClient EMS integrated with FortiSandbox. All devices are logging to FortiAnalyzer.

Which connector must the analyst use in this playbook?

Options:

A.

FortiSandbox connector

B.

FortiClient EMS connector

C.

FortiMail connector

D.

Local connector

Buy Now
Questions 10

Review the incident report. Shortly after being compromised, an infected host collected its own network configuration and connection details, then began sending low-volume connection attempts to multiple internal addresses to identify responding hosts. Which two MITRE ATT & CK techniques best describe this activity? Choose two answers.

Options:

A.

System Network Connections Discovery

B.

Network Sniffing

C.

Lateral Movement

D.

Active Scanning

Buy Now
Questions 11

Which two statements accurately describe the process to create a new rule from a search using FortiSIEM analytics? Choose two answers.

Options:

A.

Raw event logs cannot be used for incident rule creation.

B.

The incident action is automatically configured based on the event type.

C.

All search filter rows are added into a single subpattern.

D.

The default aggregate condition will always be COUNT(Matched Events) > = 1 .

Buy Now
Questions 12

Refer to the exhibit.

12

You must configure the FortiGate connector to allow FortiSOAR to perform actions on a firewall. However, the connection fails. Which two configurations are required? (Choose two answers)

Options:

A.

Trusted hosts must be enabled and the FortiSOAR IP address must be permitted.

B.

The VDOM name must be specified, or set to VDOM_1, if VDOMs are not enabled on FortiGate.

C.

HTTPS must be enabled on the FortiGate interface that FortiSOAR will communicate with.

D.

An API administrator must be created on FortiGate with the appropriate profile, along with a generated API key to configure on the connector.

Buy Now
Questions 13

Refer to the exhibits.

You configured a spearphishing event handler and the associated rule. However. FortiAnalyzer did not generate an event.

When you check the FortiAnalyzer log viewer, you confirm that FortiSandbox forwarded the appropriate logs, as shown in the raw log exhibit.

What configuration must you change on FortiAnalyzer in order for FortiAnalyzer to generate an event?

Options:

A.

In the Log Type field, change the selection to AntiVirus Log(malware).

B.

Configure a FortiSandbox data selector and add it tothe event handler.

C.

In the Log Filter by Text field, type the value: .5 ub t ype ma Iwa re..

D.

Change trigger condition by selecting. Within a group, the log field Malware Kame (mname > has 2 or more unique values.

Buy Now
Questions 14

Refer to the exhibit.

14

You are trying to find traffic flows to destinations that are in Europe or Asia, for hosts in the local LAN segment. However, the query returns no results. Assume these logs exist on FortiSIEM.

Which three mistakes can you see in the query shown in the exhibit? (Choose three answers)

Options:

A.

The null value cannot be used with the IS NOT operator.

B.

The time range must be Absolute for queries that use configuration management database (CMDB) groups.

C.

There are missing parentheses between the first row (Group: Europe) and the second row (Group: Asia).

D.

The Source IP row operator must be BETWEEN 10.0.0.0, 10.200.200.254.

E.

The logical operator for the first row (Group: Europe) must be OR.

Buy Now
Questions 15

An analyst prioritizes blocking IP addresses and domains from every phishing campaign. Based on the Pyramid of Pain model, which two statements accurately describe this approach? Choose two answers.

Options:

A.

It helps identify strategic weaknesses in adversary infrastructure.

B.

It imposes a high operational cost on adversaries when their attacks are detected.

C.

It focuses on observable network indicators rather than underlying attack methods.

D.

It relies on blocking indicators that adversaries can easily replace or rotate.

Buy Now
Questions 16

You wish to use FortiAI to help you design playbooks. Which two configurations on FortiSOAR are required? Choose two answers.

Options:

A.

Train the FortiSOAR machine learning engine.

B.

Install and configure the OpenAI connector.

C.

Grant CRUD permissions to the Playbook user.

D.

Install the FortiAI solution pack and run the configuration wizard.

Buy Now
Questions 17

When does FortiAnalyzer generate an event?

Options:

A.

When a log matches a filter in a data selector

B.

When a log matches an action in a connector

C.

When a log matches a rule in an event handler

D.

When a log matches a task in a playbook

Buy Now
Questions 18

Refer to the exhibit.

You notice that the custom event handler you configured to detect SMTP reconnaissance activities is creating a large number of events. This is overwhelming your notification system.

How can you fix this?

Options:

A.

Increase the trigger count so that it identifies and reduces the count triggered by a particular group.

B.

Disable the custom event handler because it is not working as expected.

C.

Decrease the time range that the custom event handler covers during the attack.

D.

Increase the log field value so that it looks for more unique field values when it creates the event.

Buy Now
Questions 19

Refer to Exhibits:

19

19

You configured the FortiGate connector on FortiSOAR. You want to allow FortiSOAR 10.200.200.160 to perform actions on FortiGate 172.16.200.1 . However, the connection attempt fails. Assume that the FortiGate connector is configured correctly on the FortiSOAR side.

Which two configurations are required on FortiGate? Choose two answers.

Options:

A.

HTTPS must be enabled on the FortiGate interface that FortiSOAR will communicate with.

B.

FortiSOAR IP address must be added under Trusted Hosts.

C.

The administrator profile must have System read and write permissions.

D.

The FortiGate interface role must be set to Custom API Endpoint.

Buy Now
Questions 20

Refer to Exhibit:

A SOC analyst is designing a playbook to filter for a high severity event and attach the event information to an incident.

Which local connector action must the analyst use in this scenario?

Options:

A.

Get Events

B.

Update Incident

C.

Update Asset and Identity

D.

Attach Data to Incident

Buy Now
Questions 21

Review the following incident report:

Attackers leveraged a phishing email campaign targeting your employees.

The email likely impersonated a trusted source, such as the IT department, and requested login credentials.

An unsuspecting employee clicked a malicious link in the email, leading to the download and execution of a Remote Access Trojan (RAT).

The RAT provided the attackers with remote access and a foothold in the compromised system.

Which two MITRE ATT & CK tactics does this incident report capture? (Choose two.)

Options:

A.

Initial Access

B.

Defense Evasion

C.

Lateral Movement

D.

Persistence

Buy Now
Questions 22

You suspect your organization has been a victim of numerous incidents carried out by the same threat actor. Which option allows you to group the incidents and track them? Choose one answer.

Options:

A.

Add a common tag to correlate them.

B.

Mark one incident as the parent and run a playbook to close the child incidents.

C.

Select those incidents and use the Merge function.

D.

Create a campaign and link related records to it.

Buy Now
Questions 23

You need to create a nested query in FortiSIEM that satisfies the following conditions:

    Find all devices discovered by any FortiSIEM Windows Agent.

    From those devices, identify those that have generated Windows Login Failure events.

Which two query components should be used for this nested query? Choose two answers.

Options:

A.

Outer Event Query

B.

Outer CMDB Query

C.

Inner CMDB Query

D.

Inner Event Query

Buy Now
Questions 24

A partner organization recently suffered a distributed denial-of-service (DDoS) attack, but the adversary’s identity and TTPs remain unknown. Your SOC has not received any relevant threat intelligence from the partner organization, but you are asked to determine whether similar activity could be happening in your environment. Which threat hunting action should you perform first? Choose one answer.

Options:

A.

Configure SIEM rules to alert when inbound traffic exceeds baseline thresholds.

B.

Use a packet analyzer to capture and review all traffic flows on critical devices.

C.

Develop a hunting hypothesis based on how DDoS can be executed against your network.

D.

Use threat intelligence to enrich the IP addresses of all external source IP addresses.

Buy Now
Questions 25

Refer to the exhibit.

25

Which method most effectively reduces the attack surface of this organization? (Choose one answer)

Options:

A.

Forward all firewall logs to the security information and event management (SIEM) system.

B.

Enable deep inspection on firewall policies.

C.

Implement macrosegmentation.

D.

Remove unused devices.

Buy Now
Questions 26

Which two phases are part of the FortiSOAR incident handling process but are not phases in the NIST 800-61 Revision 2 model? Choose two answers.

Options:

A.

Preparation

B.

Confirmation

C.

Detection

D.

Identification

Buy Now
Questions 27

You are trying to create a playbook that creates a manual task showing a list of public IPv6 addresses. You were successful in extracting all IP addresses from a previous action into a variable called ip_list , which contains both private and public IPv4 and IPv6 addresses. You must now filter the results to display only public IPv6 addresses. Which two Jinja expressions can accomplish this task? (Choose two answers)

Options:

A.

{{ vars.ip_list | ipv6addr( ' public ' ) }}

B.

{{ vars.ip_list | ipaddr( ' public ' ) | ipv6 }}

C.

{{ vars.ip_list | ipaddr( ' !private ' ) | ipv6 }}

D.

{{ vars.ip_list | ipv6 | ipaddr( ' public ' ) }}

Buy Now
Exam Code: NSE7_SOC_AR-7.6
Exam Name: Fortinet NSE 7 - Security Operations 7.6 Architect
Last Update: Aug 22, 2026
Questions: 91

PDF + Testing Engine

$51.42 $171.4

Testing Engine

$38.57 $128.55

PDF (Q&A)

$42.85 $142.82