Summer Sale Limited Time 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = simple75

Pass the Fortinet Certified Professional Security Operations NSE7_SOC_AR-7.6 Questions and answers with Dumpstech

Exam NSE7_SOC_AR-7.6 Premium Access

View all detail and faqs for the NSE7_SOC_AR-7.6 exam

Practice at least 50% of the questions to maximize your chances of passing.
Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions
Questions # 21:

Review the incident report. Shortly after being compromised, an infected host collected its own network configuration and connection details, then began sending low-volume connection attempts to multiple internal addresses to identify responding hosts. Which two MITRE ATT & CK techniques best describe this activity? Choose two answers.

Options:

A.

System Network Connections Discovery

B.

Network Sniffing

C.

Lateral Movement

D.

Active Scanning

Questions # 22:

When you use a manual trigger to save user input as a variable, what is the correct Jinja expression to reference the variable? (Choose one answer)

Options:

A.

{{ vars.input.params. < variable_name > }}

B.

{{ globalVars. < variable_name > }}

C.

{{ vars.item. < variable_name > }}

D.

{{ vars.steps. < variable_name > }}

Questions # 23:

When configuring a FortiAnalyzer to act as a collector device, which two steps must you perform? (Choose two.)

Options:

A.

Enable log compression.

B.

Configure log forwarding to a FortiAnalyzer in analyzer mode.

C.

Configure the data policy to focus on archiving.

D.

Configure Fabric authorization on the connecting interface.

Questions # 24:

A large enterprise FortiSIEM deployment is experiencing delays in log correlation and analytics. Which architectural adjustment is most appropriate? Choose one answer.

Options:

A.

Limit the number of rules using streaming mode.

B.

Add more workers.

C.

Add more collectors.

D.

Increase supervisor CPU and memory.

Questions # 25:

Refer to Exhibit:

A SOC analyst is designing a playbook to filter for a high severity event and attach the event information to an incident.

Which local connector action must the analyst use in this scenario?

Options:

A.

Get Events

B.

Update Incident

C.

Update Asset and Identity

D.

Attach Data to Incident

Questions # 26:

Review the incident report:

Packet captures show a host maintaining periodic TLS sessions that imitate normal HTTPS traffic but run on TCP 8443 to a single external host. An analyst flags the traffic as potential command-and-control. During the same period, the host issues frequent DNS queries with oversized TXT payloads to an attacker-controlled domain, transferring staged files.

Which two MITRE ATT & CK techniques best describe this activity? (Choose two answers)

Options:

A.

Non-Standard Port

B.

Exploitation of Remote Services

C.

Exfiltration Over Alternative Protocol

D.

Hide Artifacts

Questions # 27:

Refer to the exhibit.

Question # 27

You created a new playbook and executed it as a test. However, it failed to run. You want to investigate, but you do not see details about the error. What is the reason for the lack of details?

Options:

A.

The connector is deactivated.

B.

The playbook logging level must be debug.

C.

The Ignore Error option is enabled.

D.

The user that executed the playbook does not have the necessary permissions.

Questions # 28:

Refer to the exhibit.

Question # 28

How do you add a piece of evidence to the Action Logs Marked As Evidence area? (Choose one answer)

Options:

A.

By tagging output or a workspace comment with the keyword Evidence

B.

By linking an indicator to the war room

C.

By creating an evidence collection task and attaching a file

D.

By executing a playbook with the Save Execution Logs option enabled

Questions # 29:

Refer to the exhibit.

Question # 29

You are trying to find traffic flows to destinations that are in Europe or Asia, for hosts in the local LAN segment. However, the query returns no results. Assume these logs exist on FortiSIEM.

Which three mistakes can you see in the query shown in the exhibit? (Choose three answers)

Options:

A.

The null value cannot be used with the IS NOT operator.

B.

The time range must be Absolute for queries that use configuration management database (CMDB) groups.

C.

There are missing parentheses between the first row (Group: Europe) and the second row (Group: Asia).

D.

The Source IP row operator must be BETWEEN 10.0.0.0, 10.200.200.254.

E.

The logical operator for the first row (Group: Europe) must be OR.

Questions # 30:

An analyst prioritizes blocking IP addresses and domains from every phishing campaign. Based on the Pyramid of Pain model, which two statements accurately describe this approach? Choose two answers.

Options:

A.

It helps identify strategic weaknesses in adversary infrastructure.

B.

It imposes a high operational cost on adversaries when their attacks are detected.

C.

It focuses on observable network indicators rather than underlying attack methods.

D.

It relies on blocking indicators that adversaries can easily replace or rotate.

Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions