Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: best70

NSE7_SOC_AR-7.6 Fortinet NSE 7 - Security Operations 7.6 Architect Questions and Answers

Questions 4

Which two statements accurately describe the Custom API Endpoint playbook trigger? Choose two answers.

Options:

A.

It supports token-based, basic, and no authentication.

B.

One custom API endpoint can trigger multiple playbooks at the same time.

C.

It supports HTTP POST, GET, and PUT methods.

D.

An external system can initiate a playbook using an arbitrary endpoint on FortiSOAR.

Buy Now
Questions 5

Based on the Pyramid of Pain model, which two statements accurately describe the value of an indicator and how difficult it is for an adversary to change? (Choose two answers)

Options:

A.

IP addresses are easy because adversaries can spoof them or move them to new resources.

B.

Tactics, techniques, and procedures are hard because adversaries must adapt their methods.

C.

Artifacts are easy because adversaries can alter file paths or registry keys.

D.

Tools are easy because often, multiple alternatives exist.

Buy Now
Questions 6

Which two ways can you create an incident on FortiAnalyzer? (Choose two answers)

Options:

A.

Using a custom event handler

B.

Using a connector action

C.

Manually, on the Event Monitor page

D.

By running a playbook

Buy Now
Questions 7

You created a war room and want to run a connector action to look up the reputation of a domain. Then, you need to save the output for your team to review. However, there is a lot of output, and you want to limit the amount of information attached to the war room. How do you accomplish this? Choose one answer.

Options:

A.

From the returned output, select only the output keys you want.

B.

Apply a workspace filter to show only relevant fields.

C.

Use the Investigate tab to map only the fields you want.

D.

Lower the playbook logging level before executing the connector.

Buy Now
Questions 8

Which three end user logs does FortiAnalyzer use to identify possible IOC compromised hosts? (Choose three answers)

Options:

A.

Web filter logs1

B.

Email filter logs

C.

DNS filter logs2

D.

Application filter logs

E.

IPS logs

Buy Now
Questions 9

Refer to the exhibits.

The DOS attack playbook is configured to create an incident when an event handler generates a denial-of-ser/ice (DoS) attack event.

Why did the DOS attack playbook fail to execute?

Options:

A.

The Create SMTP Enumeration incident task is expecting an integer value but is receiving the incorrect data type

B.

The Get Events task is configured to execute in the incorrect order.

C.

The Attach_Data_To_lncident task failed.

D.

The Attach_Data_To_lncident task is expecting an integer value but is receiving the incorrect data type.

Buy Now
Questions 10

You suspect your organization has been a victim of numerous incidents carried out by the same threat actor. Which option allows you to group the incidents and track them? Choose one answer.

Options:

A.

Add a common tag to correlate them.

B.

Mark one incident as the parent and run a playbook to close the child incidents.

C.

Select those incidents and use the Merge function.

D.

Create a campaign and link related records to it.

Buy Now
Questions 11

When configuring a FortiAnalyzer to act as a collector device, which two steps must you perform? (Choose two.)

Options:

A.

Enable log compression.

B.

Configure log forwarding to a FortiAnalyzer in analyzer mode.

C.

Configure the data policy to focus on archiving.

D.

Configure Fabric authorization on the connecting interface.

Buy Now
Questions 12

What are three capabilities of the built-in FortiSOAR Jinja editor? (Choose three answers)

Options:

A.

It renders output by combining Jinja expressions and JSON input.

B.

It checks the validity of a Jinja expression.

C.

It creates new records in bulk.

D.

It loads the environment JSON of a recently executed playbook.

E.

It defines conditions to trigger a playbook step.

Buy Now
Questions 13

Using the default data ingestion wizard in FortiSOAR, place the incident handling workflow from FortiSIEM to FortiSOAR in the correct sequence. Select each workflow component in the left column, hold and drag it to a blank position in the column on the right. Place the four correct workflow components in order, placing the first step in the first position at the top of the column.

NSE7_SOC_AR-7.6 Question 13

Options:

Buy Now
Questions 14

Which three factors does the FortiSIEM rules engine use to determine the count when it evaluates the aggregate condition COUNT (Matched Events) on a specific subpattern? (Choose three answers)

Options:

A.

Group By attributes

B.

Data source

C.

Time window

D.

Search filter

E.

Incident action

Buy Now
Questions 15

You configured a new module named Users . Next, you want to configure a playbook that creates users from ingested data. When new records are created, you want to ensure that duplicate users do not overwrite existing user records and their fields. However, you also want the playbook to continue running even if duplicates are encountered so that any non-duplicate records are still created. Which two actions fulfill the requirements? Choose two answers.

Options:

A.

Use the Stop the create process option in the Create Record step.

B.

Ensure the Users module has record uniqueness conditions configured.

C.

Configure the Execution Mode to run in parallel.

D.

Use the Do not create new record (keep existing intact) option in the Create Record step.

Buy Now
Questions 16

Refer to the exhibits.

NSE7_SOC_AR-7.6 Question 16

Assume that the traffic flows are identical, except for the destination IP address. There is only one FortiGate in network address translation (NAT) mode in this environment.

Based on the exhibits, which two conclusions can you make about this FortiSIEM incident? (Choose two answers)

Options:

A.

The client 10.200.3.219 is conducting active reconnaissance.

B.

FortiGate is not routing the packets to the destination hosts.

C.

The destination hosts are not responding.

D.

FortiGate is blocking the return flows.

Buy Now
Questions 17

Refer to the exhibit.

NSE7_SOC_AR-7.6 Question 17

You must configure the FortiGate connector to allow FortiSOAR to perform actions on a firewall. However, the connection fails. Which two configurations are required? (Choose two answers)

Options:

A.

Trusted hosts must be enabled and the FortiSOAR IP address must be permitted.

B.

The VDOM name must be specified, or set to VDOM_1, if VDOMs are not enabled on FortiGate.

C.

HTTPS must be enabled on the FortiGate interface that FortiSOAR will communicate with.

D.

An API administrator must be created on FortiGate with the appropriate profile, along with a generated API key to configure on the connector.

Buy Now
Questions 18

Review the incident report:

An attacker identified employee names, roles, and email patterns from public press releases, which were then used to craft tailored emails.

The emails were directed to recipients to review an attached agenda using a link hosted off the corporate domain.

Which two MITRE ATT & CK tactics best fit this report? (Choose two answers)

Options:

A.

Reconnaissance

B.

Discovery

C.

Initial Access

D.

Defense Evasion

Buy Now
Questions 19

You want to automate a workflow on FortiSOAR so that whenever an incident is moved to the Aftermath phase, it is automatically set to status Resolved and assigned to a purple team specialist as incident lead to write an incident report. In addition, a manual task, assigned to the same specialist, will be created so they are aware of the pending work. Which three steps will accomplish this task? Choose three answers.

Options:

A.

Create a Find Record step to find matching incidents.

B.

Create a Condition step to assign both the incident and task to the specialist.

C.

Create a Manual Task step to assign the task to the specialist.

D.

Create an Update Record step to set the incident lead.

E.

Create an On Update trigger with a trigger condition that matches the Aftermath phase.

Buy Now
Questions 20

Refer to the exhibit.

NSE7_SOC_AR-7.6 Question 20

What are the two mistakes in the incident subpattern rule configuration? Choose two answers.

Options:

A.

The subpattern is missing a time window definition.

B.

The aggregate operator is incorrect.

C.

The Group By attributes conflict with each other.

D.

The mandatory Event Type attribute is missing.

Buy Now
Questions 21

A FortiSOAR playbook includes a Wait step that is configured to pause execution after initiating a reputation lookup on an indicator. Which two configurations of the Wait step are valid? Choose two answers.

Options:

A.

The playbook resumes when a specified amount of time has elapsed.

B.

The playbook resumes when the indicator record is updated.

C.

The Wait step can retry a specific step in the playbook at scheduled intervals until it succeeds.

D.

The Wait step, during the AWAITING state, can execute child playbooks.

Buy Now
Questions 22

Refer to the exhibits.

NSE7_SOC_AR-7.6 Question 22

NSE7_SOC_AR-7.6 Question 22

You configured the FortiSIEM connector on FortiSOAR. However, when you try to save the configuration, you see the error shown in the exhibit. What are two possible causes? Choose two answers.

Options:

A.

The Visibility option must be set to Public.

B.

FortiSOAR cannot reach FortiSIEM.

C.

The organization should be Super.

D.

The user credentials do not match FortiSIEM.

Buy Now
Questions 23

While monitoring your network, you discover that one FortiGate device is sending significantly more logs to FortiAnalyzer than all of the other FortiGate devices in the topology.

Additionally, the ADOM that the FortiGate devices are registered to consistently exceeds its quota.

What are two possible solutions? (Choose two.)

Options:

A.

Increase the storage space quota for the first FortiGate device.

B.

Create a separate ADOM for the first FortiGate device and configure a different set of storage policies.

C.

Reconfigure the first FortiGate device to reduce the number of logs it forwards to FortiAnalyzer.

D.

Configure data selectors to filter the data sent by the first FortiGate device.

Buy Now
Questions 24

Which two phases are part of the FortiSOAR incident handling process but are not phases in the NIST 800-61 Revision 2 model? Choose two answers.

Options:

A.

Preparation

B.

Confirmation

C.

Detection

D.

Identification

Buy Now
Questions 25

Refer to the exhibit.

Which two options describe how the Update Asset and Identity Database playbook is configured? (Choose two.)

Options:

A.

The playbook is using a local connector.

B.

The playbook is using a FortiMail connector.

C.

The playbook is using an on-demand trigger.

D.

The playbook is using a FortiClient EMS connector.

Buy Now
Questions 26

Refer to the exhibit,

which shows the partial output of the MITRE ATT & CK Enterprise matrix on FortiAnalyzer.

Which two statements are true? (Choose two.)

Options:

A.

There are four techniques that fall under tactic T1071.

B.

There are four subtechniques that fall under technique T1071.

C.

There are event handlers that cover tactic T1071.

D.

There are 15 events associated with the tactic.

Buy Now
Questions 27

Refer to Exhibits:

NSE7_SOC_AR-7.6 Question 27

NSE7_SOC_AR-7.6 Question 27

You configured the FortiGate connector on FortiSOAR. You want to allow FortiSOAR 10.200.200.160 to perform actions on FortiGate 172.16.200.1 . However, the connection attempt fails. Assume that the FortiGate connector is configured correctly on the FortiSOAR side.

Which two configurations are required on FortiGate? Choose two answers.

Options:

A.

HTTPS must be enabled on the FortiGate interface that FortiSOAR will communicate with.

B.

FortiSOAR IP address must be added under Trusted Hosts.

C.

The administrator profile must have System read and write permissions.

D.

The FortiGate interface role must be set to Custom API Endpoint.

Buy Now
Exam Code: NSE7_SOC_AR-7.6
Exam Name: Fortinet NSE 7 - Security Operations 7.6 Architect
Last Update: Aug 4, 2026
Questions: 91

PDF + Testing Engine

$134.99

Testing Engine

$99.99

PDF (Q&A)

$84.99