Summer Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

NSE7_SOC_AR-7.6 Exam Dumps - Fortinet Certified Professional Security Operations Questions and Answers

Question # 4

A FortiSOAR playbook includes a Wait step that is configured to pause execution after initiating a reputation lookup on an indicator. Which two configurations of the Wait step are valid? Choose two answers.

Options:

A.

The playbook resumes when a specified amount of time has elapsed.

B.

The playbook resumes when the indicator record is updated.

C.

The Wait step can retry a specific step in the playbook at scheduled intervals until it succeeds.

D.

The Wait step, during the AWAITING state, can execute child playbooks.

Buy Now
Question # 5

You are investigating an open incident and want to add records from the Tickets module, a custom module, to the visual correlation widget. Assume there are already linked ticket records to the incident.

How do you accomplish this? Choose one answer.

Options:

A.

Ingest ticket records through a custom connector.

B.

Tag ticket records with the incident ID.

C.

Edit the incident template and add the Tickets module to the graph.

D.

Define more module relationships under Correlation Settings.

Buy Now
Question # 6

Review the incident report:

An attacker identified employee names, roles, and email patterns from public press releases, which were then used to craft tailored emails.

The emails were directed to recipients to review an attached agenda using a link hosted off the corporate domain.

Which two MITRE ATT & CK tactics best fit this report? (Choose two answers)

Options:

A.

Reconnaissance

B.

Discovery

C.

Initial Access

D.

Defense Evasion

Buy Now
Question # 7

Refer to the exhibits.

The FortiMail Sender Blocklist playbook is configured to take manual input and add those entries to the FortiMail abc. com domain-level block list. The playbook is configured to use a FortiMail connector and the ADD_SENDER_TO_BLOCKLIST action.

Why is the FortiMail Sender Blocklist playbook execution failing7

Options:

A.

You must use the GET_EMAIL_STATISTICS action first to gather information about email messages.

B.

FortiMail is expecting a fully qualified domain name (FQDN).

C.

The client-side browser does not trust the FortiAnalzyer self-signed certificate.

D.

The connector credentials are incorrect

Buy Now
Question # 8

Refer to the exhibits.

What can you conclude from analyzing the data using the threat hunting module?

Options:

A.

Spearphishing is being used to elicit sensitive information.

B.

DNS tunneling is being used to extract confidential data from the local network.

C.

Reconnaissance is being used to gather victim identity information from the mail server.

D.

FTP is being used as command-and-control (C & C) technique to mine for data.

Buy Now
Question # 9

You need to create a nested query in FortiSIEM that satisfies the following conditions:

    Find all devices discovered by any FortiSIEM Windows Agent.

    From those devices, identify those that have generated Windows Login Failure events.

Which two query components should be used for this nested query? Choose two answers.

Options:

A.

Outer Event Query

B.

Outer CMDB Query

C.

Inner CMDB Query

D.

Inner Event Query

Buy Now
Question # 10

Refer to the exhibit.

The input of a FortiSIEM connector action is shown.

You want to create a playbook on FortiSOAR that allows you to accomplish the following:

Manually input an IP address.

Use the connector action in the exhibit to retrieve a device from the FortiSIEM configuration management database (CMDB) with that IP address.

Ask the SOC manager to review the information pulled from FortiSIEM about that device.

If the manager approves, an asset record is created.

Which combination and order of step operations fulfills the requirements with the fewest required playbook steps?

Options:

A.

Manual trigger, 2) Connector action, 3) Approval, 4) Create Record

B.

Manual trigger, 2) Set Variable, 3) Connector action, 4) Set Variable, 5) Approval, 6) Create record

C.

On Create trigger, 2) Connector action, 3) Manual Task, 4) Create record

D.

Connector action, 2) Approval, 3) Create record, 4) Update record

Buy Now
Question # 11

Which of the following are critical when analyzing and managing events and incidents in a SOC? (Choose two answers)

Options:

A.

Accurate detection of threats

B.

Immediate escalation for all alerts

C.

Rapid identification of false positives

D.

Periodic system downtime for maintenance

Buy Now
Question # 12

Match the FortiSIEM device type to its description. Select each FortiSIEM device type in the left column, hold and drag it to the blank space next to its corresponding description in the column on the right.

Options:

Buy Now
Question # 13

Based on the Pyramid of Pain model, which two statements accurately describe the value of an indicator and how difficult it is for an adversary to change? (Choose two answers)

Options:

A.

IP addresses are easy because adversaries can spoof them or move them to new resources.

B.

Tactics, techniques, and procedures are hard because adversaries must adapt their methods.

C.

Artifacts are easy because adversaries can alter file paths or registry keys.

D.

Tools are easy because often, multiple alternatives exist.

Buy Now
Exam Code: NSE7_SOC_AR-7.6
Exam Name: Fortinet NSE 7 - Security Operations 7.6 Architect
Last Update: Aug 24, 2026
Questions: 91
NSE7_SOC_AR-7.6 pdf

NSE7_SOC_AR-7.6 PDF

$25.5  $84.99
NSE7_SOC_AR-7.6 Engine

NSE7_SOC_AR-7.6 Testing Engine

$28.5  $94.99
NSE7_SOC_AR-7.6 PDF + Engine

NSE7_SOC_AR-7.6 PDF + Testing Engine

$40.5  $134.99