Fortinet NSE 7 - Security Operations 7.6 Architect - NSE7_SOC_AR-7.6무료 덤프문제 풀어보기
Review the incident report:
Packet captures show a host maintaining periodic TLS sessions that imitate normal HTTPS traffic but run on TCP 8443 to a single external host. An analyst flags the traffic as potential command-and-control. During the same period, the host issues frequent DNS queries with oversized TXT payloads to an attacker-controlled domain, transferring staged files.
Which two MITRE ATT & CK techniques best describe this activity? (Choose two answers)
Packet captures show a host maintaining periodic TLS sessions that imitate normal HTTPS traffic but run on TCP 8443 to a single external host. An analyst flags the traffic as potential command-and-control. During the same period, the host issues frequent DNS queries with oversized TXT payloads to an attacker-controlled domain, transferring staged files.
Which two MITRE ATT & CK techniques best describe this activity? (Choose two answers)
정답: A,D
설명: (Fast2test 회원만 볼 수 있음)
Which two ways can you create an incident on FortiAnalyzer? (Choose two.)
정답: B,D
설명: (Fast2test 회원만 볼 수 있음)
While monitoring your network, you discover that one FortiGate device is sending significantly more logs to FortiAnalyzer than all of the other FortiGate devices in the topology.
Additionally, the ADOM that the FortiGate devices are registered to consistently exceeds its quota.
What are two possible solutions? (Choose two.)
Additionally, the ADOM that the FortiGate devices are registered to consistently exceeds its quota.
What are two possible solutions? (Choose two.)
정답: C,D
설명: (Fast2test 회원만 볼 수 있음)
Refer to the exhibit.

You created a threat hunting playbook to perform a search query using the FortiSIEM connector. However, when you run the playbook, you do not see any output. Which step must you take first in your troubleshooting process?

You created a threat hunting playbook to perform a search query using the FortiSIEM connector. However, when you run the playbook, you do not see any output. Which step must you take first in your troubleshooting process?
정답: D
설명: (Fast2test 회원만 볼 수 있음)
Refer to the exhibits.
The Malicious File Detect playbook is configured to create an incident when an event handler generates a malicious file detection event.
Why did the Malicious File Detect playbook execution fail?
The Malicious File Detect playbook is configured to create an incident when an event handler generates a malicious file detection event.
Why did the Malicious File Detect playbook execution fail?
정답: C
설명: (Fast2test 회원만 볼 수 있음)
Refer to Exhibit:
A SOC analyst is designing a playbook to filter for a high severity event and attach the event information to an incident.
Which local connector action must the analyst use in this scenario?
A SOC analyst is designing a playbook to filter for a high severity event and attach the event information to an incident.
Which local connector action must the analyst use in this scenario?
정답: C
설명: (Fast2test 회원만 볼 수 있음)
You wish to use FortiAI to help you design playbooks. Which two configurations on FortiSOAR are required? Choose two answers.
정답: B,D
설명: (Fast2test 회원만 볼 수 있음)
When configuring an Ingest Bulk Feed playbook step, which two restrictions must you consider? Choose two answers.
정답: A,C
설명: (Fast2test 회원만 볼 수 있음)
Refer to the exhibits.

Assume that the traffic flows are identical, except for the destination IP address. There is only one FortiGate in network address translation (NAT) mode in this environment.
Based on the exhibits, which two conclusions can you make about this FortiSIEM incident? (Choose two answers)

Assume that the traffic flows are identical, except for the destination IP address. There is only one FortiGate in network address translation (NAT) mode in this environment.
Based on the exhibits, which two conclusions can you make about this FortiSIEM incident? (Choose two answers)
정답: A,D
설명: (Fast2test 회원만 볼 수 있음)
Refer to the exhibit.

Which method most effectively reduces the attack surface of this organization? (Choose one answer)

Which method most effectively reduces the attack surface of this organization? (Choose one answer)
정답: A
설명: (Fast2test 회원만 볼 수 있음)