Fortinet FCSS_SOC_AN-7.4 Practice Test - Questions Answers, Page 3
List of questions
Question 21
Which two types of variables can you use in playbook tasks? (Choose two.)
Question 22
Refer to the exhibits.
The FortiMail Sender Blocklist playbook is configured to take manual input and add those entries to the FortiMail abc. com domain-level block list. The playbook is configured to use a FortiMail connector and the ADD_SENDER_TO_BLOCKLIST action.
Why is the FortiMail Sender Blocklist playbook execution failing7
Question 23
Which two ways can you create an incident on FortiAnalyzer? (Choose two.)
Question 24
Which statement best describes the MITRE ATT&CK framework?
Question 25
Exhibit:
Which observation about this FortiAnalyzer Fabric deployment architecture is true?
Question 26
Which FortiAnalyzer feature uses the SIEM database for advance log analytics and monitoring?
Question 27
Refer to the exhibits.
You configured a custom event handler and an associated rule to generate events whenever FortiMail detects spam emails. However, you notice that the event handler is generating events for both spam emails and clean emails.
Which change must you make in the rule so that it detects only spam emails?
Question 28
When does FortiAnalyzer generate an event?
Question 29
A customer wants FortiAnalyzer to run an automation stitch that executes a CLI command on FortiGate to block a predefined list of URLs, if a botnet command-and-control (C&C) server IP is detected.
Which FortiAnalyzer feature must you use to start this automation process?
Question 30
Refer to the exhibit.
Which two options describe how the Update Asset and Identity Database playbook is configured? (Choose two.)
Question