ExamGecko
Home / Fortinet / FCSS_SOC_AN-7.4 / List of questions
Ask Question

Fortinet FCSS_SOC_AN-7.4 Practice Test - Questions Answers, Page 3

List of questions

Question 21

Report Export Collapse

Which two types of variables can you use in playbook tasks? (Choose two.)

Become a Premium Member for full access
  Unlock Premium Member

Question 22

Report Export Collapse

Refer to the exhibits.

Fortinet FCSS_SOC_AN-7.4 image Question 22 132072 12132024000421000000

The FortiMail Sender Blocklist playbook is configured to take manual input and add those entries to the FortiMail abc. com domain-level block list. The playbook is configured to use a FortiMail connector and the ADD_SENDER_TO_BLOCKLIST action.

Why is the FortiMail Sender Blocklist playbook execution failing7

Become a Premium Member for full access
  Unlock Premium Member

Question 23

Report Export Collapse

Which two ways can you create an incident on FortiAnalyzer? (Choose two.)

Become a Premium Member for full access
  Unlock Premium Member

Question 24

Report Export Collapse

Which statement best describes the MITRE ATT&CK framework?

Become a Premium Member for full access
  Unlock Premium Member

Question 25

Report Export Collapse

Exhibit:

Fortinet FCSS_SOC_AN-7.4 image Question 25 132075 12132024000421000000

Which observation about this FortiAnalyzer Fabric deployment architecture is true?

Become a Premium Member for full access
  Unlock Premium Member

Question 26

Report Export Collapse

Which FortiAnalyzer feature uses the SIEM database for advance log analytics and monitoring?

Become a Premium Member for full access
  Unlock Premium Member

Question 27

Report Export Collapse

Refer to the exhibits.

Fortinet FCSS_SOC_AN-7.4 image Question 27 132077 12132024000421000000

You configured a custom event handler and an associated rule to generate events whenever FortiMail detects spam emails. However, you notice that the event handler is generating events for both spam emails and clean emails.

Which change must you make in the rule so that it detects only spam emails?

Become a Premium Member for full access
  Unlock Premium Member

Question 28

Report Export Collapse

When does FortiAnalyzer generate an event?

Become a Premium Member for full access
  Unlock Premium Member

Question 29

Report Export Collapse

A customer wants FortiAnalyzer to run an automation stitch that executes a CLI command on FortiGate to block a predefined list of URLs, if a botnet command-and-control (C&C) server IP is detected.

Which FortiAnalyzer feature must you use to start this automation process?

Become a Premium Member for full access
  Unlock Premium Member

Question 30

Report Export Collapse

Refer to the exhibit.

Fortinet FCSS_SOC_AN-7.4 image Question 30 132080 12132024000421000000

Which two options describe how the Update Asset and Identity Database playbook is configured? (Choose two.)

Become a Premium Member for full access
  Unlock Premium Member
Total 32 questions
Go to page: of 4

Related questions