Fortinet FCSS_SOC_AN-7.4 Practice Test - Questions Answers, Page 3
List of questions
Question 21

Which two types of variables can you use in playbook tasks? (Choose two.)
Question 22

Refer to the exhibits.
The FortiMail Sender Blocklist playbook is configured to take manual input and add those entries to the FortiMail abc. com domain-level block list. The playbook is configured to use a FortiMail connector and the ADD_SENDER_TO_BLOCKLIST action.
Why is the FortiMail Sender Blocklist playbook execution failing7
Question 23

Which two ways can you create an incident on FortiAnalyzer? (Choose two.)
Question 24

Which statement best describes the MITRE ATT&CK framework?
Question 25

Exhibit:
Which observation about this FortiAnalyzer Fabric deployment architecture is true?
Question 26

Which FortiAnalyzer feature uses the SIEM database for advance log analytics and monitoring?
Question 27

Refer to the exhibits.
You configured a custom event handler and an associated rule to generate events whenever FortiMail detects spam emails. However, you notice that the event handler is generating events for both spam emails and clean emails.
Which change must you make in the rule so that it detects only spam emails?
Question 28

When does FortiAnalyzer generate an event?
Question 29

A customer wants FortiAnalyzer to run an automation stitch that executes a CLI command on FortiGate to block a predefined list of URLs, if a botnet command-and-control (C&C) server IP is detected.
Which FortiAnalyzer feature must you use to start this automation process?
Question 30

Refer to the exhibit.
Which two options describe how the Update Asset and Identity Database playbook is configured? (Choose two.)
Question