ExamGecko
Home Home / Fortinet / NSE6_FSR-7.3

Fortinet NSE6_FSR-7.3 Practice Test - Questions Answers, Page 3

Question list
Search
Search

Which two ports must be open between FortiSOAR HA nodes'* (Choose two.)

A.

Port 5432

A.

Port 5432

Answers
B.

Port 25

B.

Port 25

Answers
C.

Port 6380

C.

Port 6380

Answers
D.

Port 9200

D.

Port 9200

Answers
Suggested answer: A, D

Explanation:

In a FortiSOAR HA configuration, certain ports must be open for communication between nodes. Port 5432 is required for PostgreSQL database communication, which is essential for data replication between HA nodes. Port 9200 is used by Elasticsearch, which FortiSOAR leverages for indexing and search functions across the nodes. These ports must be accessible between nodes to ensure seamless operation and data consistency within the cluster.

On FortiSOAR. which default role is used to assign privileges to other teams and is recommended to not be removed?

A.

Application Administrator

A.

Application Administrator

Answers
B.

Full App Permissions

B.

Full App Permissions

Answers
C.

Playbook Administrator

C.

Playbook Administrator

Answers
D.

Security Administrator

D.

Security Administrator

Answers
Suggested answer: A

Explanation:

In FortiSOAR, the 'Application Administrator' role is a default role that holds broad privileges, including the ability to assign permissions to other teams. This role is fundamental to system administration and is recommended not to be removed as it provides crucial administrative capabilities. Removing or modifying this role could impact FortiSOAR's ability to manage user roles and permissions effectively, which could hinder system operations and user management.

Refer to the exhibit.

How long after the syops-ha service goes down will the heartbeat missed notification be sent to the administrator?

A.

15 minutes

A.

15 minutes

Answers
B.

60 minutes

B.

60 minutes

Answers
C.

5 minutes

C.

5 minutes

Answers
D.

3 minutes

D.

3 minutes

Answers
Suggested answer: B

Explanation:

In FortiSOAR's high availability (HA) setup, if the cyops-ha service becomes unresponsive, the system is configured to send a 'heartbeat missed' notification after a specified period, which in this case is 60 minutes. This delay allows for transient issues to be resolved without triggering immediate alerts, while also ensuring that administrators are informed of prolonged service disruptions. Timely notifications about the cyops-ha service's status help maintain the reliability and responsiveness of the HA environment.

What are two features of the FortiSOAR perpetual trial license? (Choose two.).

A.

It is a multi-tenant type license.

A.

It is a multi-tenant type license.

Answers
B.

It provides access to FortiSOAR for a limited amount of time per day.

B.

It provides access to FortiSOAR for a limited amount of time per day.

Answers
C.

It has restrictions on the number of users.

C.

It has restrictions on the number of users.

Answers
D.

It has restrictions on the number of actions that can be performed.

D.

It has restrictions on the number of actions that can be performed.

Answers
Suggested answer: C, D

Explanation:

The FortiSOAR perpetual trial license includes limitations on both the number of users and the number of actions that can be performed. These restrictions are in place to provide prospective users with a functional evaluation of FortiSOAR while limiting its usage in a production environment. The trial license does not support multi-tenancy and restricts the overall capacity for scaling, making it suitable only for testing and familiarization with FortiSOAR's capabilities.

Which edition of license, when deployed, will serve as a primary node in a distributed deployment?

A.

MT

A.

MT

Answers
B.

MT_Tenant

B.

MT_Tenant

Answers
C.

MT_RegionalSOC

C.

MT_RegionalSOC

Answers
D.

Enterprise

D.

Enterprise

Answers
Suggested answer: A

Refer to the exhibit.

View the exhibit. The dataset on FortiSOAR has been trained to predict which record field?

A.

Assigned To

A.

Assigned To

Answers
B.

Status

B.

Status

Answers
C.

Playbooks

C.

Playbooks

Answers
D.

Severity

D.

Severity

Answers
Suggested answer: D

Which three roles are defined as SAML roles?

(Choose three.)

A.

Service provider

A.

Service provider

Answers
B.

Role

B.

Role

Answers
C.

Identity provider

C.

Identity provider

Answers
D.

Attribute map

D.

Attribute map

Answers
E.

Principal

E.

Principal

Answers
Suggested answer: A, C, E

The Create Record and Update Record steps are categorized under which playbook step'

A.

Evaluate

A.

Evaluate

Answers
B.

Execute

B.

Execute

Answers
C.

Core

C.

Core

Answers
D.

Reference

D.

Reference

Answers
Suggested answer: C

Explanation:

In FortiSOAR playbooks, the 'Create Record' and 'Update Record' steps are categorized under the 'Core' category of playbook steps. Core steps are essential actions that are frequently used in playbooks to interact with records in the FortiSOAR database. They include fundamental operations such as creating, reading, updating, or deleting records within modules. These steps are crucial for the automation of tasks such as data management, where playbooks need to create new entries or update existing data as part of incident response workflows.

When configuring the system proxy on FortiSOAR. which two URLs should be accessible from the proxy server? (Choose two.)

A.

https://fortiguard.coin

A.

https://fortiguard.coin

Answers
B.

https: //licensing, fortinet .net

B.

https: //licensing, fortinet .net

Answers
C.

https://iepo.fortisoar.fcrtinet.ccm

C.

https://iepo.fortisoar.fcrtinet.ccm

Answers
D.

https://globalupdate.fortinet.net

D.

https://globalupdate.fortinet.net

Answers
Suggested answer: C, D

Explanation:

When configuring the system proxy for FortiSOAR, it is essential to ensure connectivity to certain URLs to maintain system updates and licensing. For FortiSOAR, access to https://iepo.fortisoar.fortinet.com is required for incident enrichment and analysis, while https://globalupdate.fortinet.net is necessary for global updates to keep the system up-to-date with the latest threat information. These connections allow FortiSOAR to communicate with Fortinet's servers to fetch updated threat intelligence and system updates, which are critical for the operational effectiveness of FortiSOAR.

What are two different services that you can configure for monitoring system and cluster health statuses on FortiSOAR?

(Choose two.)

A.

Exchange

A.

Exchange

Answers
B.

POP

B.

POP

Answers
C.

IMAP

C.

IMAP

Answers
D.

SMTP

D.

SMTP

Answers
Suggested answer: A, D
Total 39 questions
Go to page: of 4