최신Fortinet NSE 7 - Security Operations 7.6 Architect - NSE7_SOC_AR-7.6무료샘플문제
문제1
Which statement best describes the MITRE ATT & CK framework?
Which statement best describes the MITRE ATT & CK framework?
정답: A
문제2
Which statement describes automation stitch integration between FortiGate and FortiAnalyzer?
Which statement describes automation stitch integration between FortiGate and FortiAnalyzer?
정답: B
설명: (KoreaDumps 회원만 볼 수 있음)
문제3
While monitoring your network, you discover that one FortiGate device is sending significantly more logs to FortiAnalyzer than all of the other FortiGate devices in the topology.
Additionally, the ADOM that the FortiGate devices are registered to consistently exceeds its quota.
What are two possible solutions? (Choose two.)
While monitoring your network, you discover that one FortiGate device is sending significantly more logs to FortiAnalyzer than all of the other FortiGate devices in the topology.
Additionally, the ADOM that the FortiGate devices are registered to consistently exceeds its quota.
What are two possible solutions? (Choose two.)
정답: B,C
설명: (KoreaDumps 회원만 볼 수 있음)
문제4
Refer to the exhibits.

Assume that the traffic flows are identical, except for the destination IP address. There is only one FortiGate in network address translation (NAT) mode in this environment.
Based on the exhibits, which two conclusions can you make about this FortiSIEM incident? (Choose two answers)
Refer to the exhibits.

Assume that the traffic flows are identical, except for the destination IP address. There is only one FortiGate in network address translation (NAT) mode in this environment.
Based on the exhibits, which two conclusions can you make about this FortiSIEM incident? (Choose two answers)
정답: B,C
설명: (KoreaDumps 회원만 볼 수 있음)
문제5
Refer to the exhibit.

A list of FortiSIEM connector actions is shown. You want to create a playbook on FortiSOAR that allows you to accomplish the following:
Manually input a range of IP addresses.
Use the connector action in the exhibit to retrieve a list of devices from the FortiSIEM configuration management database (CMDB) within that IP address range.
For each returned result, create an asset record based on the IP address of the device.
Which combination and order of step operations fulfills the requirements with the fewest required playbook steps?
Refer to the exhibit.

A list of FortiSIEM connector actions is shown. You want to create a playbook on FortiSOAR that allows you to accomplish the following:
Manually input a range of IP addresses.
Use the connector action in the exhibit to retrieve a list of devices from the FortiSIEM configuration management database (CMDB) within that IP address range.
For each returned result, create an asset record based on the IP address of the device.
Which combination and order of step operations fulfills the requirements with the fewest required playbook steps?
정답: D
설명: (KoreaDumps 회원만 볼 수 있음)
문제6
Which two statements accurately describe the process to create a new rule from a search using FortiSIEM analytics? Choose two answers.
Which two statements accurately describe the process to create a new rule from a search using FortiSIEM analytics? Choose two answers.
정답: B,D
설명: (KoreaDumps 회원만 볼 수 있음)
문제7
You are trying to create a playbook that creates a manual task showing a list of public IPv6 addresses. You were successful in extracting all IP addresses from a previous action into a variable called ip_list , which contains both private and public IPv4 and IPv6 addresses. You must now filter the results to display only public IPv6 addresses. Which two Jinja expressions can accomplish this task? (Choose two answers)
You are trying to create a playbook that creates a manual task showing a list of public IPv6 addresses. You were successful in extracting all IP addresses from a previous action into a variable called ip_list , which contains both private and public IPv4 and IPv6 addresses. You must now filter the results to display only public IPv6 addresses. Which two Jinja expressions can accomplish this task? (Choose two answers)
정답: A,B
설명: (KoreaDumps 회원만 볼 수 있음)
문제8
You created a war room and want to run a connector action to look up the reputation of a domain.
Then, you need to save the output for your team to review. However, there is a lot of output, and you want to limit the amount of information attached to the war room. How do you accomplish this?
Choose one answer.
You created a war room and want to run a connector action to look up the reputation of a domain.
Then, you need to save the output for your team to review. However, there is a lot of output, and you want to limit the amount of information attached to the war room. How do you accomplish this?
Choose one answer.
정답: A
설명: (KoreaDumps 회원만 볼 수 있음)
문제9
According to the National Institute of Standards and Technology (NIST) cybersecurity framework, incident handling activities can be divided into phases.
In which incident handling phase do you quarantine a compromised host in order to prevent an adversary from using it as a stepping stone to the next phase of an attack?
According to the National Institute of Standards and Technology (NIST) cybersecurity framework, incident handling activities can be divided into phases.
In which incident handling phase do you quarantine a compromised host in order to prevent an adversary from using it as a stepping stone to the next phase of an attack?
정답: C
설명: (KoreaDumps 회원만 볼 수 있음)
문제10
When configuring an Ingest Bulk Feed playbook step, which two restrictions must you consider? Choose two answers.
When configuring an Ingest Bulk Feed playbook step, which two restrictions must you consider? Choose two answers.
정답: A,C
설명: (KoreaDumps 회원만 볼 수 있음)