Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Fortinet NSE 6 - FortiSOAR 7.6 Analyst NSE6_FSR_AN-7.6 Exam Questions

Page: 1 / 8 Total 44 questions

Want more questions? Get Premium Access.

Question 1

Refer to the exhibit.

Which two statements about the recommendation engine are true? (Choose two.)

Correct Answer: B. The dataset is trained to predict the Severity and Type fields.; D. The alert severity is High, but the recommendation is for it to be set to Medium
Explanation:

The Recommendation Engine in FortiSOAR is designed to assist in alert triage by suggesting values for certain fields based on historical data and machine learning models. In this case, the engine is trained to predict both the Severity and Type fields, suggesting values that align with past incidents and threat intelligence. Although the current alert severity is High, the recommendation engine has suggested adjusting it to Medium based on the pattern of similar past alerts, indicating a less critical threat level than initially perceived. This functionality helps analysts by providing data-driven insights, which can optimize alert handling and resource allocation.


Question 2

When deleting a user account on FortiSOAR, you must enter the user ID in which file on FortiSOAR?

Correct Answer: D. usersToDelete.txt
Explanation:

When deleting a user account in FortiSOAR, the user ID must be entered into the usersToDelete.txt file. This file is specifically used to list users that are marked for deletion. Once the user IDs are listed in this file, the system can process the deletion of these accounts as part of its user management operations. This method ensures that only specified users are deleted, as referenced in FortiSOAR's administrative controls.


Question 3

Which two roles are default roles configured on FortiSOAR? (Choose two answers)

Correct Answer: A. T1 Analyst; D. Connector Administrator
Explanation:

Comprehensive and Detailed Explanation From FortiSOAR 7.3 Exact Extract study guide:

FortiSOAR comes with several pre-defined (out-of-the-box) roles designed to align with common Security Operations Center (SOC) functions. According to the FortiSOAR 7.3 Administration Guide under the 'Security Management' section:

T1 Analyst (Tier 1): This role is a default configuration intended for front-line analysts who perform initial triaging of alerts and basic incident response tasks.

Connector Administrator: This is a specialized default role that grants permissions specifically for configuring, updating, and managing the lifecycle of connectors within the environment.

While FortiSOAR is highly customizable and allows for the creation of T2 or T3 roles, they are not always present as specific 'default' named roles in the same way the T1 Analyst is across all base installations. Furthermore, 'FortiSOAR Agent' refers to a technical component or a deployment architecture rather than a standard user RBAC (Role-Based Access Control) role. Other common default roles include Security Administrator, Application Administrator, and Full Access.


Question 4

Which two statements about upgrading a FortiSOAR HA cluster are true7 (Choose two.)

Correct Answer: C. The upgrade procedure for an active-active cluster and an active-passive cluster are the same.; D. It is recommended that the passive secondary node be upgraded first, and then the active primary node.
Explanation:

Upgrading a FortiSOAR HA cluster follows the same procedure regardless of whether it is configured in an active-active or active-passive setup. The process generally involves upgrading one node at a time to minimize service disruption. Best practices recommend upgrading the passive secondary node first before moving to the active primary node. This sequence helps maintain cluster stability and ensures that at least one node remains operational during the upgrade.


Question 5

Which two statements about FortiSOAR virtual instance deployment requirements are true? (Choose two.)

Correct Answer: A. FortiSOAR Cloud is a subscription service that allows you to deploy an instance hosted on FortlCloud.; C. FortiSOAR is supported on VMWare ESXi and Amazon Web Services (AWS).
Explanation:

FortiSOAR offers flexibility in deployment environments, including FortiSOAR Cloud, which is a subscription service that enables hosting on FortiCloud. This provides cloud-hosted management with scalable resources. Additionally, FortiSOAR supports deployment on VMware ESXi and Amazon Web Services (AWS), allowing organizations to choose based on their infrastructure preferences. This flexibility ensures that FortiSOAR can be integrated into various IT environments depending on business needs.


Question 6

What are two system-level logs that can be purged using application configuration? (Choose two.)

Correct Answer: C. Audit togs; D. Executed Playbook logs
Explanation:

In FortiSOAR, system-level logs that can be purged include both 'Audit logs' and 'Executed Playbook logs.' These types of logs can be configured to be purged periodically to free up storage space and ensure that unnecessary logs do not impact system performance. The application configuration allows administrators to schedule automatic purges, which can be especially useful in high-activity environments where log data accumulates quickly. Purging these logs helps maintain a cleaner and more efficient system.