Fortinet FCSS - Security Operations 7.4 Analyst - FCSS_SOC_AN-7.4 Exam Practice Test
Which three end user logs does FortiAnalyzer use to identify possible IOC compromised hosts? (Choose three.)
Correct Answer: A,B,C
Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
What is a key objective of managing outbreak alert handlers in a SOC?
Correct Answer: D
Vote an answer
Review the following incident report:
Attackers leveraged a phishing email campaign targeting your employees.
The email likely impersonated a trusted source, such as the IT department, and requested login credentials.
An unsuspecting employee clicked a malicious link in the email, leading to the download and execution of a Remote Access Trojan (RAT).
The RAT provided the attackers with remote access and a foothold in the compromised system.
Which two MITRE ATT&CK tactics does this incident report capture? (Choose two.)
Attackers leveraged a phishing email campaign targeting your employees.
The email likely impersonated a trusted source, such as the IT department, and requested login credentials.
An unsuspecting employee clicked a malicious link in the email, leading to the download and execution of a Remote Access Trojan (RAT).
The RAT provided the attackers with remote access and a foothold in the compromised system.
Which two MITRE ATT&CK tactics does this incident report capture? (Choose two.)
Correct Answer: B,C
Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
When configuring playbook triggers, what factor is essential to optimize the efficiency of automated responses?
Correct Answer: B
Vote an answer
Which statement describes automation stitch integration between FortiGate and FortiAnalyzer?
Correct Answer: A
Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
Exhibit:

Which observation about this FortiAnalyzer Fabric deployment architecture is true?

Which observation about this FortiAnalyzer Fabric deployment architecture is true?
Correct Answer: C
Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
Which trigger type requires manual input to run a playbook?
Correct Answer: B
Vote an answer
Refer to the exhibits.

What can you conclude from analyzing the data using the threat hunting module?

What can you conclude from analyzing the data using the threat hunting module?
Correct Answer: D
Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
What is the advantage of integrating advanced analytics in the management of events and incidents in a SOC?
Correct Answer: B
Vote an answer