Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Fortinet FCSS_SOC_AN-7.4 Practice Exam with Questions & Answers

Questions 1

Refer to the exhibits.

FCSS_SOC_AN-7.4 Question 1

What can you conclude from analyzing the data using the threat hunting module?

Options:
A.

Spearphishing is being used to elicit sensitive information.

B.

DNS tunneling is being used to extract confidential data from the local network.

C.

Reconnaissance is being used to gather victim identityinformation from the mail server.

D.

FTP is being used as command-and-control (C&C) technique to mine for data.

Fortinet FCSS_SOC_AN-7.4 Premium Access
Questions 2

Which three end user logs does FortiAnalyzer use to identify possible IOC compromised hosts? (Choose three.)

Options:
A.

Email filter logs

B.

DNS filter logs

C.

Application filter logs

D.

IPS logs

E.

Web filter logs

Questions 3

Refer to the exhibit.

FCSS_SOC_AN-7.4 Question 3

You notice that the custom event handler you configured to detect SMTP reconnaissance activities is creating a large number of events. This is overwhelming your notification system.

How can you fix this?

Options:
A.

Increase the trigger count so that it identifies and reduces the count triggered by a particular group.

B.

Disable the custom event handler because it is not working as expected.

C.

Decrease the time range that the custom event handler covers during the attack.

D.

Increase the log field value so that it looks for more unique field values when it creates the event.

Questions 4

A customer wants FortiAnalyzer to run an automation stitch that executes a CLI command on FortiGate to block a predefined list of URLs, if a botnet command-and-control (C&C) server IP is detected.

Which FortiAnalyzer feature must you use to start this automation process?

Options:
A.

Playbook

B.

Data selector

C.

Event handler

D.

Connector

Questions 5

Your company is doing a security audit To pass the audit, you must take an inventory of all software and applications running on all Windows devices

Which FortiAnalyzer connector must you use?

Options:
A.

FortiClient EMS

B.

ServiceNow

C.

FortiCASB

D.

Local Host

Questions 6

Refer to Exhibit:

FCSS_SOC_AN-7.4 Question 6

A SOC analyst is creating the Malicious File Detected playbook to run when FortiAnalyzer generates a malicious file event. The playbook must also update the incident with the malicious file event data.

What must the next task in this playbook be?

Options:
A.

A local connector with the action Update Asset and Identity

B.

A local connector with the action Attach Data to Incident

C.

A local connector with the action Run Report

D.

A local connector with the action Update Incident

Questions 7

Refer to the exhibit.

FCSS_SOC_AN-7.4 Question 7

Which two options describe how the Update Asset and Identity Database playbook is configured? (Choose two.)

Options:
A.

The playbook is using a local connector.

B.

The playbook is using a FortiMail connector.

C.

The playbook is using an on-demand trigger.

D.

The playbook is using a FortiClient EMS connector.

Questions 8

Refer to the exhibits.

FCSS_SOC_AN-7.4 Question 8

The DOS attack playbook is configured to create an incident when an event handler generates a denial-of-ser/ice (DoS) attack event.

Why did the DOS attack playbook fail to execute?

Options:
A.

The Create SMTP Enumeration incident task is expecting an integer value but is receiving the incorrect data type

B.

The Get Events task is configured to execute in the incorrect order.

C.

The Attach_Data_To_lncident task failed.

D.

The Attach_Data_To_lncident task is expecting an integer value but is receiving the incorrect data type.

Questions 9

According to the National Institute of Standards and Technology (NIST) cybersecurity framework, incident handling activities can be divided into phases.

In which incident handling phase do you quarantine a compromised host in order to prevent an adversary from using it as a stepping stone to the next phase of an attack?

Options:
A.

Containment

B.

Analysis

C.

Eradication

D.

Recovery

Exam Code: FCSS_SOC_AN-7.4
Certification Provider: Fortinet
Exam Name: FCSS - Security Operations 7.4 Analyst
Last Update: Jul 15, 2025
Questions: 32
PDF + Testing Engine
$164.99
$66
Testing Engine
$124.99
$50
PDF (Q&A)
$104.99
$42

Fortinet Free Exams

Fortinet Free Exams
Access free Fortinet exam study guides and practice tests at Examstrack. Ensure your success with top-notch preparation resources at Examstrack.