Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free Fortinet NSE7_SOC_AR-7.6 Practice Exam with Questions & Answers | Set: 2

Questions 11

Which role does a threat hunter play within a SOC?

Options:
A.

investigate and respond to a reported security incident

B.

Collect evidence and determine the impact of a suspected attack

C.

Search for hidden threats inside a network which may have eluded detection

D.

Monitor network logs to identify anomalous behavior

Fortinet NSE7_SOC_AR-7.6 Premium Access
Questions 12

Refer to the exhibit.

NSE7_SOC_AR-7.6 Question 12

You are trying to find traffic flows to destinations that are in Europe or Asia, for hosts in the local LAN segment. However, the query returns no results. Assume these logs exist on FortiSIEM.

Which three mistakes can you see in the query shown in the exhibit? (Choose three answers)

Options:
A.

The null value cannot be used with the IS NOT operator.

B.

The time range must be Absolute for queries that use configuration management database (CMDB) groups.

C.

There are missing parentheses between the first row (Group: Europe) and the second row (Group: Asia).

D.

The Source IP row operator must be BETWEEN 10.0.0.0, 10.200.200.254.

E.

The logical operator for the first row (Group: Europe) must be OR.

Questions 13

An analyst prioritizes blocking IP addresses and domains from every phishing campaign. Based on the Pyramid of Pain model, which two statements accurately describe this approach? Choose two answers.

Options:
A.

It helps identify strategic weaknesses in adversary infrastructure.

B.

It imposes a high operational cost on adversaries when their attacks are detected.

C.

It focuses on observable network indicators rather than underlying attack methods.

D.

It relies on blocking indicators that adversaries can easily replace or rotate.

Questions 14

Which FortiAnalyzer connector can you use to run automation stitches9

Options:
A.

FortiCASB

B.

FortiMail

C.

Local

D.

FortiOS

Questions 15

Refer to the exhibits.

The DOS attack playbook is configured to create an incident when an event handler generates a denial-of-ser/ice (DoS) attack event.

Why did the DOS attack playbook fail to execute?

Options:
A.

The Create SMTP Enumeration incident task is expecting an integer value but is receiving the incorrect data type

B.

The Get Events task is configured to execute in the incorrect order.

C.

The Attach_Data_To_lncident task failed.

D.

The Attach_Data_To_lncident task is expecting an integer value but is receiving the incorrect data type.

Questions 16

Which three end user logs does FortiAnalyzer use to identify possible IOC compromised hosts? (Choose three answers)

Options:
A.

Web filter logs1

B.

Email filter logs

C.

DNS filter logs2

D.

Application filter logs

E.

IPS logs

Questions 17

Which statement describes automation stitch integration between FortiGate and FortiAnalyzer?

Options:
A.

An event handler on FortiAnalyzer executes an automation stitch when an event is created.

B.

An automation stitch is configured on FortiAnalyzer and mapped to FortiGate using the FortiOS connector.

C.

An event handler on FortiAnalyzer is configured to send a notification to FortiGate to trigger an automation stitch.

D.

A security profile on FortiGate triggers a violation and FortiGate sends a webhook call to FortiAnalyzer.

Questions 18

Refer to Exhibit:

You are tasked with reviewing a new FortiAnalyzer deployment in a network with multiple registered logging devices. There is only one FortiAnalyzer in the topology.

Which potential problem do you observe?

Options:
A.

The disk space allocated is insufficient.

B.

The analytics-to-archive ratio is misconfigured.

C.

The analytics retention period is too long.

D.

The archive retention period is too long.

Questions 19

You want to trigger an incident when multiple failed logins from the same host are followed by a successful login on that same host within 15 minutes. The rule must correlate all events by source IP address and user to ensure they belong to the same login sequence. Which three configurations achieve this goal? Choose three answers.

Options:
A.

Ensure both subpatterns have the same aggregate condition.

B.

Define a time window condition for each subpattern.

C.

Configure two subpatterns—one for failed logins and one for the successful login.

D.

Apply sequential logic using a FOLLOWED_BY operator between the subpatterns.

E.

Define the subpattern relationships and constraints.

Questions 20

Refer to the exhibit.

NSE7_SOC_AR-7.6 Question 20

A list of FortiSIEM connector actions is shown. You want to create a playbook on FortiSOAR that allows you to accomplish the following:

Manually input a range of IP addresses.

Use the connector action in the exhibit to retrieve a list of devices from the FortiSIEM configuration management database (CMDB) within that IP address range.

For each returned result, create an asset record based on the IP address of the device.

Which combination and order of step operations fulfills the requirements with the fewest required playbook steps?

Options:
A.

1) Connector action, 2) Create record, 3) Update record

B.

1) On create trigger, 2) Connector action, 3) Code snippet, 4) Create record

C.

1) Manual trigger, 2) Connector action, 3) Create record

D.

1) Manual trigger, 2) Set variable, 3) Connector action, 4) Create record, 5) Update record

Exam Code: NSE7_SOC_AR-7.6
Certification Provider: Fortinet
Exam Name: Fortinet NSE 7 - Security Operations 7.6 Architect
Last Update: Aug 21, 2026
Questions: 91