Question 6 of 27Refer to the exhibit. A SOC analyst is designing a playbook to filter for a high severity event and attach the event information to an incident. Which local connector action must the analyst use in this scenario?
Correct Answer: D
Question 7 of 27When does FortiAnalyzer generate an event?
Correct Answer: B
Question 8 of 27Refer to the exhibit. Which two options describe how the Update Asset and Identity Database playbook is configured? (Choose two.)
Correct Answer: B, C
Question 9 of 27When configuring a FortiAnalyzer to act as a collector device, which two steps must you perform? (Choose two.)
Correct Answer: C, D
Question 10 of 27Refer to the exhibit, which shows the partial output of the MITRE ATT&CK Enterprise matrix on FortiAnalyzer. Which two statements are true? (Choose two.)