Question 6 of 27

Refer to the exhibit.
Exam FCSS_SOC_AN-7.4: Question 6 - Image 1
A SOC analyst is designing a playbook to filter for a high severity event and attach the event information to an incident.
Which local connector action must the analyst use in this scenario?
Answer

Suggested Answer

The suggested answer is D.

Question 7 of 27

When does FortiAnalyzer generate an event?
Answer

Suggested Answer

The suggested answer is B.

Community Votes1 vote
CMost voted
100%
Question 8 of 27

Refer to the exhibit.
Exam FCSS_SOC_AN-7.4: Question 8 - Image 1
Which two options describe how the Update Asset and Identity Database playbook is configured? (Choose two.)
Answer

Suggested Answer

The suggested answer is B, C.

Community Votes1 vote
DMost voted
100%
Question 9 of 27

When configuring a FortiAnalyzer to act as a collector device, which two steps must you perform? (Choose two.)
Answer

Suggested Answer

The suggested answer is C, D.

Question 10 of 27

Refer to the exhibit, which shows the partial output of the MITRE ATT&CK Enterprise matrix on FortiAnalyzer.
Exam FCSS_SOC_AN-7.4: Question 10 - Image 1
Which two statements are true? (Choose two.)
Answer

Suggested Answer

The suggested answer is C, D.

Community Votes1 vote
AMost voted
100%