Question 6 of 38

Which three are threat hunting activities? (Choose three.)
Answer

Suggested Answer

The suggested answer is A, C, E.

Question 7 of 38

DRAG DROP -
Using the default data ingestion wizard in FortiSOAR, place the incident handling workflow from FortiSIEM to FortiSOAR in the correct sequence.
Select each workflow component in the left column, hold and drag it to a blank position on the right. Place the four correct workflow components in order, placing the first step in the first position at the top of the column. Once you place a step, you can move it again if you want to change your answer before moving to the next question. You need to drop four workflow components in the work area.
Select and drag the screen divider to change the viewable area of the source and work areas.
Exam nse7-soc-ar-7-6: Image 1
Answer

Suggested Answer

Question 8 of 38

Refer to the exhibit.
Exam nse7-soc-ar-7-6: Image 1
You are investigating an open incident and want to add records from the Tickets module, a custom module, to the visual correlation widget. Assume there are already linked ticket records to the incident.
How do you accomplish this?
Answer

Suggested Answer

The suggested answer is A.

Question 9 of 38

Refer to the exhibit.
Exam nse7-soc-ar-7-6: Image 1
You created a new playbook and executed it as a test. However, it failed to run. You want to investigate, but you do not see details about the error.
What is the reason for the lack of details?
Answer

Suggested Answer

The suggested answer is B.

Question 10 of 38

Refer to the exhibit.
Exam nse7-soc-ar-7-6: Image 1
You configured a playbook named False Positive Close, and want to run it to verify if it works. However, when you click Execute and search for the playbook, you do not see it listed.
Which two reasons could be the cause of the problem? (Choose two.)
Answer

Suggested Answer

The suggested answer is A, C.