Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: cramtick70

NSE7_SOC_AR-7.6 Fortinet NSE 7 - Security Operations 7.6 Architect Questions and Answers

Questions 4

Exhibit:

Which observation about this FortiAnalyzer Fabric deployment architecture is true?

Options:

A.

The AMER HQ SOC team cannot run automation playbooks from the Fabric supervisor.

B.

The AMER HQ SOC team must configure high availability (HA) for the supervisor node.

C.

The EMEA SOC team has access to historical logs only.

D.

The APAC SOC team has access to FortiView and other reporting functions.

Buy Now
Questions 5

Which two statements accurately describe the Custom API Endpoint playbook trigger? Choose two answers.

Options:

A.

It supports token-based, basic, and no authentication.

B.

One custom API endpoint can trigger multiple playbooks at the same time.

C.

It supports HTTP POST, GET, and PUT methods.

D.

An external system can initiate a playbook using an arbitrary endpoint on FortiSOAR.

Buy Now
Questions 6

Your company is doing a security audit To pass the audit, you must take an inventory of all software and applications running on all Windows devices

Which FortiAnalyzer connector must you use?

Options:

A.

FortiClient EMS

B.

ServiceNow

C.

FortiCASB

D.

Local Host

Buy Now
Questions 7

Which FortiAnalyzer connector can you use to run automation stitches9

Options:

A.

FortiCASB

B.

FortiMail

C.

Local

D.

FortiOS

Buy Now
Questions 8

You are trying to create a playbook that uses source data from ingestion to populate the description field of a task. You successfully saved the source data to a variable called ingestion_data . Now, you must parse the results and extract a list of indicators. Which Jinja expression can accomplish this task? Choose one answer.

Options:

A.

{{ vars.ingestion_data | json_query( " [?type== ' IOC ' ] " ) }}

B.

{{ vars.ingestion_data | to_nice_json | ipaddr | hwaddr | email | hash }}

C.

{{ vars.ingestion_data | type_debug }}

D.

{{ vars.ingestion_data | extract_artifacts }}

Buy Now
Questions 9

You configured a new module named Users . Next, you want to configure a playbook that creates users from ingested data. When new records are created, you want to ensure that duplicate users do not overwrite existing user records and their fields. However, you also want the playbook to continue running even if duplicates are encountered so that any non-duplicate records are still created. Which two actions fulfill the requirements? Choose two answers.

Options:

A.

Use the Stop the create process option in the Create Record step.

B.

Ensure the Users module has record uniqueness conditions configured.

C.

Configure the Execution Mode to run in parallel.

D.

Use the Do not create new record (keep existing intact) option in the Create Record step.

Buy Now
Questions 10

You are designing a FortiSOAR hybrid multi-tenant deployment. The architecture must support remote tenant execution and automation inside segmented networks. Which three elements are true for this design? Choose three answers.

Options:

A.

The secure message exchange must be a dedicated instance instead of an embedded one.

B.

The FortiSOAR master cluster can host shared tenants, with strict data isolation between them.

C.

Each tenant or agent has a dedicated, access-controlled space on a secure message exchange for message routing.

D.

FortiSOAR tenant nodes or agents use TCP port 5671 to communicate with the secure message exchange.

E.

FortiSOAR agents are deployed on the master cluster to improve high availability (HA) performance.

Buy Now
Questions 11

Refer to the exhibit.

Which method most effectively reduces the attack surface of this organization? (Choose one answer)

Options:

A.

Forward all firewall logs to the security information and event management (SIEM) system.

B.

Enable deep inspection on firewall policies.

C.

Implement macrosegmentation.

D.

Remove unused devices.

Buy Now
Questions 12

Which two ways can you create an incident on FortiAnalyzer? (Choose two.)

Options:

A.

Using a connector action

B.

Manually, on the Event Monitor page

C.

By running a playbook

D.

Using a custom event handler

Buy Now
Questions 13

Refer to the exhibit.

What is the correct Jinja expression to filter the results to show only the MD5 hash values?

{{ [slot 1]|[slot 2] [slot 3].[slot 4] }}

Select the jinja expression in the left column, hold and drag it to a blank position on the right. Place the four correct steps in order, placing the first

step in the first slot. Once you place an expression, you can move it again if you want to change your answer before moving to the next question. You

need to drop four jinja expressions in the work area.

Select and drag the screen divider to change the viewable area of the source and work areas.

Options:

Buy Now
Questions 14

Refer to the Exhibit:

An analyst wants to create an incident and generate a report whenever FortiAnalyzer generates a malicious attachment event based on FortiSandbox analysis. The endpoint hosts are protected by FortiClient EMS integrated with FortiSandbox. All devices are logging to FortiAnalyzer.

Which connector must the analyst use in this playbook?

Options:

A.

FortiSandbox connector

B.

FortiClient EMS connector

C.

FortiMail connector

D.

Local connector

Buy Now
Questions 15

Review the incident report:

An attacker identified employee names, roles, and email patterns from public press releases, which were then used to craft tailored emails.

The emails were directed to recipients to review an attached agenda using a link hosted off the corporate domain.

Which two MITRE ATT & CK tactics best fit this report? (Choose two answers)

Options:

A.

Reconnaissance

B.

Discovery

C.

Initial Access

D.

Defense Evasion

Buy Now
Questions 16

Which two statements about the FortiAnalyzer Fabric topology are true? (Choose two.)

Options:

A.

Downstream collectors can forward logs to Fabric members.

B.

Logging devices must be registered to the supervisor.

C.

The supervisor uses an API to store logs, incidents, and events locally.

D.

Fabric members must be in analyzer mode.

Buy Now
Questions 17

You wish to use FortiAI to help you design playbooks. Which two configurations on FortiSOAR are required? Choose two answers.

Options:

A.

Train the FortiSOAR machine learning engine.

B.

Install and configure the OpenAI connector.

C.

Grant CRUD permissions to the Playbook user.

D.

Install the FortiAI solution pack and run the configuration wizard.

Buy Now
Questions 18

Which two ways can you create an incident on FortiAnalyzer? (Choose two answers)

Options:

A.

Using a custom event handler

B.

Using a connector action

C.

Manually, on the Event Monitor page

D.

By running a playbook

Buy Now
Questions 19

Which statement best describes the MITRE ATT & CK framework?

Options:

A.

It provides a high-level description of common adversary activities, but lacks technical details

B.

It covers tactics, techniques, and procedures, but does not provide information about mitigations.

C.

It describes attack vectors targeting network devices and servers, but not user endpoints.

D.

It contains some techniques or subtechniques that fall under more than one tactic.

Buy Now
Questions 20

Refer to Exhibit:

You are tasked with reviewing a new FortiAnalyzer deployment in a network with multiple registered logging devices. There is only one FortiAnalyzer in the topology.

Which potential problem do you observe?

Options:

A.

The disk space allocated is insufficient.

B.

The analytics-to-archive ratio is misconfigured.

C.

The analytics retention period is too long.

D.

The archive retention period is too long.

Buy Now
Questions 21

Refer to the exhibits.

You configured the FortiSIEM connector on FortiSOAR. However, when you try to save the configuration, you see the error shown in the exhibit. What are two possible causes? Choose two answers.

Options:

A.

The Visibility option must be set to Public.

B.

FortiSOAR cannot reach FortiSIEM.

C.

The organization should be Super.

D.

The user credentials do not match FortiSIEM.

Buy Now
Questions 22

You created a war room and want to run a connector action to look up the reputation of a domain. Then, you need to save the output for your team to review. However, there is a lot of output, and you want to limit the amount of information attached to the war room. How do you accomplish this? Choose one answer.

Options:

A.

From the returned output, select only the output keys you want.

B.

Apply a workspace filter to show only relevant fields.

C.

Use the Investigate tab to map only the fields you want.

D.

Lower the playbook logging level before executing the connector.

Buy Now
Questions 23

When configuring a FortiAnalyzer to act as a collector device, which two steps must you perform? (Choose two.)

Options:

A.

Enable log compression.

B.

Configure log forwarding to a FortiAnalyzer in analyzer mode.

C.

Configure the data policy to focus on archiving.

D.

Configure Fabric authorization on the connecting interface.

Buy Now
Questions 24

Refer to the exhibits.

You configured a custom event handler and an associated rule to generate events whenever FortiMail detects spam emails. However, you notice that the event handler is generating events for both spam emails and clean emails.

Which change must you make in the rule so that it detects only spam emails?

Options:

A.

In the Log Type field, select Anti-Spam Log (spam)

B.

In the Log filter by Text field, type type==spam.

C.

Disable the rule to use the filter in the data selector to create the event.

D.

In the Trigger an event when field, select Within a group, the log field Spam Name (snane) has 2 or more unique values.

Buy Now
Questions 25

Refer to the exhibit.

You created a threat hunting playbook to perform a search query using the FortiSIEM connector. However, when you run the playbook, you do not see any output. Which step must you take first in your troubleshooting process?

Options:

A.

Confirm that the event logs matching your criteria exist on FortiSIEM.

B.

Configure a Set Variable step to save the output.

C.

Confirm that the FortiSIEM connector is up.

D.

Check the documentation for the input and output for the action.

Buy Now
Questions 26

Which two phases are part of the FortiSOAR incident handling process but are not phases in the NIST 800-61 Revision 2 model? Choose two answers.

Options:

A.

Preparation

B.

Confirmation

C.

Detection

D.

Identification

Buy Now
Questions 27

Which two types of variables can you use in playbook tasks? (Choose two.)

Options:

A.

input

B.

Output

C.

Create

D.

Trigger

Buy Now
Exam Code: NSE7_SOC_AR-7.6
Exam Name: Fortinet NSE 7 - Security Operations 7.6 Architect
Last Update: Aug 18, 2026
Questions: 91
NSE7_SOC_AR-7.6 pdf

NSE7_SOC_AR-7.6 PDF

$25.5  $84.99
NSE7_SOC_AR-7.6 Engine

NSE7_SOC_AR-7.6 Testing Engine

$30  $99.99
NSE7_SOC_AR-7.6 PDF + Engine

NSE7_SOC_AR-7.6 PDF + Testing Engine

$40.5  $134.99