Fortinet NSE 7 - Security Operations 7.6 Architect - NSE7_SOC_AR-7.6 FREE EXAM DUMPS QUESTIONS & ANSWERS
Packet captures show a host maintaining periodic TLS sessions that imitate normal HTTPS traffic but run on TCP 8443 to a single external host. An analyst flags the traffic as potential command-and-control. During the same period, the host issues frequent DNS queries with oversized TXT payloads to an attacker-controlled domain, transferring staged files.
Which two MITRE ATT&CK techniques best describe this activity? (Choose two answers)
Which two MITRE ATT&CK techniques best describe this activity? (Choose two answers)
Correct Answer: B,D
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
Refer to the exhibits.

How is the investigation and remediation output generated on FortiSIEM? (Choose one answer)

How is the investigation and remediation output generated on FortiSIEM? (Choose one answer)
Correct Answer: A
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
Refer to the exhibits.

What can you conclude from analyzing the data using the threat hunting module?

What can you conclude from analyzing the data using the threat hunting module?
Correct Answer: B
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
Which three are threat hunting activities? (Choose three answers)
Correct Answer: B,C,D
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
Refer to the exhibit.

You are reviewing the Triggering Events page for a FortiSIEM incident. You want to remove the Reporting IP column because you have only one firewall in the topology. How do you accomplish this? (Choose one answer)

You are reviewing the Triggering Events page for a FortiSIEM incident. You want to remove the Reporting IP column because you have only one firewall in the topology. How do you accomplish this? (Choose one answer)
Correct Answer: C
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
Which two types of variables can you use in playbook tasks? (Choose two.)
Correct Answer: A,C
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).