Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Fortinet logo

FortinetNSE 6 - FortiSIEM Analyst

Domain 2Objective 3

Configure Playbooks NSE6-FORTISIEM-ANALYST Practice Questions (Page 2)

Part of the FortiEDR Security Settings and Policies domain, which makes up ~24% of our current practice bank. Fortinet does not publish an official question count, but from its 70-minute exam (~30–45 total, ~7–11 in this domain), expect 2–3 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)

25questions here
5free pages
7concepts

Questions 6–10

  1. 6expert · hard

    An organization has a playbook that responds to 'data exfiltration' events. The current flow is: 1) Block the user's network access, 2) Send an email to the security team, 3) Create a ticket. The security team has found that blocking network access before verifying the event is too aggressive and causes business disruption. They want to change the flow so that a ticket is created first, then the security team manually reviews and decides whether to block access. The email should be sent only after the block action is manually approved and executed. How should the analyst modify the playbook?

    Select an answer first
  2. 7application · medium

    A playbook is triggered by a 'malware detected' event. The first action is to enrich the event with threat intelligence data. The next action should only run if the enrichment result indicates the file is malicious. The analyst has added the enrichment action and is now adding the next action. What should the analyst configure to ensure the next action only runs under the specified condition?

    Select an answer first
  3. 8foundation · easy

    What is the purpose of an action in a FortiSIEM playbook?

    Select an answer first
  4. 9application · easy

    A junior analyst is learning about FortiSIEM playbooks and asks a senior analyst: 'What is the primary purpose of a playbook in our incident response process?' The senior analyst should respond that a playbook is used to:

    Select an answer first
  5. 10application · easy

    An analyst is creating a new playbook to handle 'user lockout' events. The analyst wants to ensure the playbook is easily identifiable in the list of playbooks and that it is not active until fully configured. What should the analyst do during the creation process?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Fortinet. “NSE6-FORTISIEM-ANALYST” is a trademark of its owner, used for identification only.