
FortinetNSE 6 - FortiSOAR Analyst
Domain 2Objective 3
Analyze Basic JSON Query and YAQL Statements NSE6-FORTISOAR-ANALYST Practice Questions (Page 2)
Part of the Playbook Development domain, which accounts for 25-35% of the NSE6-FORTISOAR-ANALYST exam.
8questions here
2free pages
3concepts
25-35%of the exam
Questions 6–8
- 6
A playbook has a list of alert objects with 'type' and 'count' fields. The analyst needs to calculate the TOTAL count of all alerts where type equals 'Malware'. Which YAQL expression should be used?
Select an answer first - 7
Which YAQL statement transforms a list of incident objects to a list of their 'id' values?
Select an answer first - 8
A playbook receives a webhook payload that may contain either a single object or an array of objects under the 'data' key. The analyst needs to extract the 'id' field from the first object regardless of the structure. The playbook must handle both cases without failing. Which approach is most robust?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to NSE6-FORTISOAR-ANALYST
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Fortinet. “NSE6-FORTISOAR-ANALYST” is a trademark of its owner, used for identification only.