
FortinetNSE 6 - FortiSOAR Analyst
Domain 3Objective 4
Correlate Records Across Modules NSE6-FORTISOAR-ANALYST Practice Questions (Page 3)
Part of the Incident Handling domain, which accounts for 5-15% of the NSE6-FORTISOAR-ANALYST exam.
14questions here
3free pages
3concepts
5-15%of the exam
Questions 11–14
- 11
A SOC analyst is investigating a phishing email that delivered a malicious attachment. In FortiSOAR, the analyst has already created an alert for the email and an indicator record for the attachment's hash. The analyst now wants to ensure that when the alert is viewed, the related indicator is immediately visible and traceable. What should the analyst do?
Select an answer first - 12
A security team is handling a ransomware incident. The incident commander wants to track which phase each containment action belongs to. In FortiSOAR, what is the most efficient way to associate tasks with the appropriate incident response phase?
Select an answer first - 13
During an incident, the incident commander wants to ensure that all evidence collected is associated with the correct response phase. In FortiSOAR, what is the recommended way to achieve this?
Select an answer first - 14
An analyst is working on an incident and discovers a new indicator of compromise (IOC) that is also relevant to another open incident. What is the best way to ensure both incidents benefit from this IOC?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to NSE6-FORTISOAR-ANALYST
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Fortinet. “NSE6-FORTISOAR-ANALYST” is a trademark of its owner, used for identification only.