
FortinetNSE 6 - FortiSOAR Analyst
Domain 3Objective 3
Use War Rooms for Incident Handling NSE6-FORTISOAR-ANALYST Practice Questions (Page 3)
Part of the Incident Handling domain, which accounts for 5-15% of the NSE6-FORTISOAR-ANALYST exam.
24questions here
5free pages
5concepts
5-15%of the exam
Questions 11–15
- 11
During an active incident, the response team is using a war room to coordinate. The incident commander wants to ensure that all team members are aware of the latest containment steps and can quickly access the relevant files. What should the team do in the war room?
Select an answer first - 12
A war room is being used for a phishing incident. The incident commander wants to add a new analyst to the war room so they can assist with the investigation. What should the analyst do?
Select an answer first - 13
An incident has been resolved, but the incident commander wants to keep the war room active for a few more days to allow for final reporting and potential follow-up questions. However, the SOC manager wants to ensure that no new activity occurs in the war room. What should the analyst do?
Select an answer first - 14
A security incident has been fully contained and eradicated. The incident commander wants to preserve the war room's discussion for future reference but no longer needs it to be active. What should the analyst do?
Select an answer first - 15
After a major incident is resolved, the incident commander wants to review the war room's activity to assess the team's response. What should the analyst do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Fortinet. “NSE6-FORTISOAR-ANALYST” is a trademark of its owner, used for identification only.