Month End Sale Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Fortinet NSE6_FSR-7.3 Fortinet NSE 6 - FortiSOAR 7.3 Administrator Exam Practice Test

Fortinet NSE 6 - FortiSOAR 7.3 Administrator Questions and Answers

Question 1

Which two statements about Elasticsearch are true? (Choose two.)

Options:

A.

Elasticsearch allows you to store, search, and analyze huge volumes of data quickly. In near real time, and return answers in milliseconds.

B.

To change the location of your Elasticsearch instance from the local instance to a remote location, you must update the falcon. conf file.

C.

The minimum version of the Elasticsearch cluster must be 6.0.2. if you want to externalize the Elasticsearch data.

D.

The global search mechanism in FortiSOAR leverages an Elasticsearch database to achieve rapid, efficient searches across the entire record system.

Question 2

Refer to the exhibit.

Question # 2

When importing modules to FortiSOAR using the configuration wizard, what actions are applied to fields it you select Merge with Existing as the Bulk action?

Options:

A.

Existing fields are kept, new fields are added, and non-imported fields are deleted.

B.

Existing Holds are overwritten, now fields are added, and non-imported fields are deleted.

C.

Existing fields are kept, new fields are added, and non-imported fields are kept.

D.

Existing fields are overwritten, new fields are added, and non-Imported fields are kept.

Question 3

An administrator wants to collect and review all FortiSOAR log tiles to troubleshoot an issue. Which two methods can they use to accomplish this? (Choose two.)

Options:

A.

Enter the csacta services —status command, and then copy the output.

B.

Download the logs from the GUI.

C.

Enter the caacta log —collect directory command.

D.

Review the contents of /var/log/messages.

Question 4

Which two roles are default roles configured on FortiSOAR? (Choose two answers)

Options:

A.

T1 Analyst

B.

T3 Analyst

C.

FortiSOAR Agent

D.

Connector Administrator

Question 5

Which three features are installed with the FortiSOAR Incidence Response Content Pack? (Choose three answers)

Options:

A.

System monitoring connectors1

B.

Sample data for playbooks

C.

Sample alerts and incidents

D.

System playbooks2

E.

SLA template module

Question 6

Which two statements about appliance users are true? (Choose two.)

Options:

A.

Appliance users do not have a login ID and do not add to the license count.

B.

Appliance users represent non-human users.

C.

Appliance users use two-factor authentication for messages sent to the API.

D.

Appliance users use time-expiring tokens for primary authentication.

Question 7

The Create Record and Update Record steps are categorized under which playbook step'

Options:

A.

Evaluate

B.

Execute

C.

Core

D.

Reference

Question 8

Which three activities can be achieved using the FortiSOAR queue and shift management feature? (Choose three)

Options:

A.

Initiate shift handovers

B.

Designate a coordinator to monitor queues and shifts

C.

Generate shift leads and shift members

D.

Set up queue meeting rooms

E.

Create queue rules based on matching conditions

Question 9

Refer to the exhibit.

Question # 9

Which two statements about the recommendation engine are true? (Choose two.)

Options:

A.

There are no playbooks that can be run on the recommended alerts using the recommendation panel

B.

The dataset is trained to predict the Severity and Type fields.

C.

The recommendation engine is set to automatically accept suggestions.

D.

The alert severity is High, but the recommendation is for it to be set to Medium

Question 10

What are two system-level logs that can be purged using application configuration? (Choose two.)

Options:

A.

Connector logs

B.

Reporting logs

C.

Audit togs

D.

Executed Playbook logs

Question 11

View the exhibit:

What does the command output mean?

Question # 11

Options:

A.

The configuration to enable database externalization has not been completed.

B.

The local PostgreSQL database is disabled on the FortiSOAR instance.

C.

The local PostgreSQL database is configured on the FortiSOAR instance.

D.

There is no connectivity between the PostgreSQL databases of the primary and secondary FortiSOAR instances.

Question 12

Which three actions can be performed from within the war room? (Choose three)

Options:

A.

View graphical representation of all records linked to an incident in the Artifacts lab

B.

Change the room's status to Escalated to enforce hourly updates.

C.

Investigate issues by tagging results as evidence.

D.

Use the Task Manager tab to create, manage, assign, and track tasks.

E.

Integrate a third-party instant messenger directly into the collaboration workspace.

Question 13

What two permissions must you assign to a user to allow the purge of audit logs for all users? (Choose two answers)

Options:

A.

Delete permission on the Security module

B.

Delete permission on the Audit Log Activities module

C.

Delete permission on the People module

D.

Delete permission on the Users module