Summer Special Sale - 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: best70

Page: 1 / 3
Total 27 questions
Exam Code: NSE7_SOC_AR-7.6                Update: Jul 29, 2026
Exam Name: Fortinet NSE 7 - Security Operations 7.6 Architect

Fortinet Fortinet NSE 7 - Security Operations 7.6 Architect NSE7_SOC_AR-7.6 Exam Dumps: Updated Questions & Answers (July 2026)

Question # 1

Refer to the exhibit.

Which method most effectively reduces the attack surface of this organization? (Choose one answer)

A.

Forward all firewall logs to the security information and event management (SIEM) system.

B.

Enable deep inspection on firewall policies.

C.

Implement macrosegmentation.

D.

Remove unused devices.

Question # 2

Which statement best describes the MITRE ATT & CK framework?

A.

It provides a high-level description of common adversary activities, but lacks technical details

B.

It covers tactics, techniques, and procedures, but does not provide information about mitigations.

C.

It describes attack vectors targeting network devices and servers, but not user endpoints.

D.

It contains some techniques or subtechniques that fall under more than one tactic.

Question # 3

Which three are threat hunting activities? (Choose three answers)

A.

Enrich records with threat intelligence.

B.

Automate workflows.

C.

Generate a hypothesis.

D.

Perform packet analysis.

E.

Tune correlation rules.

Question # 4

A partner organization recently suffered a distributed denial-of-service (DDoS) attack, but the adversary’s identity and TTPs remain unknown. Your SOC has not received any relevant threat intelligence from the partner organization, but you are asked to determine whether similar activity could be happening in your environment. Which threat hunting action should you perform first? Choose one answer.

A.

Configure SIEM rules to alert when inbound traffic exceeds baseline thresholds.

B.

Use a packet analyzer to capture and review all traffic flows on critical devices.

C.

Develop a hunting hypothesis based on how DDoS can be executed against your network.

D.

Use threat intelligence to enrich the IP addresses of all external source IP addresses.

Question # 5

Which three factors does the FortiSIEM rules engine use to determine the count when it evaluates the aggregate condition COUNT (Matched Events) on a specific subpattern? (Choose three answers)

A.

Group By attributes

B.

Data source

C.

Time window

D.

Search filter

E.

Incident action

Question # 6

Refer to the exhibits.

Assume that the traffic flows are identical, except for the destination IP address. There is only one FortiGate in network address translation (NAT) mode in this environment.

Based on the exhibits, which two conclusions can you make about this FortiSIEM incident? (Choose two answers)

A.

The client 10.200.3.219 is conducting active reconnaissance.

B.

FortiGate is not routing the packets to the destination hosts.

C.

The destination hosts are not responding.

D.

FortiGate is blocking the return flows.

Question # 7

Using the default data ingestion wizard in FortiSOAR, place the incident handling workflow from FortiSIEM to FortiSOAR in the correct sequence. Select each workflow component in the left column, hold and drag it to a blank position in the column on the right. Place the four correct workflow components in order, placing the first step in the first position at the top of the column.

Question # 8

Review the incident report:

Packet captures show a host maintaining periodic TLS sessions that imitate normal HTTPS traffic but run on TCP 8443 to a single external host. An analyst flags the traffic as potential command-and-control. During the same period, the host issues frequent DNS queries with oversized TXT payloads to an attacker-controlled domain, transferring staged files.

Which two MITRE ATT & CK techniques best describe this activity? (Choose two answers)

A.

Non-Standard Port

B.

Exploitation of Remote Services

C.

Exfiltration Over Alternative Protocol

D.

Hide Artifacts

Question # 9

Refer to the exhibit.

What are the two mistakes in the incident subpattern rule configuration? Choose two answers.

A.

The subpattern is missing a time window definition.

B.

The aggregate operator is incorrect.

C.

The Group By attributes conflict with each other.

D.

The mandatory Event Type attribute is missing.

Question # 10

You suspect your organization has been a victim of numerous incidents carried out by the same threat actor. Which option allows you to group the incidents and track them? Choose one answer.

A.

Add a common tag to correlate them.

B.

Mark one incident as the parent and run a playbook to close the child incidents.

C.

Select those incidents and use the Merge function.

D.

Create a campaign and link related records to it.

Page: 1 / 3
Total 27 questions

Most Popular Certification Exams

Payment

       

Contact us

Site Secure

mcafee secure

TESTED 29 Jul 2026