FCSS-SOC-AN-7-4 Fortinet FCSS - Security Operations 7.4 Analyst Practice Questions
Prepare for FCSS-SOC-AN-7-4 with more than an answer.
- Exam fee
- $400 USD
- Level
- Solution Specialist
- Valid for
- 2 years
Domains covered on the exam 4
- SOC Concepts and Adversary Behavior25%
- Architecture and Detection Capabilities30%
- SOC Operation25%
- SOC Automation20%
- 1
During an incident investigation, a SOC analyst identifies a malicious domain that was used for command and control (C2). The analyst wants to quickly determine which internal hosts have attempted to resolve this domain in the past 7 days. Which log type in FortiAnalyzer should be queried to find this information?
Show answer details
Correct answer: C
DNS logs specifically record DNS queries and responses processed by the FortiGate's DNS filter. To find which internal hosts tried to resolve a malicious domain, the analyst should query the DNS logs, filtering for the specific domain name in the 'query' field. This will reveal the source IP addresses of the clients that made the requests.
- 2
A FortiAnalyzer is configured in a Security Fabric with multiple downstream FortiGate devices. A security administrator wants to create a single report that shows the top web users across all FortiGate devices in the Fabric. What must be configured to achieve this?
Show answer details
Correct answer: B
To generate consolidated reports that include data from multiple devices in a Security Fabric, those devices must be part of a special 'Fabric' type ADOM. This ADOM type enables the FortiAnalyzer to treat the logs from all member devices as a single, unified dataset, allowing for cross-device reporting and analysis.
- 3
Which three of the following are valid trigger types for a FortiAnalyzer playbook? (Select THREE).
Show answer details
Correct answer: A, B, C
FortiAnalyzer playbooks can be initiated in three ways: automatically in response to an event handler (Event-based), at a predefined time or interval (Scheduled), or by a SOC analyst on-demand from an incident or event view (Manual). User-based triggers are not a standard type.
- 4
What is the primary purpose of defining an 'Outbreak Alert' in FortiAnalyzer?
Show answer details
Correct answer: C
Outbreak Alerts are a threat hunting feature linked to FortiGuard Labs. When FortiGuard identifies a new, widespread, and high-risk threat (an 'outbreak'), they can push IOCs to FortiAnalyzer. The Outbreak Alert feature then automatically scans historical logs for these new IOCs, allowing organizations to determine if they were compromised by the threat before it was widely known.
- 5
A company has two data centers, East and West. They have deployed a FortiAnalyzer in Collector mode in the West data center and an Analyzer in the East data center. The Collector is configured to forward all logs to the Analyzer. An administrator at the West data center needs to run a report on traffic originating only from the West data center devices. Where must this report be generated?
graph TD subgraph West_DC FGT_W[FortiGate West] FAZ_C(FAZ Collector) end subgraph East_DC FGT_E[FortiGate East] FAZ_A(FAZ Analyzer) end FGT_W --> FAZ_C FGT_E --> FAZ_A FAZ_C -- Logs --> FAZ_AShow answer details
Correct answer: B
A FortiAnalyzer in Collector mode does not have the analytics engine required to generate reports. Its primary function is to collect and forward logs. All reporting and analysis must be performed on the device in Analyzer mode. To get a report for only the West devices, the administrator would log into the East Analyzer and create a report that includes a device filter for the West FortiGate.
- 6
A SOC analyst at a large financial institution is designing a FortiAnalyzer playbook to automate the initial response to a critical 'Potential Ransomware Activity' event. The playbook must first isolate the affected endpoint using a FortiGate connector, then retrieve the process hash from the event logs, and finally submit this hash to a third-party sandboxing service for deep analysis. Which playbook task sequence represents the most logical and effective workflow for this scenario?
Show answer details
Correct answer: B
The most effective workflow prioritizes containment. First, quarantine the endpoint to prevent the potential ransomware from spreading (Containment). Second, retrieve the necessary artifact (the process hash) for investigation. Finally, submit the hash to the sandbox for detailed analysis to confirm the threat and inform further response actions. Performing these steps out of order could allow the threat to propagate or lead to analysis of an incorrect artifact.
- 7
A threat hunter is using FortiAnalyzer's advanced search capabilities to proactively search for signs of lateral movement within the network. The hunter suspects an attacker is using PsExec for remote command execution. Which two of the following search queries would be most effective for identifying this specific activity? (Select TWO).
Show answer details
Correct answer: A, C
PsExec operates by creating a temporary Windows service named
PSEXESVCon the target machine. Searching for the creation of this service is a primary indicator of PsExec usage. Additionally, monitoring for the execution of thepsexec.exeprocess itself, especially by non-administrative or unexpected user accounts, is a direct way to detect its initiation. The other options are too generic; port 80 traffic is common web traffic, and DNS queries formicrosoft.comare normal. - 8
True or False: In a high-availability (HA) cluster of two FortiAnalyzer units, if the primary unit fails, a playbook that was in the middle of execution will be seamlessly migrated to the secondary unit and continue from the exact task where it left off.
Show answer details
Correct answer: B
While FortiAnalyzer HA provides redundancy for logging and reporting, it does not support stateful failover for in-flight playbook executions. If the primary unit fails, any playbook currently running will be terminated. Once the secondary unit becomes active, new playbook triggers will be processed, but the state of the previously running playbook is lost.
- 9
A junior SOC analyst observes an event in FortiAnalyzer indicating a successful user login from an IP address geolocated in a country where the company has no employees. This is followed by the creation of a new administrative account. According to the MITRE ATT&CK framework, which two tactics are most clearly demonstrated by this sequence of events? (Select TWO).
Show answer details
Correct answer: A, C
The successful login from an unexpected foreign IP address represents the adversary gaining a foothold in the network, which maps to the 'Initial Access' tactic. The subsequent creation of a new administrative account is a classic technique for maintaining long-term access, which falls under the 'Persistence' tactic.
- 10
A retail company is expanding its FortiAnalyzer deployment to handle logs from new stores. The current setup consists of a single FortiAnalyzer in analyzer mode at the headquarters. The new stores have unstable WAN connections. The company requires centralized analysis and reporting at HQ but needs to ensure logs are not lost during WAN outages at the store level. What is the most appropriate architectural change?
Show answer details
Correct answer: C
Deploying a FortiAnalyzer in collector mode at each store addresses the primary requirement. The collector will receive and store logs locally from the store's devices. This prevents log loss during WAN outages. When the connection is stable, it will reliably forward the stored logs to the central analyzer at HQ for unified analysis and reporting. This distributed model is ideal for environments with unreliable WAN links.
