Skip to content

NSE6-FSR-7-3 Fortinet NSE 6 - FortiSOAR 7.3 Administrator Practice Questions

Prepare for NSE6-FSR-7-3 with more than an answer.

214 questions in the full set20 sample questionsUpdated Jan 25, 2026
Exam fee
$200 USD
Level
Solution Specialist (FCSS)
Valid for
3 years
Domains covered on the exam 5
  1. SOC and SOAR Overview20%
  2. System Configuration25%
  3. Security Management25%
  4. System Operation15%
  5. System Monitoring and Maintenance15%
  1. 1

    Case Study: Global Retailer FortiSOAR Deployment

    Company Background:
    A large, multinational retail corporation, 'GlobalMart', has recently deployed FortiSOAR 7.3 to centralize its security operations. They have SOC teams located in three regions: North America (NA), Europe (EU), and Asia-Pacific (APAC). Each regional SOC handles incidents originating from their respective geographical areas. A global 'Threat Intel' team is responsible for creating and managing enrichment playbooks that all regions use.

    Current Situation:
    The initial deployment was set up with a single, flat structure. All analysts from all regions have the same role and can see all incidents, leading to confusion and potential data privacy violations under GDPR for the EU team. The Threat Intel team is currently unable to create and test playbooks without having access to live incident data, which violates their policy of separation of duties.

    Requirements:

    1. Enforce strict data segregation so that regional SOC teams can only access incidents relevant to their own region.
    2. The NA SOC has a senior team (L2) that should be able to view, but not modify, incidents in the EU and APAC queues for situational awareness.
    3. The Threat Intel team needs a dedicated, isolated environment to develop and test playbooks without accessing any production incident data.
    4. A global CISO role must have read-only visibility into all incidents across all regions for reporting purposes.

    Problem:
    Which FortiSOAR configuration strategy best meets all of GlobalMart's requirements?

    Show answer details

    Correct answer: C

    This solution correctly uses the Teams and Team Hierarchy feature. Creating a parent/child structure allows the NA L2 team, when assigned to the Parent SOC, to view incidents in child teams (EU, APAC). Creating a separate, isolated team for Threat Intel achieves the required separation for playbook development. A global CISO role assigned at the parent level provides the necessary cross-region visibility. Full multi-tenancy is too rigid and doesn't allow for the required cross-team visibility for the NA L2 and CISO roles. Using only roles without teams cannot enforce the regional data segregation.

  2. 2

    The System Monitoring widget on the FortiSOAR dashboard shows a persistent 95% CPU usage. An administrator needs to identify which specific process is consuming the most resources. Which command should be run from the appliance's shell to get a real-time, interactive view of running processes sorted by CPU consumption?

    Show answer details

    Correct answer: C

    The top command is a standard Linux utility that provides a dynamic, real-time view of a running system's processes. It can be sorted by various metrics, including CPU usage (which it is by default), making it the ideal tool for identifying which specific process is causing high CPU load. csadm services --status shows if services are running, not their resource usage. df -h shows disk space. netstat shows network connections.

  3. 3

    A FortiSOAR deployment requires a new license file to be applied. What is the recommended method for uploading and activating the new license?

    Show answer details

    Correct answer: B

    The standard and recommended procedure for managing the FortiSOAR license is through the graphical user interface. The License Manager page under the Settings module provides a simple interface to upload a new license file and view the current license status.

  4. 4

    Which three of the following actions can be performed from within the FortiSOAR War Room? (Choose three.)

    Show answer details

    Correct answer: A, B, D

    The War Room is a collaborative investigation hub. From within it, analysts can execute connector commands (e.g., query a SIEM), tag the results as evidence to link them to the incident timeline, and communicate with other team members in real-time. Modifying RBAC is an administrative function done outside the War Room. Creating new connectors is also an admin task.

  5. 5

    An administrator needs to create a new role for contractors that allows them to view and comment on incidents, but prevents them from executing any playbooks or deleting records. Where in the FortiSOAR UI would the administrator configure these specific permissions?

    Show answer details

    Correct answer: B

    Role definitions, which control what actions users can perform, are managed in the Security > Roles module. Here, an administrator can create a new role and granularly define its permissions for each module (e.g., granting Read and Update for Incidents but not Delete), and also explicitly deny permissions for Playbook execution.

  6. 6

    A FortiSOAR administrator is tasked with integrating a new threat intelligence platform that requires communication through a corporate forward proxy. The proxy requires authentication. After configuring the proxy settings in the FortiSOAR UI, the connector still fails to connect. Which command-line utility should the administrator use to verify and troubleshoot the proxy connectivity from the FortiSOAR appliance's shell?

    Show answer details

    Correct answer: B

    The curl command is the most effective and standard Linux utility for testing network connectivity through a proxy from the command line. It allows specifying proxy credentials and the destination URL, providing a direct way to confirm if the FortiSOAR appliance can reach the external service through the configured proxy, independent of the connector's specific implementation. csadm proxy --test is not a valid command. ping does not support proxy settings. systemctl status secure-gateway checks the service status, not connectivity through it.

  7. 7

    A security architect is designing a multi-tiered role-based access control (RBAC) model for a global SOC. The requirements state that Level 1 (L1) analysts should only see incidents assigned to their specific regional team and should not be able to view sensitive PII fields within those incidents. What two FortiSOAR features are essential to implement this granular access control? (Choose two.)

    Show answer details

    Correct answer: A, B

    To meet the requirements, Teams must be used to segregate incidents by region, ensuring L1 analysts can only view records assigned to their team. Field-Level Permissions are then applied to the L1 analyst role to hide or make read-only specific sensitive fields like PII. System Fixtures are for system-wide settings, and Playbook Permissions control who can execute or modify playbooks, neither of which directly address the specified record and field visibility requirements.

  8. 8

    During a routine audit, an administrator discovers that a junior analyst was able to view and modify a high-severity financial fraud incident they should not have had access to. The analyst is part of the 'Tier 1 SOC' team, which has restricted permissions. What is the most likely reason for this unintended access?

    Show answer details

    Correct answer: B

    In FortiSOAR, the 'Owner' of a record implicitly gets full CRUD (Create, Read, Update, Delete) permissions on that specific record, which overrides the standard team and role-based permissions. If a senior analyst accidentally assigned ownership of the high-severity incident to the junior analyst, it would grant them the unintended access described. The other options are less likely to grant full modification rights that bypass team restrictions.

  9. 9

    A FortiSOAR administrator needs to perform a version upgrade from 7.3.0 to 7.3.1. To ensure system integrity and minimize downtime, they must follow the correct procedure. Which of the following represents the correct, high-level sequence of steps for performing the upgrade?

    flowchart TD A[Start] --> B{Take VM Snapshot / Backup}; B --> C{Download Upgrade Package}; C --> D{Run Pre-check Script}; D --> E{Execute Upgrade Script}; E --> F{Reboot System}; F --> G[End];
    Show answer details

    Correct answer: B

    The correct and safest procedure is to first create a backup or VM snapshot to allow for rollback. Then, the upgrade package must be downloaded and extracted (typically in /tmp). Finally, the upgrade.sh script is executed to perform the upgrade. This sequence ensures a recovery point exists before any system changes are made.

  10. 10

    True or False: When FortiSOAR is configured in a High Availability (HA) cluster, playbooks are automatically synchronized and executed on the active node only.

    Show answer details

    Correct answer: A

    This statement is true. In a standard FortiSOAR active-passive HA cluster, all data, configurations, and playbooks are replicated to the passive node, but active processing and playbook execution only occur on the active node. If a failover occurs, the passive node becomes active and takes over these responsibilities.

Create an account to continue.