Skip to content

FCSS-ADA-AR-6-7 Fortinet FCSS Advanced Analytics 6.7 Architect Practice Questions

Prepare for FCSS-ADA-AR-6-7 with more than an answer.

208 questions in the full set20 sample questionsUpdated Dec 7, 2025
Level
Solution Specialist
Valid for
2 years
Domains covered on the exam 4
  1. Multi-Tenancy SOC Solution for MSSP25%
  2. FortiSIEM Rules and Analytics30%
  3. FortiSIEM Baseline and UEBA25%
  4. Conditions and Remediation20%
  1. 1

    What is the function of a 'Clear If' condition in a FortiSIEM rule?

    Show answer details

    Correct answer: C

    A 'Clear If' condition specifies a pattern of events that indicates the threat or issue that triggered the incident has been resolved. When FortiSIEM detects this 'clear' event pattern, it automatically changes the status of the corresponding active incident to 'cleared' or 'resolved', helping to automate the incident lifecycle and reduce analyst workload.

  2. 2

    An organization wants to use FortiSOAR to orchestrate the response to a phishing email reported by a user. Which of the following actions can be automated in a FortiSOAR playbook for this scenario? (Select THREE)

    Show answer details

    Correct answer: A, B, D

    FortiSOAR can parse email content to automatically extract indicators of compromise (IOCs) like URLs, file hashes, and IP addresses.

    Through integration with sandboxing solutions (like FortiSandbox), FortiSOAR can automate the detonation and analysis of suspicious files and links.

    With appropriate connectors and permissions, FortiSOAR can query email systems like Microsoft 365 or Exchange to find and delete or quarantine similar malicious emails across the organization.

  3. 3

    A FortiSIEM administrator has created a new baseline profile for 'User Login Activity' but finds that no baseline data is being generated. Which of the following configurations must be in place for the profile to start collecting data? (Select TWO)

    Show answer details

    Correct answer: B, C

    Creating a baseline profile does not automatically activate it. The administrator must explicitly enable the profile to start the data collection and learning process.

    FortiSIEM only collects and processes baseline data for profiles that are actively being used by at least one enabled baseline rule. Without a rule to consume the data, the system does not perform the resource-intensive baseline calculations.

  4. 4

    In FortiSIEM, the ____ is a specific type of database that is optimized for fast, real-time searching of recent event data, while older data is moved to a separate historical archive.

    Show answer details

    Correct answer: C

    The FortiSIEM EventDB is a proprietary, in-memory NoSQL event database specifically designed for extremely high-speed data ingestion and real-time analytics. It holds the most recent event data to power real-time searches and rule correlation, after which data is archived to a file-based system on disk for long-term historical searching.

  5. 5

    Case Study:

    Company Background: Global Retail Corp (GRC) is a large e-commerce company with a hybrid infrastructure. Their primary data center is on-premises, hosting critical databases and legacy applications. They also have a significant presence in a public cloud provider for their web front-end, which scales dynamically based on traffic. GRC operates under strict PCI DSS compliance requirements.

    Current Situation: GRC's existing SIEM is struggling with the volume of logs from their cloud environment and cannot effectively correlate activities between on-premises and cloud systems. They recently experienced a data breach where an attacker used compromised on-premises credentials to access sensitive customer data stored in a cloud database. The security team was slow to detect this lateral movement.

    Requirements: GRC needs a new security analytics solution that provides a unified view across their hybrid environment. The solution must support multi-tenancy to segment data from their production and development environments. It must also have strong anomaly detection capabilities to identify unusual user behavior, and it needs to automate the initial response to high-severity threats to meet PCI DSS response time requirements.

    Question: Based on the case study, which FortiSIEM and FortiSOAR architecture would be the most appropriate for Global Retail Corp?

    Show answer details

    Correct answer: C

    This architecture directly addresses all of GRC's requirements. The hybrid deployment with a cloud collector provides a unified view. The Supervisor on-premises protects critical data. Multi-tenancy handles segmentation. UEBA is the specific feature for detecting the type of lateral movement they experienced. FortiSOAR integration meets the automated response requirement for PCI DSS. This is the most comprehensive and optimal solution.

  6. 6

    A Managed Security Service Provider (MSSP) is designing a FortiSIEM deployment for a new client with strict data sovereignty requirements. The client's infrastructure is split between an on-premises data center in Canada and a public cloud environment in the UK. All logs generated in a specific region must be processed and stored within that same region. Which architectural design best meets these requirements while maintaining centralized management?

    Show answer details

    Correct answer: C

    This is the correct architecture. Collectors can be deployed in each geographic region to receive, parse, and compress logs locally. This ensures that the initial processing happens within the region. While the event data is ultimately sent to the central Supervisor for correlation and storage, this model is the standard FortiSIEM design for handling geographically distributed log sources efficiently and is the first step towards meeting sovereignty, although full sovereignty would require local supervisors. The other options are architecturally flawed: direct agent forwarding is inefficient and doesn't meet the regional processing requirement, a Supervisor/Worker split doesn't ensure logs stay local during processing, and two separate Supervisor deployments create management overhead without a unified view.

  7. 7

    A security analyst needs to create a FortiSIEM rule that detects a user logging in successfully from two different countries within a 10-minute window. Which rule components are essential for this detection logic? (Select TWO)

    Show answer details

    Correct answer: B, C

    The 'Group By' clause is necessary to correlate logon events for the same user.

    The 'HAVING' clause is used after the 'Group By' to filter the groups, in this case, keeping only the users that have logged on from more than one distinct country.

  8. 8

    An administrator at a financial institution has configured a baseline profile to monitor the number of daily failed credit card transactions for each customer. The learning period was set to 14 days. After 20 days, the baseline rule is generating a high number of false positive alerts. What is the most likely cause of the false positives?

    Show answer details

    Correct answer: B

    Baseline profiles learn 'normal' behavior during the learning period. For business cycles that have weekly or monthly patterns (like spikes in transactions at the end of a month), a 14-day period may not be sufficient. It could establish a baseline that is too low, causing normal cyclical peaks to be flagged as anomalies. Extending the learning period to capture a full business cycle (e.g., 30-45 days) would create a more accurate profile.

  9. 9

    A SOC has integrated FortiSIEM with FortiSOAR to automate responses to malware detection incidents. An analyst observes that when a malware incident is triggered in FortiSIEM, a ticket is created in FortiSOAR, but the associated playbook to isolate the endpoint fails to execute. The FortiSOAR connector test is successful. What is the most probable cause of this issue?

    Show answer details

    Correct answer: A

    FortiSOAR playbooks often require specific data points (artifacts) from the incoming alert to function correctly. If a playbook is designed to isolate a host, it will need an IP address, hostname, or MAC address as an input. If the FortiSIEM incident notification is not configured to send these specific attributes, the playbook will be triggered but will fail at the step that requires this missing information. A successful connector test only confirms connectivity, not the correctness of the data payload.

  10. 10

    True or False: In a multi-tenant FortiSIEM environment, a report created by an MSSP administrator for a specific customer organization is automatically visible to all other customer organizations.

    Show answer details

    Correct answer: B

    FortiSIEM's multi-tenancy model enforces strict data isolation between customer organizations. When an administrator creates a resource like a report and associates it with a specific organization, it is only visible to users within that organization's scope and to Super/MSSP level administrators. This role-based access control (RBAC) and organizational scoping are fundamental to the security of an MSSP offering.

Create an account to continue.