FCSS-SOC-AN-7-4 Sample Questions & Answers
Designing collector and FortiAnalyzer Fabric deployments carries the most weight, next to analyzing incidents and linking what adversaries do to MITRE ATT&CK tactics, managing event handlers and threat-hunting feeds, and automating response with playbook connectors.
Launch the full FCSS-SOC-AN-7-4 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
SOC Operation · Analyze and manage events and incidents
A SOC manager wants to create a custom dashboard in FortiAnalyzer to monitor for potential data exfiltration. The dashboard needs a chart that displays the top 10 users by the volume of data uploaded to
Cloud.Storageapplications. What is the correctdatasetthat should be used to build this chart?Show answer & explanation
Correct answer: C
The
fortiview-cloud-applications-by-userdataset is specifically designed to aggregate traffic data related to cloud application usage and group it by user. This dataset contains the necessary fields, such asuser,appcat(application category), andsentbyteorbytes, which are required to filter for 'Cloud.Storage' applications and sum the uploaded data volume per user. - Question 2Intermediate
SOC Operation · Configure and manage event handlers
An administrator configures an event handler to trigger an alert when more than 100 failed login attempts occur from a single source IP within 5 minutes. After deploying the handler, the SOC team receives numerous false positive alerts from an internal vulnerability scanner. What is the most effective way to modify the event handler to ignore the scanner while still monitoring other sources?
Show answer & explanation
Correct answer: C
The most precise and effective solution is to add a filter to the event handler's logic. By creating a filter that excludes events where the source IP (
srcip) matches the IP of the vulnerability scanner, the handler will ignore this legitimate activity. This allows the handler to remain active and continue monitoring all other sources for the suspicious behavior, effectively tuning out the noise without reducing security visibility. - Question 3Beginner
Architecture and Detection Capabilities · Configure and manage collectors and analyzers
What is the primary function of the
fazlic-op-modeCLI command on a FortiAnalyzer device?Show answer & explanation
Correct answer: B
The
fazlic-op-modecommand is used in the FortiAnalyzer CLI to switch the device's fundamental operational mode. The two primary modes are 'Analyzer', which provides full analysis, reporting, and SOC features, and 'Collector', which functions as a log aggregation and forwarding point, typically used in distributed logging architectures. - Question 4Intermediate
SOC Operation · Analyze and manage events and incidents
A SOC analyst is investigating a security incident and needs to determine if a suspicious file, identified by its SHA256 hash, has been seen anywhere else in the network over the past 30 days. The analyst has access to logs from FortiGate, FortiSandbox, and FortiClient. Which FortiAnalyzer feature provides the most efficient way to perform this cross-device search for the indicator of compromise (IOC)?
Show answer & explanation
Correct answer: B
The 'Threat Hunting' view in FortiAnalyzer's FortiSOC module is specifically designed for this purpose. It allows an analyst to search for indicators of compromise (such as file hashes, IPs, or URLs) across all logs from integrated Security Fabric devices. This provides a unified, historical view of the IOC's presence in the network, making it the most efficient method for this type of investigation.
- Question 5Intermediate
SOC Automation · Configure and manage connectors
A security architect is configuring a webhook connector in a FortiAnalyzer playbook. The purpose of this connector is to send alert details to a custom-built internal chat application. The chat application's API requires the 'Content-Type' header to be set to 'application/json'. Where in the FortiAnalyzer GUI would the architect configure this custom HTTP header for the webhook connector?
Show answer & explanation
Correct answer: C
Custom HTTP headers for connectors are defined when the connector itself is configured, not within each playbook that uses it. The correct location is under 'Incidents & Events > Automation > Connectors'. When editing or creating the webhook connector, there is a dedicated section to add custom HTTP headers (key-value pairs) that will be included in every API call made by that connector.
- Question 6Advanced
Architecture and Detection Capabilities · Design stable and efficient FortiAnalyzer deployments
Case Study:
Company Background: Global Logistics Inc. (GLI) is a multinational shipping company with a central data center and over 50 branch offices worldwide. Each branch office has a local FortiGate, and the central data center houses a high-performance FortiAnalyzer cluster running in analyzer mode.
Current Situation: GLI's SOC team, located at the data center, is struggling with visibility into threats at the branch offices. The branches are connected via MPLS links of varying quality and bandwidth. The SOC team reports significant delays in receiving logs, and during network brownouts, logs are often lost, causing compliance issues and hindering timely incident response.
Requirements: The new Head of Security Operations has mandated a new architecture to solve these issues. The key requirements are: 1) Eliminate log loss from branches during network instability. 2) Reduce non-essential log traffic over the WAN links. 3) Maintain centralized visibility and advanced threat analysis at the central SOC. 4) The solution must be managed within the existing Fortinet ecosystem.
Which solution best meets all of GLI's requirements?
Show answer & explanation
Correct answer: B
This solution addresses all requirements. Deploying collectors at each branch ensures logs are stored locally, eliminating loss during network instability (Requirement 1). The collectors can be configured with log forwarding filters to send only high-priority security logs to the central analyzer, reducing WAN traffic (Requirement 2). The central analyzer still receives the critical logs for centralized visibility and analysis (Requirement 3). The entire solution uses FortiAnalyzer collectors, keeping it within the Fortinet ecosystem (Requirement 4).
- Question 7Intermediate
SOC Concepts and Adversary Behavior · Analyze security incidents and identify adversary behaviors
A SOC analyst is reviewing an incident in FortiAnalyzer and notices that an attacker used a PowerShell command to download a file from a remote server, a technique identified as T1059.001 (PowerShell) and T1105 (Ingress Tool Transfer). What is the primary role of FortiAnalyzer in identifying this type of adversary behavior?
Show answer & explanation
Correct answer: B
FortiAnalyzer's primary role is not active blocking but centralized log collection, correlation, and analysis. To identify this behavior, it would ingest process creation logs from an endpoint agent (like FortiClient) showing PowerShell execution, and correlate them with traffic logs from a network device (like FortiGate) showing the resulting connection to the remote server. This correlation provides the full context of the attack.
- Question 8Advanced
Architecture and Detection Capabilities · Design stable and efficient FortiAnalyzer deployments
A FortiAnalyzer administrator notices that the
sqlplugindprocess is consistently consuming high CPU resources, impacting the GUI performance. Which of the following is the most likely cause and the best first step for troubleshooting?Show answer & explanation
Correct answer: C
The
sqlplugindprocess is responsible for handling the log database, including building datasets for reports and FortiView. High CPU usage is often caused by poorly optimized or overly complex custom reports and charts that trigger long-running database queries. The best first step is to use the CLI diagnostic commands (diagnose sql statusanddiagnose test application sqlplugind) to identify which specific queries are causing the high load, and then optimize the corresponding report or dataset. - Question 9Beginner
SOC Automation · Manage playbook templates
True or False: When a playbook template is imported into FortiAnalyzer, it is immediately activated and will trigger on matching events without any further configuration.
Show answer & explanation
Correct answer: B
Importing a playbook template only adds it to the library of available playbooks. To make it operational, an analyst must create a new playbook from the template, configure its specific trigger conditions (such as linking it to a specific event handler), assign any required connectors, and then explicitly enable it.
- Question 10Intermediate
SOC Automation · Configure playbook triggers and tasks
A security analyst needs to create a playbook that performs a different set of actions based on the severity of an incoming incident. For incidents with 'critical' severity, the playbook should open a ticket in an external system. For 'high' severity, it should only send an email notification. Which playbook component is used to implement this type of conditional logic?
Show answer & explanation
Correct answer: C
Conditional logic in FortiAnalyzer playbooks is implemented using tasks that support branching. An analyst would add a task (often a 'Condition' or 'Branch' task type) that evaluates a variable from the incoming incident, such as
incident.severity. Based on the value of this variable, the playbook execution will follow a different path or 'branch', allowing for different sets of subsequent tasks to be executed.
Ready for the real thing?
The full FCSS-SOC-AN-7-4 simulator has every exam-style question, timed mode, and instant scoring.