Fortinet FCSS Advanced Analytics 6.7 Architect Free Sample Questions

20 free sample questions208 in the full practice test

Try simulator

FCSS-ADA-AR-6-7 Sample Questions

  1. Question 1

    A Managed Security Service Provider (MSSP) is designing a FortiSIEM deployment for a new client with strict data sovereignty requirements. The client's infrastructure is split between an on-premises data center in Canada and a public cloud environment in the UK. All logs generated in a specific region must be processed and stored within that same region. Which architectural design best meets these requirements while maintaining centralized management?

    Answer and explanation

    Correct answer: C

    This is the correct architecture. Collectors can be deployed in each geographic region to receive, parse, and compress logs locally. This ensures that the initial processing happens within the region. While the event data is ultimately sent to the central Supervisor for correlation and storage, this model is the standard FortiSIEM design for handling geographically distributed log sources efficiently and is the first step towards meeting sovereignty, although full sovereignty would require local supervisors. The other options are architecturally flawed: direct agent forwarding is inefficient and doesn't meet the regional processing requirement, a Supervisor/Worker split doesn't ensure logs stay local during processing, and two separate Supervisor deployments create management overhead without a unified view.

  2. Question 2

    Multiple answers

    A security analyst needs to create a FortiSIEM rule that detects a user logging in successfully from two different countries within a 10-minute window. Which rule components are essential for this detection logic? (Select TWO)

    Answer and explanation

    Correct answers: B, C

    The 'Group By' clause is necessary to correlate logon events for the same user.

    The 'HAVING' clause is used after the 'Group By' to filter the groups, in this case, keeping only the users that have logged on from more than one distinct country.

  3. Question 3

    An administrator at a financial institution has configured a baseline profile to monitor the number of daily failed credit card transactions for each customer. The learning period was set to 14 days. After 20 days, the baseline rule is generating a high number of false positive alerts. What is the most likely cause of the false positives?

    Answer and explanation

    Correct answer: B

    Baseline profiles learn 'normal' behavior during the learning period. For business cycles that have weekly or monthly patterns (like spikes in transactions at the end of a month), a 14-day period may not be sufficient. It could establish a baseline that is too low, causing normal cyclical peaks to be flagged as anomalies. Extending the learning period to capture a full business cycle (e.g., 30-45 days) would create a more accurate profile.

  4. Question 4

    A SOC has integrated FortiSIEM with FortiSOAR to automate responses to malware detection incidents. An analyst observes that when a malware incident is triggered in FortiSIEM, a ticket is created in FortiSOAR, but the associated playbook to isolate the endpoint fails to execute. The FortiSOAR connector test is successful. What is the most probable cause of this issue?

    Answer and explanation

    Correct answer: A

    FortiSOAR playbooks often require specific data points (artifacts) from the incoming alert to function correctly. If a playbook is designed to isolate a host, it will need an IP address, hostname, or MAC address as an input. If the FortiSIEM incident notification is not configured to send these specific attributes, the playbook will be triggered but will fail at the step that requires this missing information. A successful connector test only confirms connectivity, not the correctness of the data payload.

  5. Question 5

    True or False: In a multi-tenant FortiSIEM environment, a report created by an MSSP administrator for a specific customer organization is automatically visible to all other customer organizations.

    Answer and explanation

    Correct answer: B

    FortiSIEM's multi-tenancy model enforces strict data isolation between customer organizations. When an administrator creates a resource like a report and associates it with a specific organization, it is only visible to users within that organization's scope and to Super/MSSP level administrators. This role-based access control (RBAC) and organizational scoping are fundamental to the security of an MSSP offering.

  6. Question 6

    A security architect is using a lookup table to enrich firewall logs with information about internal application owners. The lookup table is a CSV file containing IP_Address, AppName, and AppOwnerEmail. The architect needs to add the AppOwnerEmail to any firewall log where the srcIp matches an IP_Address in the table. Which function or method should be used within a rule's display fields to achieve this?

    Answer and explanation

    Correct answer: B

    The correct syntax for retrieving a value from a lookup table in FortiSIEM is LOOKUP(tableName, eventAttributeToMatch, tableColumnToMatch, tableColumnToReturn). In this scenario, AppOwners is the table name, srcIp is the event attribute, IP_Address is the key column in the lookup table, and AppOwnerEmail is the value column to be returned and added to the event.

  7. Question 7

    A hospital's security team wants to use FortiSIEM UEBA to detect anomalous access to its Electronic Health Record (EHR) database. They have deployed UEBA agents on the database servers. Which of the following UEBA models would be most effective at detecting a compromised administrator account that starts accessing an unusually high number of unique patient records?

    Answer and explanation

    Correct answer: C

    The User Behavior Model is specifically designed to learn the normal patterns of activity for individual users. It would establish a baseline for each administrator, including the typical number and type of patient records they access. A sudden, significant deviation from this learned behavior, such as accessing a much higher volume of unique records, would be flagged as a high-risk anomaly, indicative of potential account compromise.

  8. Question 8

    The command to run a remediation script on FortiSIEM for an incident is found to be failing. The script is a Python script intended to add an IP to a blocklist on a FortiGate. Which of the following is the BEST first step to troubleshoot the issue?

    Answer and explanation

    Correct answer: B

    For FortiSIEM to execute a remediation script, the script file itself must have the correct Linux file permissions (typically chmod 755) and be owned by the appropriate user (usually phoenix). This is a common and fundamental configuration issue that prevents script execution. Checking permissions is the most logical and effective first troubleshooting step before investigating more complex issues like API keys or network connectivity.

  9. Question 9

    An MSSP is configuring event parsing for a new customer's bespoke application. The logs are unstructured and require a complex parsing logic that involves conditional matching and data extraction. The performance of the collector processing these logs is critical. Which FortiSIEM component should the architect use to define this parsing logic?

    Answer and explanation

    Correct answer: B

    FortiSIEM uses a powerful XML-based language to define log parsers. For custom or bespoke log sources, an administrator must create a new parser XML file. This file defines the regular expressions, patterns, and logic needed to extract attributes from raw logs. This parser is then uploaded to the Supervisor and distributed to the appropriate Collectors, which use it to process incoming logs.

  10. Question 10

    A FortiSIEM rule is configured to detect '5 failed logins followed by 1 successful login for the same user from the same IP address within 2 minutes'. This is an example of what type of rule?

    Answer and explanation

    Correct answer: C

    This rule requires matching two distinct conditions in a specific sequence and timeframe: a pattern of failed logins AND a pattern of a successful login. Because it involves more than one pattern or condition that must be met, it is classified as a multiple subpattern rule. This type of rule is essential for detecting complex attack sequences like brute-force attempts.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 208 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon