Fortinet FCSS - Security Operations 7.4 Analyst Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 254 questions. Use the simulator for timed and flashcard mode.

Try Simulator

FCSS-SOC-AN-7-4 Sample Questions

  1. Question 1

    Q1

    A SOC analyst at a large financial institution is designing a FortiAnalyzer playbook to automate the initial response to a critical 'Potential Ransomware Activity' event. The playbook must first isolate the affected endpoint using a FortiGate connector, then retrieve the process hash from the event logs, and finally submit this hash to a third-party sandboxing service for deep analysis. Which playbook task sequence represents the most logical and effective workflow for this scenario?

    Show answer & explanation

    Correct answer: B

    The most effective workflow prioritizes containment. First, quarantine the endpoint to prevent the potential ransomware from spreading (Containment). Second, retrieve the necessary artifact (the process hash) for investigation. Finally, submit the hash to the sandbox for detailed analysis to confirm the threat and inform further response actions. Performing these steps out of order could allow the threat to propagate or lead to analysis of an incorrect artifact.

  2. Question 2

    Q2Multiple answers

    A threat hunter is using FortiAnalyzer's advanced search capabilities to proactively search for signs of lateral movement within the network. The hunter suspects an attacker is using PsExec for remote command execution. Which two of the following search queries would be most effective for identifying this specific activity? (Select TWO).

    Show answer & explanation

    Correct answers: A, C

    PsExec operates by creating a temporary Windows service named PSEXESVC on the target machine. Searching for the creation of this service is a primary indicator of PsExec usage. Additionally, monitoring for the execution of the psexec.exe process itself, especially by non-administrative or unexpected user accounts, is a direct way to detect its initiation. The other options are too generic; port 80 traffic is common web traffic, and DNS queries for microsoft.com are normal.

  3. Question 3

    Q3

    True or False: In a high-availability (HA) cluster of two FortiAnalyzer units, if the primary unit fails, a playbook that was in the middle of execution will be seamlessly migrated to the secondary unit and continue from the exact task where it left off.

    Show answer & explanation

    Correct answer: B

    While FortiAnalyzer HA provides redundancy for logging and reporting, it does not support stateful failover for in-flight playbook executions. If the primary unit fails, any playbook currently running will be terminated. Once the secondary unit becomes active, new playbook triggers will be processed, but the state of the previously running playbook is lost.

  4. Question 4

    Q4Multiple answers

    A junior SOC analyst observes an event in FortiAnalyzer indicating a successful user login from an IP address geolocated in a country where the company has no employees. This is followed by the creation of a new administrative account. According to the MITRE ATT&CK framework, which two tactics are most clearly demonstrated by this sequence of events? (Select TWO).

    Show answer & explanation

    Correct answers: A, C

    The successful login from an unexpected foreign IP address represents the adversary gaining a foothold in the network, which maps to the 'Initial Access' tactic. The subsequent creation of a new administrative account is a classic technique for maintaining long-term access, which falls under the 'Persistence' tactic.

  5. Question 5

    Q5

    A retail company is expanding its FortiAnalyzer deployment to handle logs from new stores. The current setup consists of a single FortiAnalyzer in analyzer mode at the headquarters. The new stores have unstable WAN connections. The company requires centralized analysis and reporting at HQ but needs to ensure logs are not lost during WAN outages at the store level. What is the most appropriate architectural change?

    Show answer & explanation

    Correct answer: C

    Deploying a FortiAnalyzer in collector mode at each store addresses the primary requirement. The collector will receive and store logs locally from the store's devices. This prevents log loss during WAN outages. When the connection is stable, it will reliably forward the stored logs to the central analyzer at HQ for unified analysis and reporting. This distributed model is ideal for environments with unreliable WAN links.

  6. Question 6

    Q6

    A SOC manager wants to create a custom dashboard in FortiAnalyzer to monitor for potential data exfiltration. The dashboard needs a chart that displays the top 10 users by the volume of data uploaded to Cloud.Storage applications. What is the correct dataset that should be used to build this chart?

    Show answer & explanation

    Correct answer: C

    The fortiview-cloud-applications-by-user dataset is specifically designed to aggregate traffic data related to cloud application usage and group it by user. This dataset contains the necessary fields, such as user, appcat (application category), and sentbyte or bytes, which are required to filter for 'Cloud.Storage' applications and sum the uploaded data volume per user.

  7. Question 7

    Q7

    An administrator configures an event handler to trigger an alert when more than 100 failed login attempts occur from a single source IP within 5 minutes. After deploying the handler, the SOC team receives numerous false positive alerts from an internal vulnerability scanner. What is the most effective way to modify the event handler to ignore the scanner while still monitoring other sources?

    Show answer & explanation

    Correct answer: C

    The most precise and effective solution is to add a filter to the event handler's logic. By creating a filter that excludes events where the source IP (srcip) matches the IP of the vulnerability scanner, the handler will ignore this legitimate activity. This allows the handler to remain active and continue monitoring all other sources for the suspicious behavior, effectively tuning out the noise without reducing security visibility.

  8. Question 8

    Q8

    What is the primary function of the fazlic-op-mode CLI command on a FortiAnalyzer device?

    Show answer & explanation

    Correct answer: B

    The fazlic-op-mode command is used in the FortiAnalyzer CLI to switch the device's fundamental operational mode. The two primary modes are 'Analyzer', which provides full analysis, reporting, and SOC features, and 'Collector', which functions as a log aggregation and forwarding point, typically used in distributed logging architectures.

  9. Question 9

    Q9

    A SOC analyst is investigating a security incident and needs to determine if a suspicious file, identified by its SHA256 hash, has been seen anywhere else in the network over the past 30 days. The analyst has access to logs from FortiGate, FortiSandbox, and FortiClient. Which FortiAnalyzer feature provides the most efficient way to perform this cross-device search for the indicator of compromise (IOC)?

    Show answer & explanation

    Correct answer: B

    The 'Threat Hunting' view in FortiAnalyzer's FortiSOC module is specifically designed for this purpose. It allows an analyst to search for indicators of compromise (such as file hashes, IPs, or URLs) across all logs from integrated Security Fabric devices. This provides a unified, historical view of the IOC's presence in the network, making it the most efficient method for this type of investigation.

  10. Question 10

    Q10

    A security architect is configuring a webhook connector in a FortiAnalyzer playbook. The purpose of this connector is to send alert details to a custom-built internal chat application. The chat application's API requires the 'Content-Type' header to be set to 'application/json'. Where in the FortiAnalyzer GUI would the architect configure this custom HTTP header for the webhook connector?

    Show answer & explanation

    Correct answer: C

    Custom HTTP headers for connectors are defined when the connector itself is configured, not within each playbook that uses it. The correct location is under 'Incidents & Events > Automation > Connectors'. When editing or creating the webhook connector, there is a dedicated section to add custom HTTP headers (key-value pairs) that will be included in every API call made by that connector.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the FCSS-SOC-AN-7-4 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 254 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon