Fortinet NSE 6 - FortiSOAR 7.3 Administrator Free Sample Questions

20 free sample questions214 in the full practice test

Try simulator

NSE6-FSR-7-3 Sample Questions

  1. Question 1

    A FortiSOAR administrator is tasked with integrating a new threat intelligence platform that requires communication through a corporate forward proxy. The proxy requires authentication. After configuring the proxy settings in the FortiSOAR UI, the connector still fails to connect. Which command-line utility should the administrator use to verify and troubleshoot the proxy connectivity from the FortiSOAR appliance's shell?

    Answer and explanation

    Correct answer: B

    The curl command is the most effective and standard Linux utility for testing network connectivity through a proxy from the command line. It allows specifying proxy credentials and the destination URL, providing a direct way to confirm if the FortiSOAR appliance can reach the external service through the configured proxy, independent of the connector's specific implementation. csadm proxy --test is not a valid command. ping does not support proxy settings. systemctl status secure-gateway checks the service status, not connectivity through it.

  2. Question 2

    Multiple answers

    A security architect is designing a multi-tiered role-based access control (RBAC) model for a global SOC. The requirements state that Level 1 (L1) analysts should only see incidents assigned to their specific regional team and should not be able to view sensitive PII fields within those incidents. What two FortiSOAR features are essential to implement this granular access control? (Choose two.)

    Answer and explanation

    Correct answers: A, B

    To meet the requirements, Teams must be used to segregate incidents by region, ensuring L1 analysts can only view records assigned to their team. Field-Level Permissions are then applied to the L1 analyst role to hide or make read-only specific sensitive fields like PII. System Fixtures are for system-wide settings, and Playbook Permissions control who can execute or modify playbooks, neither of which directly address the specified record and field visibility requirements.

  3. Question 3

    During a routine audit, an administrator discovers that a junior analyst was able to view and modify a high-severity financial fraud incident they should not have had access to. The analyst is part of the 'Tier 1 SOC' team, which has restricted permissions. What is the most likely reason for this unintended access?

    Answer and explanation

    Correct answer: B

    In FortiSOAR, the 'Owner' of a record implicitly gets full CRUD (Create, Read, Update, Delete) permissions on that specific record, which overrides the standard team and role-based permissions. If a senior analyst accidentally assigned ownership of the high-severity incident to the junior analyst, it would grant them the unintended access described. The other options are less likely to grant full modification rights that bypass team restrictions.

  4. Question 4

    A FortiSOAR administrator needs to perform a version upgrade from 7.3.0 to 7.3.1. To ensure system integrity and minimize downtime, they must follow the correct procedure. Which of the following represents the correct, high-level sequence of steps for performing the upgrade?

    flowchart TD A[Start] --> B{Take VM Snapshot / Backup}; B --> C{Download Upgrade Package}; C --> D{Run Pre-check Script}; D --> E{Execute Upgrade Script}; E --> F{Reboot System}; F --> G[End];
    Answer and explanation

    Correct answer: B

    The correct and safest procedure is to first create a backup or VM snapshot to allow for rollback. Then, the upgrade package must be downloaded and extracted (typically in /tmp). Finally, the upgrade.sh script is executed to perform the upgrade. This sequence ensures a recovery point exists before any system changes are made.

  5. Question 5

    True or False: When FortiSOAR is configured in a High Availability (HA) cluster, playbooks are automatically synchronized and executed on the active node only.

    Answer and explanation

    Correct answer: A

    This statement is true. In a standard FortiSOAR active-passive HA cluster, all data, configurations, and playbooks are replicated to the passive node, but active processing and playbook execution only occur on the active node. If a failover occurs, the passive node becomes active and takes over these responsibilities.

  6. Question 6

    A FortiSOAR administrator has been asked to externalize the Elasticsearch database to a dedicated, multi-node cluster for improved performance and scalability. After running the externalization script, what is the final step required to make the change effective?

    Answer and explanation

    Correct answer: B

    After modifying the configuration to point to an external Elasticsearch cluster, the FortiSOAR services must be restarted for the changes to take effect. The csadm services --restart command is the correct way to restart all necessary services and complete the externalization process. Simply rebooting may work but restarting the services is the documented and direct method. Re-indexing is part of the migration process, not the final activation step. The firewall rules should have been configured prior to starting the process.

  7. Question 7

    A SOC manager wants to track the Mean Time to Resolution (MTTR) for different incident types. To do this, they need to export all incident data from the last quarter, including custom fields, for analysis in an external business intelligence tool. Which FortiSOAR feature provides the most efficient way to accomplish this bulk data export?

    Answer and explanation

    Correct answer: D

    The most straightforward and efficient method for bulk exporting records for external analysis is to use the built-in 'Export to CSV/XLSX' functionality. The administrator can filter the incident list to show records from the last quarter and then export the results. This feature is designed for this exact purpose and includes all fields, including custom ones, in a format that is easily ingestible by BI tools. The API is a more complex solution, PDF is not suitable for data analysis, and scheduled reports are for visualization, not raw data export.

  8. Question 8

    Multiple answers

    A new FortiSOAR deployment is being planned. The security team wants to ensure that user authentication is managed centrally through their existing Active Directory infrastructure. Which two authentication methods in FortiSOAR are suitable for this requirement? (Choose two.)

    Answer and explanation

    Correct answers: A, B

    Both LDAP and SAML 2.0 can be used to integrate with Active Directory for centralized user authentication. LDAP allows FortiSOAR to directly query the Active Directory server. SAML 2.0 can be used by integrating with Active Directory Federation Services (ADFS) to provide single sign-on (SSO) capabilities. Appliance (local) authentication uses a local database. RADIUS is another protocol but LDAP and SAML are the most common for AD integration.

  9. Question 9

    A playbook designed to quarantine a malicious endpoint is failing intermittently. The administrator suspects a problem with the underlying uwsgi service that handles playbook execution. Which log file should the administrator examine first to find detailed error messages related to this service?

    Answer and explanation

    Correct answer: C

    The uwsgi service is a key component of the FortiSOAR application server stack, responsible for running the Python web application framework. Its specific logs are stored in /var/log/uwsgi/fortisoar.log. This file will contain detailed tracebacks and errors if the service itself is encountering problems, which could cause playbook failures. The cyops-workflow.log contains high-level playbook execution logs, but issues with the underlying service would be in the uwsgi log.

  10. Question 10

    An administrator is exporting the full system configuration of a FortiSOAR instance to migrate it to a new appliance. Which statement accurately describes the contents of the exported .tgz file?

    Answer and explanation

    Correct answer: A

    The system configuration export is designed to capture the entire state of the FortiSOAR application's configuration, including system settings, users, roles, modules, playbooks, and connectors. However, it explicitly excludes transactional record data like alerts and incidents. This allows for a clean migration of the system's structure without carrying over historical operational data.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 214 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon