{"id":21799,"date":"2026-09-25T07:24:20","date_gmt":"2026-09-25T07:24:20","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=21799"},"modified":"2026-09-25T07:24:20","modified_gmt":"2026-09-25T07:24:20","slug":"fortinet-nse6_fsr-7-3-practice-test-questions-and-exam-dumps-part9-q161-180","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-nse6_fsr-7-3-practice-test-questions-and-exam-dumps-part9-q161-180\/","title":{"rendered":"Fortinet NSE6_FSR-7.3 Practice Test Questions and Exam Dumps Part9 Q161-180"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/nse6-fsr-7-3-exam-dumps\"><b>Fortinet NSE6_FSR-7.3 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 161.<\/b><\/p>\n<p><b>A FortiSOAR administrator wants a playbook to run at a defined recurring time rather than when a security record is created. Which approach is appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use scheduled execution for the playbook.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Change the dashboard theme.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Increase connector privileges.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Create a new physical network interface.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Scheduled execution is appropriate when a workflow needs to run according to a defined time-based schedule rather than in direct response to a newly created or modified security record. This can be useful for recurring data collection, maintenance, synchronization, or reporting-related automation. The workflow should still include appropriate error handling and validation. Dashboard appearance and connector privileges do not control execution timing, while a physical network interface provides connectivity rather than scheduling. The execution mechanism should match the operational trigger for the process.<\/span><\/p>\n<p><b>Question 162.<\/b><\/p>\n<p><b>Which operation would typically be used when a FortiSOAR playbook needs to change the status field of an existing incident?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Delete the module.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Update the existing record.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Reinstall the connector.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Create a new dashboard.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Changing a field on an existing incident is an update operation. The workflow should identify the correct record and modify the required field while preserving the rest of the incident information. Record updates are commonly used to change status, assignment, severity, or other workflow-related values. Deleting a module would affect the data structure, while reinstalling a connector and creating a dashboard do not modify the existing incident. Careful record updates help keep FortiSOAR information synchronized with the actual investigation state.<\/span><\/p>\n<p><b>Question 163.<\/b><\/p>\n<p><b>A playbook needs to obtain only incidents that are still open and have high severity. Which capability should it use?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Physical disk filtering<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Dashboard color selection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Record search or filtering with appropriate criteria<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Connector credential rotation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Record search or filtering can select incidents according to field values such as status and severity. Applying multiple criteria allows a workflow to operate on the specific records relevant to the use case rather than processing the entire dataset. This improves efficiency and reduces unintended actions. Disk filtering and dashboard colors are unrelated to record selection, while credential rotation addresses authentication. Search and filtering are therefore appropriate when automation needs to retrieve records matching defined operational conditions.<\/span><\/p>\n<p><b>Question 164.<\/b><\/p>\n<p><b>What should a playbook do before automatically closing an incident after executing containment actions?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Delete the execution history.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Remove all associated indicators.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable the connector.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Verify that required response and closure criteria have been satisfied.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Incident closure should represent the actual state of the response process. Before automatically closing a record, the workflow should verify that required containment, investigation, documentation, or other organizational closure criteria have been completed successfully. A failed response action should not be hidden by changing the incident to a closed state. Deleting execution history or associated evidence reduces visibility, while disabling the connector is unrelated. Explicit closure criteria help keep automated incident lifecycle management accurate and auditable.<\/span><\/p>\n<p><b>Question 165.<\/b><\/p>\n<p><b>What is a key advantage of linking alerts to the incident created from them?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Analysts can preserve and navigate the relationship between source alerts and the investigation.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> FortiSOAR no longer requires authentication.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Connector APIs become faster automatically.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Physical storage capacity increases.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Linking alerts to an incident preserves the relationship between the source detection information and the investigation created to handle it. Analysts can use that context to review supporting evidence, understand why the incident exists, and navigate associated records. Playbooks can also use record relationships when automating investigation and response. Relationships do not remove authentication requirements, increase API performance automatically, or expand storage hardware. Their value is in maintaining structured investigative context across related security records.<\/span><\/p>\n<p><b>Question 166.<\/b><\/p>\n<p><b>A SOC wants to reduce repeated incidents generated from substantially duplicate alerts. Which capability is most relevant to the workflow design?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Dashboard formatting<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Deduplication or correlation logic<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Physical server clustering<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> API password length<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Deduplication or correlation logic can evaluate incoming security information and determine whether multiple alerts represent the same or related activity. Instead of creating unnecessary independent investigations, qualifying alerts can be grouped or associated according to defined criteria. The exact implementation should reflect the organization&#8217;s data sources and operational process. Dashboard formatting and server clustering do not determine alert similarity, while password length concerns credential security. Correlation can reduce noise and help analysts focus on meaningful security cases.<\/span><\/p>\n<p><b>Question 167.<\/b><\/p>\n<p><b>A playbook receives a JSON response containing nested objects. What must the administrator identify to use a deeply nested value later in the workflow?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The server&#8217;s physical serial number<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The analyst&#8217;s display settings<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The correct path or reference to the required response value<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The dashboard refresh interval<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Structured API responses can contain nested objects and arrays. To use a particular value, the playbook must reference the correct location in the returned data structure. Administrators should inspect actual connector output and confirm field names, nesting, data types, and any required transformations. An incorrect reference can return a null or unexpected value even when the connector request itself succeeds. Hardware serial numbers, display settings, and dashboard refresh intervals have no effect on how workflow logic extracts values from JSON data.<\/span><\/p>\n<p><b>Question 168.<\/b><\/p>\n<p><b>Why should an automated endpoint-isolation playbook include safeguards for critical systems?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To increase the number of playbook executions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To remove the need for endpoint authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To guarantee all alerts become incidents<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To reduce the risk of disrupting essential business services.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint isolation can immediately affect business operations, particularly when the target is a critical server or other essential system. Safeguards such as asset context, exclusion criteria, additional validation, or required approval can help prevent inappropriate isolation. The specific controls should reflect organizational policy and risk. Safeguards are not intended to increase workflow volume or remove authentication. Their purpose is to balance rapid containment with protection against unnecessary disruption caused by false positives or incomplete investigative evidence.<\/span><\/p>\n<p><b>Question 169.<\/b><\/p>\n<p><b>Which FortiSOAR capability allows an analyst to add human-generated investigative context to a case or incident?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Notes or comments associated with the relevant record<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Physical routing tables<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Connector authentication tokens<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disk partitions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Notes or comments can preserve analyst observations, investigation findings, decisions, and other human-generated context alongside the relevant security record. This improves collaboration when several analysts or teams participate in an investigation and helps later reviewers understand why actions were taken. Such information can complement automatically collected evidence. Routing tables, authentication tokens, and disk partitions perform unrelated technical functions. Maintaining investigative notes supports continuity, accountability, and communication throughout the incident-response lifecycle.<\/span><\/p>\n<p><b>Question 170.<\/b><\/p>\n<p><b>A connector action begins failing immediately after an external product is upgraded. What should the administrator investigate first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Dashboard font size<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Connector compatibility, API behavior, and returned errors<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Analyst keyboard layout<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Incident title colors<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An external product upgrade can change APIs, authentication requirements, supported operations, or response structures. If a previously working connector begins failing immediately afterward, administrators should review connector compatibility and the actual error returned by the integration. They should also determine whether the connector or affected playbooks require updates. Dashboard fonts, keyboard layouts, and title colors do not affect API behavior. Investigating the integration boundary first is appropriate because the failure coincides directly with the external system change.<\/span><\/p>\n<p><b>Question 171.<\/b><\/p>\n<p><b>A FortiSOAR workflow must notify a supervisor only when an incident exceeds a defined severity threshold. Which design should be used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Notify the supervisor for every record.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable incident severity.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Evaluate severity with conditional logic before the notification action.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Remove the notification connector.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Conditional logic allows the workflow to evaluate the incident severity and execute the notification action only when the specified threshold is met. This prevents unnecessary notifications and keeps escalation aligned with the organization&#8217;s response process. Additional criteria, such as incident type or assignment, can also be considered if required. Sending every record ignores the stated condition, while disabling severity removes useful context. Removing the integration would prevent notification entirely. Conditions provide targeted and data-driven workflow behavior.<\/span><\/p>\n<p><b>Question 172.<\/b><\/p>\n<p><b>What should be done when a playbook&#8217;s automatic remediation action repeatedly fails because the external API rate limit is exceeded?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Grant all users administrator rights.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Delete all failed incidents.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Ignore the API response.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Adjust the workflow to handle rate limits with appropriate pacing, retry, or escalation.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">API rate limits restrict how frequently an external service accepts requests. A workflow that ignores these limits may repeatedly fail and generate unnecessary load. The playbook should handle the service&#8217;s limitations appropriately, potentially through controlled retries, pacing, batching where supported, or escalation when the action cannot be completed. Granting administrator rights does not increase API limits, while deleting incidents or ignoring failures creates operational risk. Resilient automation should account for external service constraints as part of its error-handling strategy.<\/span><\/p>\n<p><b>Question 173.<\/b><\/p>\n<p><b>Which FortiSOAR feature can help management review incident volumes and response trends over a selected period?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reports and dashboards<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Connector passwords<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Physical switch ports<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> BIOS settings<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Reports and dashboards can summarize operational information such as incident volumes, severity distributions, status, assignments, and relevant response measurements. These views help management understand workload and trends without examining each individual incident. The exact metrics should be selected according to organizational objectives. Connector passwords provide authentication, while switch ports and BIOS settings are infrastructure elements. Reporting and visualization capabilities are therefore appropriate for presenting historical and operational security information to management and SOC leadership.<\/span><\/p>\n<p><b>Question 174.<\/b><\/p>\n<p><b>Why should an administrator test both successful and failure paths when validating a new playbook?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To make the playbook file larger<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To verify that the workflow behaves safely under different execution outcomes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To eliminate the need for connector credentials<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To guarantee external APIs never fail<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Testing only the ideal path does not show how automation behaves when data is missing, an API is unavailable, authentication fails, or a response action is unsuccessful. Failure-path testing verifies that errors are detected and that the workflow retries, escalates, stops, or takes another safe action as designed. Testing cannot guarantee that external APIs will never fail, nor does it remove authentication requirements. Validating multiple execution paths helps prevent unexpected behavior when the workflow encounters real-world exceptions in production.<\/span><\/p>\n<p><b>Question 175.<\/b><\/p>\n<p><b>Which approach best protects a playbook that contains a highly privileged containment action?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow every user to execute and modify it.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Use a shared unrestricted account.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Restrict permissions and apply appropriate authorization controls.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable audit visibility.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A workflow capable of performing highly privileged containment should be accessible only to authorized users and processes. Appropriate permissions, least-privilege integration accounts, and approval controls where required can reduce the risk of accidental or unauthorized execution. Shared unrestricted accounts weaken accountability, while disabling auditing makes misuse harder to investigate. Security controls should be proportional to the impact of the action. Restricting access while maintaining appropriate auditability provides stronger governance over sensitive automated response capabilities.<\/span><\/p>\n<p><b>Question 176.<\/b><\/p>\n<p><b>An analyst wants to determine what happened during a failed playbook execution. Which information is most useful?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Dashboard theme settings<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Physical server dimensions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Analyst profile picture<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Playbook execution history and step-level error details<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Execution history provides evidence about which workflow steps ran, which values were processed, and where the failure occurred. Step-level errors can reveal problems such as invalid input, authentication failure, unavailable services, or unexpected responses. This information allows troubleshooting to focus on the actual failure rather than making unrelated configuration changes. Dashboard themes, server dimensions, and profile pictures do not explain workflow execution. Detailed execution information is therefore central to diagnosing failed or partially completed playbooks.<\/span><\/p>\n<p><b>Question 177.<\/b><\/p>\n<p><b>What is the main purpose of a case-management process in FortiSOAR?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To organize investigation and response activities around security records and associated work<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To configure physical firewall interfaces<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To replace all security products<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To increase server clock speed<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Case management helps organize the information and activities associated with security investigations. This can include relevant records, assignments, tasks, evidence, notes, status, and other context required to move work through the incident lifecycle. Automation can support the process, while analysts retain visibility and responsibility where necessary. Case management does not configure physical interfaces, replace every security technology, or change hardware performance. Its purpose is to provide a structured operational framework for investigating and responding to security events.<\/span><\/p>\n<p><b>Question 178.<\/b><\/p>\n<p><b>A playbook must send a ticket to an external IT service-management platform. What is normally required?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A new physical disk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A configured connector with the required operation and permissions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A dashboard without filters<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A different FortiSOAR login page<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Integration with an external ticketing or IT service-management platform normally requires an appropriate connector configured with the endpoint, authentication, and permissions needed for the intended operation. The playbook can then invoke the connector to create or update a ticket and pass relevant incident information. A physical disk and login-page customization are unrelated, while dashboards only display information. The connector provides the application-level communication required for coordinated ticket creation as part of an automated security workflow.<\/span><\/p>\n<p><b>Question 179.<\/b><\/p>\n<p><b>Which approach should a playbook use when multiple response actions depend on a common enrichment result?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Request the same enrichment repeatedly without reason.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Ignore the enrichment output.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Store or pass the result so subsequent steps can reuse it.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Create a new user for every response action.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When several workflow decisions depend on the same enrichment result, the data should be retained or passed to subsequent steps so it can be reused. This avoids unnecessary duplicate API requests and helps maintain consistency because each decision evaluates the same evidence. Repeating external calls can waste resources and may contribute to rate-limit problems. Ignoring the result defeats the purpose of enrichment, while creating users is unrelated. Efficient data reuse is an important principle when designing multi-step automation.<\/span><\/p>\n<p><b>Question 180.<\/b><\/p>\n<p><b>What is the most appropriate practice after changing the data model or fields used by several production playbooks?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assume all existing playbooks will adapt automatically.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Delete historical records immediately.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable all connectors permanently.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Identify dependent workflows and test their field references and behavior.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Changes to fields or data structures can affect playbooks that reference those values for conditions, mappings, connector inputs, or record updates. Administrators should identify dependent automation and verify that the expected fields remain available and correctly interpreted. Testing should cover relevant workflow paths before relying on the modified configuration in production. Assuming automatic adaptation can result in silent failures, while deleting historical records or disabling connectors does not address dependency problems. Dependency-aware testing helps maintain reliable automation after data-model changes.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet NSE6_FSR-7.3 Exam Dumps and Practice Test Dumps &nbsp; Question 161. A FortiSOAR administrator wants a playbook to run at a defined recurring time rather than when a security record is created. Which approach is appropriate? Use scheduled execution for the playbook. 2. Change the dashboard theme. 3. Increase connector privileges. 4. Create [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21799"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=21799"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21799\/revisions"}],"predecessor-version":[{"id":21800,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21799\/revisions\/21800"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=21799"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=21799"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=21799"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}