{"id":21819,"date":"2026-09-25T07:27:38","date_gmt":"2026-09-25T07:27:38","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=21819"},"modified":"2026-09-25T07:27:38","modified_gmt":"2026-09-25T07:27:38","slug":"fortinet-nse6_fsr-7-3-practice-test-questions-and-exam-dumps-part19-q361-380","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-nse6_fsr-7-3-practice-test-questions-and-exam-dumps-part19-q361-380\/","title":{"rendered":"Fortinet NSE6_FSR-7.3 Practice Test Questions and Exam Dumps Part19 Q361-380"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/nse6-fsr-7-3-exam-dumps\"><b>Fortinet NSE6_FSR-7.3 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 361.<\/b><\/p>\n<p><b>A FortiSOAR workflow receives a new alert from a SIEM and needs to determine whether an incident already exists for the same external alert ID. What should it do first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Search the relevant module for a record containing the external alert ID.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Create a new incident immediately.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Delete the external identifier.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable the SIEM connector.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Searching for the external alert identifier before creating another incident supports deduplication. If an existing record already represents the same alert, the workflow can update that record or associate additional information with it instead of creating another case. This helps reduce duplicate analyst work and keeps case data organized. Creating an incident immediately can produce redundant records, while removing the identifier eliminates useful correlation information. Disabling the connector would prevent legitimate alerts from entering the response process.<\/span><\/p>\n<p><b>Question 362.<\/b><\/p>\n<p><b>A connector returns HTTP 400 when a playbook submits a request to an external API. What should the administrator examine?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The number of dashboard widgets<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The request parameters, required fields, and data format<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The physical disk model<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The analyst&#8217;s screen resolution<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An HTTP 400 response generally indicates that the external service considers the request invalid. Administrators should inspect the parameters generated by the connector action, confirm that required values are present, and verify that data is formatted as expected by the API. Dynamic playbook inputs should also be checked for null or malformed values. Dashboard widgets and workstation hardware do not determine whether an API request is syntactically or semantically valid. Request-level troubleshooting is therefore the appropriate approach.<\/span><\/p>\n<p><b>Question 363.<\/b><\/p>\n<p><b>A playbook receives several user records from an identity service and must find the record matching a specific email address. What should the workflow do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Select a random user record.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Create a dashboard for every user.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Iterate or filter the returned records using the email value.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Delete all nonmatching users.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When an integration returns multiple records, the workflow should evaluate the collection and identify the object whose relevant field matches the expected email address. This can be accomplished through appropriate filtering or iterative logic depending on the returned structure and available playbook capabilities. Selecting a random result can target the wrong identity, while deleting external records is unnecessary and potentially harmful. Structured collection processing allows the playbook to reliably identify the correct object for subsequent enrichment or response actions.<\/span><\/p>\n<p><b>Question 364.<\/b><\/p>\n<p><b>A workflow is about to block a domain, but the domain appears on the organization&#8217;s trusted-domain list. What should happen?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Block it regardless of the trusted status.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Remove it from the trusted list automatically.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable all domain enrichment.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Prevent the automatic block and follow the defined exception or review process.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Trusted-domain lists can act as safeguards against disruptive false-positive response. If a domain is identified as trusted, the workflow should not automatically perform the block unless the organization&#8217;s defined process specifically authorizes an exception. It can document the match, gather additional evidence, or request analyst review. Automatically removing the domain from the trusted list would bypass the safeguard. Pre-action validation helps ensure that automated containment does not inadvertently disrupt approved business resources.<\/span><\/p>\n<p><b>Question 365.<\/b><\/p>\n<p><b>What is a primary benefit of assigning incidents to team queues?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It organizes responsibility and helps distribute work among appropriate responders.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It increases external API limits.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It eliminates connector authentication.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It expands physical server memory.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Team queues provide a structured mechanism for routing incidents to groups responsible for particular types of security work. They can help distribute workload, clarify ownership, and ensure cases are visible to the appropriate responders. Assignment logic can also use incident category, severity, business unit, or other context to select the correct queue. Team assignment does not change API limits, authentication requirements, or server hardware. Its purpose is to support organized case management and operational accountability.<\/span><\/p>\n<p><b>Question 366.<\/b><\/p>\n<p><b>A FortiSOAR service account requires permission to create external tickets but not to delete them. Which configuration is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Full administrator privileges<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Grant only the permissions needed to create and manage the required ticket operations.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Anonymous API access<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Unrestricted shared credentials<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least privilege requires service accounts to receive only the permissions necessary for their intended functions. If the FortiSOAR integration creates or updates tickets but does not delete them, deletion privileges should generally not be granted. This limits the potential impact of credential compromise or incorrect automation. Anonymous or shared unrestricted access weakens security and accountability. Matching external account permissions to the specific connector operations used by production playbooks provides required functionality while minimizing unnecessary exposure.<\/span><\/p>\n<p><b>Question 367.<\/b><\/p>\n<p><b>A playbook must run different enrichment operations for file hashes, URLs, domains, and IP addresses. Which design should be used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A single action that ignores indicator type<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Separate FortiSOAR installations for every indicator type<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Conditional branching according to indicator type<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Dashboard filters only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Different indicator types frequently require different connector operations or input formats. Conditional branching allows the workflow to inspect the indicator type and route execution to the appropriate enrichment path. This makes the workflow flexible while reducing invalid requests. A generic operation that ignores type may send unsupported values to integrations, while separate FortiSOAR installations are unnecessary. Dashboard filters affect presentation or record selection but do not replace workflow branching. Type-aware conditions support reliable observable processing.<\/span><\/p>\n<p><b>Question 368.<\/b><\/p>\n<p><b>A connector action returns a timeout while creating an external case. Why should the playbook check the external system before immediately retrying?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To change the dashboard theme<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To increase local disk capacity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To remove execution records<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The external case may have been created even though the response was not received.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A timeout indicates that FortiSOAR did not receive the expected response within the configured period, but it does not necessarily mean the external service failed to process the request. If the case was created, an immediate retry could produce a duplicate. The workflow should use available identifiers or search capabilities to determine whether the original action completed. This duplicate-safe approach is particularly important for create operations. Controlled retries and idempotency make automation more reliable during uncertain communication failures.<\/span><\/p>\n<p><b>Question 369.<\/b><\/p>\n<p><b>Which FortiSOAR capability is appropriate for providing management with a recurring summary of incident statistics?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Scheduled reporting<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Connector credential rotation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> API authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Physical network switching<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Scheduled reporting is appropriate when stakeholders require incident information on a recurring basis. Reports can summarize relevant operational measurements such as incident counts, severity distribution, status, or other configured information. This supports regular review without requiring users to manually compile the same information each reporting period. Credential rotation and API authentication secure integrations, while physical switching concerns network infrastructure. Reporting capabilities provide a structured mechanism for communicating recurring SOC information to appropriate stakeholders.<\/span><\/p>\n<p><b>Question 370.<\/b><\/p>\n<p><b>An external integration works for read operations but returns a permission error for record updates. What should the administrator verify?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The dashboard background<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The external account&#8217;s authorization to modify the records<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The physical server rack position<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The number of analyst monitors<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Successful read operations demonstrate that basic connectivity and authentication may already be working. If modifications fail with a permission-related response, the account may lack the required write privilege. Administrators should review authorization for the specific update operation and grant only the necessary permission when appropriate. Dashboard appearance and physical hardware do not control API authorization. Evaluating operation-specific privileges helps troubleshoot the problem while maintaining the principle of least privilege.<\/span><\/p>\n<p><b>Question 371.<\/b><\/p>\n<p><b>A connector response may contain either a populated value or null for an asset owner field. What should the playbook do before using the field for assignment?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Always assume the owner exists.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Replace every owner with the same user.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Validate that the field contains a usable value and define a fallback for missing data.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Delete the asset record when the field is null.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The workflow should verify that the asset owner field contains a valid value before using it to assign an incident or task. If the value is missing, a defined fallback can route the record to a default team, request additional enrichment, or trigger analyst review. Assuming the value always exists can cause workflow errors or incorrect assignments. Deleting the asset would discard useful information. Explicit null handling makes automation more resilient to incomplete but otherwise valid external data.<\/span><\/p>\n<p><b>Question 372.<\/b><\/p>\n<p><b>A malware-response playbook requires analyst approval before deleting a suspicious file from a critical server. What should happen if the analyst rejects the request?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Delete the file anyway.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Remove the approval record.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Increase connector permissions.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Follow the rejection path and do not perform the unauthorized deletion.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An approval step is intended to control whether a sensitive action can proceed. If the analyst rejects the request, the workflow should honor that decision and follow the defined rejection path. This may include documenting the reason, performing further analysis, or using an alternative response. Deleting the file despite rejection would bypass the control and could disrupt a critical server. Preserving the approval outcome also provides useful accountability for subsequent review and auditing.<\/span><\/p>\n<p><b>Question 373.<\/b><\/p>\n<p><b>Why should administrators maintain separate production and testing versions or configurations when developing high-impact playbooks?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To reduce the chance that testing causes unintended actions against production systems.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To guarantee that connectors never fail.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To eliminate the need for authentication.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To make all users administrators.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Testing high-impact workflows directly against production systems can cause unintended containment, deletion, account changes, or other disruptive actions. A controlled test environment or configuration allows administrators to validate logic using appropriate endpoints, credentials, and data before deployment. Separation does not guarantee that connectors will never fail and does not remove authentication or access-control requirements. It supports safer change management by reducing the operational risk associated with developing and validating security automation.<\/span><\/p>\n<p><b>Question 374.<\/b><\/p>\n<p><b>A playbook&#8217;s condition stops working after an external service changes a numeric risk score to a text value. What should be reviewed?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Physical network cabling<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Data type handling and any required conversion before the comparison<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Dashboard color selection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Server rack height<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Conditions can behave incorrectly when the data type changes. A numerical comparison may no longer work as expected if the external API now returns the score as text. Administrators should inspect the actual output and apply appropriate type conversion or normalization before evaluating the threshold. Physical cabling and display settings do not affect logical comparisons. Correct data type handling is essential when workflows depend on external values that may change representation across API versions or product updates.<\/span><\/p>\n<p><b>Question 375.<\/b><\/p>\n<p><b>A SOC wants incidents involving executive accounts to follow a specialized escalation process. Which workflow design is appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ignore user context.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Send every incident through the executive process.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Enrich user context and use conditional routing for qualifying accounts.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable identity integrations.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Identity enrichment can provide the context needed to determine whether the affected user belongs to a specially handled group. Conditional logic can then route only qualifying incidents through the appropriate escalation path. This avoids applying the specialized process to unrelated cases while ensuring the relevant incidents receive required handling. Ignoring user context prevents the distinction, while sending every incident through the same escalation process is inefficient. Context-aware routing enables consistent application of organization-specific response requirements.<\/span><\/p>\n<p><b>Question 376.<\/b><\/p>\n<p><b>A playbook uses an external API that becomes unavailable for several minutes. Which retry design is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Retry continuously with no delay or limit.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Treat the first failure as successful.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Delete the affected incident.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use controlled retries with suitable delays and an escalation path if failures continue.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Temporary service outages can often be handled with controlled retries, but repeated immediate requests can add load and provide little benefit while the service remains unavailable. The workflow should use an appropriate delay or backoff strategy, limit retries, and escalate or create a manual task when recovery does not occur. Treating failures as success creates inaccurate status, while deleting incidents removes valuable context. Bounded retry behavior improves resilience without allowing external service problems to create uncontrolled workflow activity.<\/span><\/p>\n<p><b>Question 377.<\/b><\/p>\n<p><b>Which FortiSOAR capability allows one workflow to query a SIEM, enrich an IP address, update a firewall, and create a service ticket?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Orchestration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Physical disk mirroring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Hardware partitioning<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Network cabling<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Orchestration coordinates actions across multiple integrated technologies as part of one response process. A playbook can consume information from a SIEM, use a threat-intelligence integration for enrichment, invoke an authorized firewall operation, and synchronize the result with a ticketing system. This reduces manual tool switching and helps standardize incident handling. Disk mirroring, partitioning, and cabling are infrastructure concepts rather than cross-product security workflow capabilities. Orchestration enables integrated systems to participate in a unified response.<\/span><\/p>\n<p><b>Question 378.<\/b><\/p>\n<p><b>A connector begins failing immediately after its service account password is changed on the external system. What should the administrator do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Delete the connector permanently.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Update the stored connector credential and validate the required operations.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Remove all incident records.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable auditing.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When an external service-account password changes, FortiSOAR must be configured with the corresponding new credential. Administrators should update the connector securely, test authentication, and validate important operations used by production workflows. Testing only login may be insufficient if the account&#8217;s permissions also changed. Deleting the connector or incident records does not solve a credential mismatch, while disabling auditing reduces visibility. Credential synchronization and post-change validation restore reliable integration behavior.<\/span><\/p>\n<p><b>Question 379.<\/b><\/p>\n<p><b>A workflow receives two threat-intelligence results with different confidence levels. What should it do when policy defines a minimum confidence requirement for blocking?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Always use the first result.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Block regardless of confidence.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Evaluate the results according to the defined confidence and conflict-handling rules.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Delete both results.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Threat-intelligence sources can differ in confidence, freshness, or assessment. If organizational policy defines a minimum confidence requirement, the workflow should evaluate the evidence according to that rule rather than choosing arbitrarily. Conflicting or insufficient results can trigger additional enrichment or analyst review. Automatically blocking without meeting the evidence threshold increases false-positive risk, while deleting results removes useful investigative context. Explicit confidence and conflict-handling logic makes automated response decisions more consistent and defensible.<\/span><\/p>\n<p><b>Question 380.<\/b><\/p>\n<p><b>After deploying a new synchronization workflow between FortiSOAR and a ticketing system, what should be monitored closely?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only the dashboard background<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Only the number of FortiSOAR users<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Only the ticketing product logo<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Synchronization failures, duplicate updates, field mappings, conflicts, and overall execution outcomes.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Synchronization introduces dependencies between two systems and can expose problems involving field mappings, duplicate actions, conflicting updates, authentication, and external API behavior. Monitoring early production executions helps administrators confirm that data moves in the intended direction and that retry logic does not create duplicates. Conflict-resolution rules should also behave predictably when both systems change the same information. Reviewing the full synchronization outcome provides far more useful assurance than monitoring cosmetic or unrelated platform characteristics.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet NSE6_FSR-7.3 Exam Dumps and Practice Test Dumps &nbsp; Question 361. A FortiSOAR workflow receives a new alert from a SIEM and needs to determine whether an incident already exists for the same external alert ID. What should it do first? Search the relevant module for a record containing the external alert ID. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21819"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=21819"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21819\/revisions"}],"predecessor-version":[{"id":21820,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21819\/revisions\/21820"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=21819"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=21819"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=21819"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}