Podcast
Questions and Answers
What is one of the main resources where users can find product documentation for FortiSOAR?
What is one of the main resources where users can find product documentation for FortiSOAR?
Which of the following topics is likely covered in the FortiSOAR study guide?
Which of the following topics is likely covered in the FortiSOAR study guide?
What is the primary purpose of the Application Editor in FortiSOAR?
What is the primary purpose of the Application Editor in FortiSOAR?
Which section of the FortiSOAR study guide would you refer to for learning about data ingestion?
Which section of the FortiSOAR study guide would you refer to for learning about data ingestion?
Signup and view all the answers
What is the focus of the Playbook Evaluate Steps in FortiSOAR?
What is the focus of the Playbook Evaluate Steps in FortiSOAR?
Signup and view all the answers
What is the first action taken by a level 3 analyst upon receiving an escalated incident?
What is the first action taken by a level 3 analyst upon receiving an escalated incident?
Signup and view all the answers
What happens if the threat identified by the level 3 analyst is valid?
What happens if the threat identified by the level 3 analyst is valid?
Signup and view all the answers
Which of the following is NOT part of the level 3 analyst's follow-up work?
Which of the following is NOT part of the level 3 analyst's follow-up work?
Signup and view all the answers
What should a level 3 analyst do if there is no known procedure for an incident?
What should a level 3 analyst do if there is no known procedure for an incident?
Signup and view all the answers
Which component is essential for the level 3 analyst in the review process of an incident?
Which component is essential for the level 3 analyst in the review process of an incident?
Signup and view all the answers
What is the purpose of building a new SIEM rule or SOAR playbook?
What is the purpose of building a new SIEM rule or SOAR playbook?
Signup and view all the answers
What does the level 3 analyst do after identifying the threat during the development of new procedures?
What does the level 3 analyst do after identifying the threat during the development of new procedures?
Signup and view all the answers
Which of the following describes a potential outcome of performing a review process?
Which of the following describes a potential outcome of performing a review process?
Signup and view all the answers
What action can a level 1 analyst take if an alert is determined to be a false positive?
What action can a level 1 analyst take if an alert is determined to be a false positive?
Signup and view all the answers
What should a level 1 analyst do if an incident is confirmed as a threat?
What should a level 1 analyst do if an incident is confirmed as a threat?
Signup and view all the answers
What happens if a playbook remediation is not available for an incident?
What happens if a playbook remediation is not available for an incident?
Signup and view all the answers
How does FortiSOAR support the knowledge base of the SOC?
How does FortiSOAR support the knowledge base of the SOC?
Signup and view all the answers
Which of the following is NOT an established technique for a level 1 analyst?
Which of the following is NOT an established technique for a level 1 analyst?
Signup and view all the answers
What is the role of a level 2 analyst when an incident has been escalated to them?
What is the role of a level 2 analyst when an incident has been escalated to them?
Signup and view all the answers
Which of the following best describes the purpose of a playbook in FortiSOAR?
Which of the following best describes the purpose of a playbook in FortiSOAR?
Signup and view all the answers
What is one of the primary responsibilities of a level 1 analyst in incident handling with FortiSIEM or FortiSOAR?
What is one of the primary responsibilities of a level 1 analyst in incident handling with FortiSIEM or FortiSOAR?
Signup and view all the answers
When should a level 1 analyst escalate an incident to a level 2 analyst?
When should a level 1 analyst escalate an incident to a level 2 analyst?
Signup and view all the answers
What is a key feature of the MT_RegionalSOC deployment?
What is a key feature of the MT_RegionalSOC deployment?
Signup and view all the answers
Which of the following offers a license for an unlimited time for FortiSOAR?
Which of the following offers a license for an unlimited time for FortiSOAR?
Signup and view all the answers
How many actions per day does the Perpetual (Trial) license allow by default?
How many actions per day does the Perpetual (Trial) license allow by default?
Signup and view all the answers
Which license type allows evaluation with a predefined user count and expiry date?
Which license type allows evaluation with a predefined user count and expiry date?
Signup and view all the answers
What does the Subscription license offer in terms of user management?
What does the Subscription license offer in terms of user management?
Signup and view all the answers
What distinguishes the FortiGuard threat intel feeds in version 7.3.0?
What distinguishes the FortiGuard threat intel feeds in version 7.3.0?
Signup and view all the answers
Which statement is true regarding the Evaluation license?
Which statement is true regarding the Evaluation license?
Signup and view all the answers
What is the role of FortiSOAR in relation to the global SOC?
What is the role of FortiSOAR in relation to the global SOC?
Signup and view all the answers
What is the primary purpose of integrating FortiSOAR with FortiSIEM?
What is the primary purpose of integrating FortiSOAR with FortiSIEM?
Signup and view all the answers
Why is it recommended to send logs through the SIEM rather than using direct connectors?
Why is it recommended to send logs through the SIEM rather than using direct connectors?
Signup and view all the answers
What action can be performed on incidents in FortiSOAR?
What action can be performed on incidents in FortiSOAR?
Signup and view all the answers
What does FortiSOAR do when it receives an incident indicating a malicious actor's access attempt?
What does FortiSOAR do when it receives an incident indicating a malicious actor's access attempt?
Signup and view all the answers
What does each incident forwarded from FortiSIEM to FortiSOAR represent?
What does each incident forwarded from FortiSIEM to FortiSOAR represent?
Signup and view all the answers
In a typical enterprise architecture involving FortiSOAR, what role does the SIEM play?
In a typical enterprise architecture involving FortiSOAR, what role does the SIEM play?
Signup and view all the answers
What is the result of incidents generated by FortiGate and sent to FortiSIEM?
What is the result of incidents generated by FortiGate and sent to FortiSIEM?
Signup and view all the answers
What is typically not a feature of FortiSOAR in relation to incident management?
What is typically not a feature of FortiSOAR in relation to incident management?
Signup and view all the answers
Study Notes
Introduction to FortiSOAR
- FortiSOAR 7.3 automates investigation processes used by level 1 analysts, such as IOC reputation lookups.
- Analysts can close false positive alerts or escalate incidents to level 2 or level 3 analysts depending on the threat validity.
- Level 2 analysts assess incidents and can run remediation playbooks or document cases for future playbook development.
SOC Incident Handling
- Level 3 analysts take charge of escalated incidents, conducting advanced manual investigations after level 1 and level 2 efforts.
- If a threat is not valid, cases are documented and closed; if valid, manual remediation and potential updates to FortiSIEM rules or firewall policies are performed.
- New procedures may be developed for future incidents based on the findings, and case logs document these updates.
Developing New Techniques
- Protocols for creating new techniques involve identifying threats, indicators, and remediation strategies.
- Risks from exploitation may be mitigated through patches, blocks, and implementing future identification methods via SIEM rules or SOAR playbooks.
Enterprise Architecture Overview
- FortiSOAR operates within a typical enterprise architecture where logs from various devices are ingested through connectors.
- Recommended practice is to send logs through SIEM for centralization, analytics, and reporting rather than direct connectors.
- Incidents generated by FortiSIEM are unique records in FortiSOAR, allowing for remediation actions on target devices.
Licensing Options
- FortiSOAR licenses include:
- Perpetual: Unlimited time license.
- Perpetual (Trial): Free but restricted trial version.
- Subscription: Limits on users and defined timeframes; renewable and adjustable user counts.
- Evaluation: Limited user count with an expiry date for testing purposes.
- The license manager is accessed under the settings menu for management and configuration of licenses.
Studying That Suits You
Use AI to generate personalized quizzes and flashcards to suit your learning preferences.
Related Documents
Description
This quiz focuses on the design and development aspects of FortiSOAR version 7.3. It will test your knowledge and understanding of essential concepts required for effective use and implementation within organizations. Prepare to enhance your skills and comprehension of FortiSOAR functionalities.