FCSS-ADA-AR-6-7 Sample Questions

FCSS-ADA-AR-6-7 Sample Questions & Answers

Constructing FortiSIEM rules and advanced analytics techniques take the biggest slice, with the rest spread across running a multi-tenant SOC for managed providers, rolling out Windows and Linux agents, baseline profile reports and UEBA, and FortiSOAR remediation.

Launch the full FCSS-ADA-AR-6-7 simulator →

Showing 10 of 20 free samples.

  1. Question 1Advanced

    FortiSIEM Rules and Analytics · Configure advanced nested queries and lookup tables

    A security architect is using a lookup table to enrich firewall logs with information about internal application owners. The lookup table is a CSV file containing IP_Address, AppName, and AppOwnerEmail. The architect needs to add the AppOwnerEmail to any firewall log where the srcIp matches an IP_Address in the table. Which function or method should be used within a rule's display fields to achieve this?

    Show answer & explanation

    Correct answer: B

    The correct syntax for retrieving a value from a lookup table in FortiSIEM is LOOKUP(tableName, eventAttributeToMatch, tableColumnToMatch, tableColumnToReturn). In this scenario, AppOwners is the table name, srcIp is the event attribute, IP_Address is the key column in the lookup table, and AppOwnerEmail is the value column to be returned and added to the event.

  2. Question 2Intermediate

    FortiSIEM Baseline and UEBA · Explain UEBA on FortiSIEM

    A hospital's security team wants to use FortiSIEM UEBA to detect anomalous access to its Electronic Health Record (EHR) database. They have deployed UEBA agents on the database servers. Which of the following UEBA models would be most effective at detecting a compromised administrator account that starts accessing an unusually high number of unique patient records?

    Show answer & explanation

    Correct answer: C

    The User Behavior Model is specifically designed to learn the normal patterns of activity for individual users. It would establish a baseline for each administrator, including the typical number and type of patient records they access. A sudden, significant deviation from this learned behavior, such as accessing a much higher volume of unique records, would be flagged as a high-risk anomaly, indicative of potential account compromise.

  3. Question 3Beginner

    Conditions and Remediation · Remediate incidents on FortiSIEM both manually and automatically

    The command to run a remediation script on FortiSIEM for an incident is found to be failing. The script is a Python script intended to add an IP to a blocklist on a FortiGate. Which of the following is the BEST first step to troubleshoot the issue?

    Show answer & explanation

    Correct answer: B

    For FortiSIEM to execute a remediation script, the script file itself must have the correct Linux file permissions (typically chmod 755) and be owned by the appropriate user (usually phoenix). This is a common and fundamental configuration issue that prevents script execution. Checking permissions is the most logical and effective first troubleshooting step before investigating more complex issues like API keys or network connectivity.

  4. Question 4Intermediate

    Multi-Tenancy SOC Solution for MSSP · Define and deploy collectors and agents

    An MSSP is configuring event parsing for a new customer's bespoke application. The logs are unstructured and require a complex parsing logic that involves conditional matching and data extraction. The performance of the collector processing these logs is critical. Which FortiSIEM component should the architect use to define this parsing logic?

    Show answer & explanation

    Correct answer: B

    FortiSIEM uses a powerful XML-based language to define log parsers. For custom or bespoke log sources, an administrator must create a new parser XML file. This file defines the regular expressions, patterns, and logic needed to extract attributes from raw logs. This parser is then uploaded to the Supervisor and distributed to the appropriate Collectors, which use it to process incoming logs.

  5. Question 5Beginner

    FortiSIEM Rules and Analytics · Construct FortiSIEM rules

    A FortiSIEM rule is configured to detect '5 failed logins followed by 1 successful login for the same user from the same IP address within 2 minutes'. This is an example of what type of rule?

    Show answer & explanation

    Correct answer: C

    This rule requires matching two distinct conditions in a specific sequence and timeframe: a pattern of failed logins AND a pattern of a successful login. Because it involves more than one pattern or condition that must be met, it is classified as a multiple subpattern rule. This type of rule is essential for detecting complex attack sequences like brute-force attempts.

  6. Question 6Beginner

    FortiSIEM Baseline and UEBA · Explain FortiSIEM baseline and profile reports

    What is the primary purpose of the 'learning period' in a FortiSIEM baseline profile?

    Show answer & explanation

    Correct answer: B

    The learning period is a defined timeframe during which FortiSIEM observes and collects data for a specific metric (e.g., traffic volume, login failures) without generating alerts. It uses this data to build a statistical model of what constitutes normal activity. Once the learning period is complete, this model becomes the baseline against which future activity is compared to detect anomalies.

  7. Question 7Intermediate

    Conditions and Remediation · Remediate incidents through FortiSOAR

    A FortiSOAR playbook needs to perform different actions based on the severity of an incoming incident from FortiSIEM. For example, 'High' severity incidents should trigger an automated endpoint isolation, while 'Medium' severity incidents should only create a ticket for manual review. Which playbook component is used to implement this logic?

    Show answer & explanation

    Correct answer: C

    A decision node in a FortiSOAR playbook is used to create conditional branches in the workflow. It evaluates an input, such as the severity attribute from a FortiSIEM incident, and directs the playbook execution down a specific path based on whether the condition is true or false. This allows for the creation of dynamic and context-aware automation.

  8. Question 8Intermediate

    Multi-Tenancy SOC Solution for MSSP · Install and manage FortiSIEM Windows and Linux agents

    An administrator is troubleshooting a FortiSIEM Linux agent that is not sending logs to its assigned collector. The administrator has verified network connectivity between the agent and the collector on the correct port. The agent process is running on the Linux host. Which of the following is the next most likely cause of the issue?

    Show answer & explanation

    Correct answer: B

    The FortiSIEM agent runs as a specific user. If that user does not have read permissions on the log files or directories specified in its configuration (/opt/fortisiem-agent/etc/config.xml), it will be unable to access and forward the log data, even if the process is running and network connectivity is fine. This is a common OS-level configuration error.

  9. Question 9Advanced

    FortiSIEM Rules and Analytics · Configure advanced nested queries and lookup tables

    A SOC analyst is building a query to find all events related to a specific user, 'j.doe', that have occurred on any device classified as a 'Domain Controller' in the CMDB. Which of the following represents the most efficient query structure to achieve this?

    flowchart LR A[Event Query] --> B{Filter by User} B --> C{Filter by Device Type} C --> D[Results]

    Show answer & explanation

    Correct answer: B

    This structure is the most efficient. The inner CMDB query (deviceType = 'Domain Controller') executes first and returns a relatively small, targeted list of device IPs. The outer event query then searches only for events from that specific list of IPs where the user is 'j.doe'. This significantly reduces the search space for the event query compared to searching all events first and then filtering. Using a nested query to pre-filter from the CMDB is a key optimization technique.

  10. Question 10Intermediate

    FortiSIEM Baseline and UEBA · Explain FortiSIEM baseline and profile reports

    When comparing FortiSIEM baseline reports to standard reports, which statement is accurate?

    Show answer & explanation

    Correct answer: A

    This is the core difference. A standard report provides a straightforward aggregation of data (e.g., top talkers, event counts). A baseline report, however, compares current data against a previously established statistical baseline of normal behavior and highlights significant deviations, which are potential anomalies.

Ready for the real thing?

The full FCSS-ADA-AR-6-7 simulator has every exam-style question, timed mode, and instant scoring.