Sign In
Home/Fortinet/FortiSOAR 7.6 Analyst/Free questions

Fortinet NSE 6 - FortiSOAR 7.6 Analyst — Free Practice Questions

10 free sample questions from a bank of 39, with the correct answers and explanations. No signup required — start practising right now.

1Refer to the exhibit. Which two statements about the recommendation engine are true? (Choose two.)
Fortinet NSE 6 - FortiSOAR 7.6 Analyst question 1
  • There are no playbooks that can be run on the recommended alerts using the recommendation panel
  • The dataset is trained to predict the Severity and Type fields.
  • The recommendation engine is set to automatically accept suggestions.
  • The alert severity is High, but the recommendation is for it to be set to Medium
Answer: B, D

The short version

The banked answers B and D are kept because the reconstructed recommendation panel shows a Severity and Type trained dataset with a High alert recommended to Medium, so exhibit missing is resolved by reconstruction.

Key concepts in this question

This question tests FortiSOAR recommendation engine behavior and which statements about training fields and severity suggestions are true.

Why B and D are correct

The reconstructed exhibit shows a recommendation panel trained to predict Severity and Type where the current High severity alert carries a Medium recommendation without auto accept or runnable playbooks stated, which makes B and D consistent with the stem options and banked answers.

Why the others are wrong

No runnable playbooks overstates the panel and auto accept contradicts the manual suggestion display in the reconstructed exhibit, so A and C are wrong.

NSE6_FSR_AN-7.6 exam tip

Remember to read the trained fields and the current versus recommended severity pair in the recommendation panel.

2Refer to the exhibit. Which statement correctly describes the user's login behavior?
Fortinet NSE 6 - FortiSOAR 7.6 Analyst question 2
  • The user is sent to a waiting queue if there are named users logged in.
  • The user can log in only if there are enough seats available.
  • The user will always be able to draw from the concurrent pool and log in.
  • The user has an active concurrent session that does not time out.
Answer: B

The short version

The banked answer B is kept because the reconstructed seat login view shows a seat constrained user who needs available seats to log in, so exhibit missing is resolved by reconstruction.

Key concepts in this question

This question tests FortiSOAR named versus concurrent seats and the login behavior enforced by seat availability.

Why B is correct

The reconstructed exhibit shows a license and session view where the user consumes a seat, so the user can log in only if enough seats are available, which makes B consistent with the stem options and banked answer.

Why the others are wrong

A waiting queue for named users, always drawing from the concurrent pool, and a non timing out concurrent session all describe different license behaviors than the reconstructed seat requirement, so A and C and D are wrong.

NSE6_FSR_AN-7.6 exam tip

Remember to separate named seats from the concurrent pool and check seat availability for login questions.

3Which three roles are defined as SAML roles? (Choose three.)
  • Principal
  • Attribute map
  • Identity provider
  • Service provider
  • Role
Answer: A, C, D

The short version

A, C, D — SAML roles need a principal, an identity provider, and a service provider. Who, who-vouches, who-trusts.

Key concepts in this question

  • Principal: the subject. IdP: asserts identity. SP: consumes assertions.
  • Attribute maps and role objects configure mapping; they are not SAML roles.

Why A, C and D are correct

Principal/IdP/SP is the canonical SAML role trio.

Why the others are wrong

  • B. Attribute maps translate claims; they are not roles.
  • E. Roles are FortiSOAR objects assigned from claims, not SAML roles.

FortiSOAR exam tip

SAML roles = principal, IdP, SP.

4Which three actions can be performed from within the war room? (Choose three)
  • View graphical representation of all records linked to an incident in the Artifacts lab
  • Change the room's status to Escalated to enforce hourly updates.
  • Investigate issues by tagging results as evidence.
  • Use the Task Manager tab to create, manage, assign, and track tasks.
  • Integrate a third-party instant messenger directly into the collaboration workspace.
Answer: A, C, D

The short version

A, C, D — war rooms offer artifact graphs, evidence tagging, and task management. Visualize, preserve, coordinate.

Key concepts in this question

  • Artifacts lab graphs linked records; evidence tagging preserves findings; Task Manager tracks response work.
  • Status-forcing and third-party chat embedding are not war-room actions.

Why A, C and D are correct

The three documented war-room capabilities.

Why the others are wrong

  • B. No Escalated-status hourly-enforcement exists.
  • E. External messengers are not natively embedded.

FortiSOAR exam tip

War room = artifacts, evidence, tasks.

5A decision step checks if a reputation score is greater than 80. However, some IPs with a score of "90" are not passing the condition.What is the MOST likely cause?
  • The connector returned inconsistent data
  • The score is being treated as a string instead of a number
  • The threshold should be set to 100
  • The playbook requires manual approval
Answer: B

The short version

B — "90" failing a >80 check is a string-vs-number type bug. Lexicographic comparison betrays you.

Key concepts in this question

  • String comparison: quoted values compare character-by-character, so multi-digit scores misbehave against numeric thresholds.
  • FortiSOAR Jinja/conditions require explicit numeric casting.

Why B is correct

Quoted scores evaluated as strings is the documented classic decision-step failure.

Why the others are wrong

  • A. Consistent connector data would not selectively fail.
  • C. Raising thresholds masks the type bug.
  • D. Approval gates block execution; they do not fail conditions.

FortiSOAR exam tip

Quoted numbers in conditions = cast to number.

6Review the following command:#/opt/cyops-workflow/.env/bin/python /opt/cyops-workflow/sealab/manage.py cleandb --keep 1000What is the expected outcome of the command?
  • Deletes all workflow run history, apart from the last 1000 entries
  • Reclaims disk space for backup, restore, or upgrade process
  • Deletes the last 1000 entries from the workflow run history
  • Schedules a workflow execution history cleanup for every Saturday night
Answer: A

The short version

A — cleandb --keep 1000 prunes run history to the newest thousand. Trim, keep N.

Key concepts in this question

  • cleandb deletes workflow execution history.
  • --keep retains the most recent N entries.

Why A is correct

Delete-all-but-latest-1000 is the documented command effect.

Why the others are wrong

  • B. Disk reclamation for backup is a different workflow.
  • C. The flag keeps (not deletes) the last 1000.
  • D. No scheduling is involved in this one-shot command.

FortiSOAR exam tip

cleandb --keep N = keep newest N.

7Which two relationship types are configurable on FortiSOAR? (Choose two.)
  • Grandparents
  • Parents
  • Siblings
  • Relatives
Answer: B, C

The short version

B and C — FortiSOAR relationships come in parents and siblings. Hierarchy plus lateral links.

Key concepts in this question

  • Parent relationships build record hierarchies.
  • Sibling relationships link lateral records.

Why B and C are correct

The two documented configurable relationship types.

Why the others are wrong

  • A. No grandparent relationship type exists.
  • D. No relatives relationship type exists.

FortiSOAR exam tip

Relationships = parents + siblings.

8On FortiSOAR. which default role is used to assign privileges to other teams and is recommended to not be removed?
  • Application Administrator
  • Full App Permissions
  • Playbook Administrator
  • Security Administrator
Answer: A

The short version

A — Application Administrator grants team privileges and must stay. The delegating root role.

Key concepts in this question

  • Application Administrator assigns privileges across teams.
  • Removing it strands privilege management.

Why A is correct

The documented keep-this-role for cross-team privilege assignment.

Why the others are wrong

  • B. Full App Permissions is broad but not the delegating role.
  • C. Playbook Administrator scopes to playbooks only.
  • D. Security Administrator scopes to security functions.

FortiSOAR exam tip

Never delete Application Administrator.

9An administrator wants to collect and review all FortiSOAR log tiles to troubleshoot an issue.Which two methods can they use to accomplish this? (Choose two.)
  • Enter the csacta services --status command, and then copy the output.
  • Download the logs from the GUI.
  • Enter the caacta log --collect directory command.
  • Review the contents of /var/log/messages.
Answer: B, C

The short version

B and C — collect every log tile via GUI download or the log-collect command. Point-click plus CLI.

Key concepts in this question

  • GUI log download bundles tiles for review.
  • log --collect gathers them from the shell.

Why B and C are correct

The two documented full-log collection methods.

Why the others are wrong

  • A. Service-status output shows states, not log contents.
  • D. /var/log/messages is host-level, not the FortiSOAR tiles.

FortiSOAR exam tip

All log tiles = GUI download or log-collect.

10Which three attributes are required on FortiSOAR when mapping users from an identity provider (IdP) for SAML authentication? (Choose three.)
  • firstName
  • role
  • lastName
  • team
  • email
Answer: A, D, E

The short version

A, D, E — SAML user mapping needs firstName, team, and email. Name, placement, identity.

Key concepts in this question

  • firstName/email identify the user; team places them.
  • Role and lastName are optional or derived, not required mapping attributes.

Why A, D and E are correct

The three documented required IdP-mapping attributes.

Why the others are wrong

  • B. Roles derive from team/mapping, not required directly.
  • C. lastName is optional in the mapping schema.

FortiSOAR exam tip

SAML mapping = firstName, team, email.

Want the full bank of 39 questions for Fortinet NSE 6 - FortiSOAR 7.6 Analyst? See all practice exams.