FCP Security Automation & Orchestration (SOAR) 2 — Questions and Answers
Question 1: What is the role of a connector in FortiSOAR?
- A connector defines the structure of an incident alert
- A connector is a pre-built integration module that enables FortiSOAR to interact with a specific third-party tool or service (Correct answer)
- A connector routes network packets between security zones
- A connector stores enriched threat intelligence in a local database
Correct answer: A connector is a pre-built integration module that enables FortiSOAR to interact with a specific third-party tool or service
Connectors in FortiSOAR are modular integration packages that define how FortiSOAR communicates with and executes actions on external tools such as firewalls, EDR solutions, or threat intelligence platforms.
Question 2: Which FortiSOAR feature provides a collaborative workspace where multiple analysts can work together on a major security incident in real time?
- Incident Queue
- Playbook Designer
- War Room (Correct answer)
- Threat Feed Manager
Correct answer: War Room
The War Room in FortiSOAR is a dedicated collaborative environment where multiple analysts can communicate, share findings, and coordinate response actions on critical incidents simultaneously.
Question 3: In FortiSOAR, what is the primary function of case management?
- Generating compliance reports for auditors
- Storing and organizing all data, evidence, actions, and communications related to a security incident in one place (Correct answer)
- Automatically patching vulnerable systems identified during an incident
- Scheduling analyst shifts for 24/7 SOC coverage
Correct answer: Storing and organizing all data, evidence, actions, and communications related to a security incident in one place
Case management in FortiSOAR centralizes all incident-related information — alerts, evidence, tasks, notes, and timeline — providing a single pane of glass for the entire investigation lifecycle.
Question 4: FortiSOAR playbooks can be triggered by which of the following events?
- Only by manual analyst initiation
- Only by scheduled cron jobs
- By alert ingestion, manual triggers, schedule-based triggers, or API calls (Correct answer)
- Only when a new user account is created in Active Directory
Correct answer: By alert ingestion, manual triggers, schedule-based triggers, or API calls
FortiSOAR supports multiple trigger types for playbooks: automatic triggers based on incoming alerts, manual triggers by analysts, scheduled (time-based) triggers, and external API-initiated triggers.
Question 5: What data format is most commonly used for sharing threat intelligence indicators between SOAR platforms and threat intelligence tools?
- CSV flat files
- STIX/TAXII (Correct answer)
- NetFlow v9
- SNMP MIB
Correct answer: STIX/TAXII
STIX (Structured Threat Information Expression) and TAXII (Trusted Automated eXchange of Intelligence Information) are the industry-standard formats for structured threat intelligence sharing between security platforms.
Question 6: Which of the following best describes IoC enrichment within a FortiSOAR automated playbook?
- Blocking all IoCs immediately at the perimeter firewall without further analysis
- Querying threat intelligence sources to add context (such as reputation, geolocation, and associated malware families) to a suspicious indicator (Correct answer)
- Removing duplicate alerts from the incident queue
- Converting raw log entries into structured syslog format
Correct answer: Querying threat intelligence sources to add context (such as reputation, geolocation, and associated malware families) to a suspicious indicator
IoC enrichment involves automatically querying threat intelligence feeds and databases to augment a raw indicator (like an IP or hash) with contextual data that helps analysts assess its threat level.
Question 7: How does FortiSOAR's role-based access control (RBAC) benefit a security operations team?
- It allows all analysts to access any playbook and case regardless of sensitivity
- It restricts access to incidents, playbooks, and data based on user roles, ensuring analysts only see what they are authorized to handle (Correct answer)
- It automatically promotes junior analysts to senior roles after completing a set number of cases
- It enforces network segmentation policies on connected FortiGate devices
Correct answer: It restricts access to incidents, playbooks, and data based on user roles, ensuring analysts only see what they are authorized to handle
RBAC in FortiSOAR ensures that different roles (analyst, team lead, administrator) have appropriate access to cases, playbooks, and sensitive data, supporting least-privilege principles and regulatory compliance.
What is the role of a connector in FortiSOAR?