Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet NSE7_SOC_AR-7.6 Exam - Topic 2 Question 1 Discussion

Which two best practices should be followed when exporting playbooks in FortiAnalyzer? (Choose two answers)
A) Disable playbooks before exporting them. and B) Include the associated connector settings.
C) Move playbooks between ADOMs rather than exporting playbooks and re-importing them.
D) Ensure the exported playbook's names do not exist in the target ADOM.

Fortinet NSE7_SOC_AR-7.6 Exam - Topic 2 Question 1 Discussion

Actual exam question for Fortinet's NSE7_SOC_AR-7.6 exam
Question #: 1
Topic #: 2
[All NSE7_SOC_AR-7.6 Questions]

Which two best practices should be followed when exporting playbooks in FortiAnalyzer? (Choose two answers)

Show Suggested Answer Hide Answer
Suggested Answer: A, B

Comprehensive and Detailed Explanation From FortiSOAR 7.6., FortiSIEM 7.3 Exact Extract study guide:

According to the FortiAnalyzer 7.4 SOC Analyst official training material (Lesson 5: Automation) and supporting documentation for FortiSOAR 7.6 and FortiSIEM 7.3 integration, the following best practices are recommended for playbook portability:

Disable playbooks before exporting (A): When a playbook is exported, its current status (Enabled or Disabled) is preserved in the export file. If an Enabled playbook is imported into a destination ADOM where its trigger conditions are immediately met, it will start executing automatically. Disabling the playbook before export is a critical best practice to prevent unintended automated actions from occurring in the new environment before the analyst has had a chance to verify local configurations.

Include the associated connector settings (B): FortiAnalyzer allows you to include required connector configurations during the export process. By selecting this option, the exported file includes the necessary metadata and configurations for the connectors that the playbook relies on to execute its tasks. This ensures the playbook remains functional and portable across different FortiAnalyzer units or ADOMs without requiring the manual recreation of every connector.

Why other options are incorrect:

Move playbooks between ADOMs (C): There is no native 'Move' function for automation playbooks between ADOMs in the same sense as moving a device. The standard supported workflow for transferring automation logic is the Export and Import process.

Ensure names do not exist in target (D): While maintaining unique names is good practice, it is not a required 'best practice' for the export process itself because FortiAnalyzer automatically handles name conflicts. If an imported playbook shares a name with an existing one, the system automatically appends a timestamp to the new playbook's name to avoid a conflict.


Contribute your Thoughts:

0/2000 characters
Jesusa
3 hours ago
I prefer C and D. Moving between ADOMs is cleaner.
upvoted 0 times
...
Jacob
5 days ago
I think A and B are the best options. Disabling playbooks avoids issues.
upvoted 0 times
...
Sherron
10 days ago
B is a must, can't leave out those settings!
upvoted 0 times
...
Avery
16 days ago
Totally agree with A, it saves a lot of hassle!
upvoted 0 times
...
Oliva
2 months ago
Wait, are you sure about D? That sounds tricky.
upvoted 0 times
...
Myrtie
2 months ago
I think C is a better option than exporting.
upvoted 0 times
...
Xuan
2 months ago
A and B are definitely the way to go!
upvoted 0 times
...
Ailene
3 months ago
Moving between ADOMs is way easier than exporting.
upvoted 0 times
...
Robt
3 months ago
Totally agree with A and D!
upvoted 0 times
...
Margot
3 months ago
Wait, are you sure about A? Seems risky to disable them first.
upvoted 0 times
...
Delbert
3 months ago
I think B is super important too!
upvoted 0 times
...
Nelida
3 months ago
A and D are definitely the way to go.
upvoted 0 times
...
Casie
3 months ago
I think we discussed ensuring the exported playbook names don’t clash with existing ones in the target ADOM. That sounds like a critical step to avoid confusion.
upvoted 0 times
...
Ligia
4 months ago
I feel like moving playbooks between ADOMs is a better option than exporting. It just seems more straightforward, but I can't recall the exact reasons.
upvoted 0 times
...
Dominic
4 months ago
I'm not entirely sure, but I remember something about including connector settings being important. It might help maintain functionality after the export.
upvoted 0 times
...
Nancey
4 months ago
I think one of the best practices is to disable playbooks before exporting them. It seems like a safe step to avoid any issues.
upvoted 0 times
...

Save Cancel