NSE 7
Security Operations Architect
Part of NSE 7: Security Operations
Time allowed: 75 minutes. Language: English. Product version: FortiSOAR 7.6., FortiSIEM 7.3.
Independent study aid built from the public exam blueprint. Not affiliated with, authorized by, or endorsed by fortinet. Objectives are transcribed and mapped by hand, so this page may contain mistakes or may have fallen behind the vendor's current material: exam objectives, versions, numbering and availability all change without notice. Treat fortinet's own certification portal as the source of truth and verify against it before you book anything.
SOC Concepts and Frameworks
1.01 Analyze security incidents and identify adversary behaviors
1.02 Explain Fortinet SOC enterprise architecture
1.03 Identify attack vectors
Detection Capabilities
2.01 Configure FortiSIEM incident rules
2.02 Build queries to search event logs on FortiSIEM
2.03 Analyze FortiSIEM incidents
SOAR Incident Handling and Threat Hunting
3.01 Analyze threat hunting processes and data
3.02 Manage FortiSOAR incidents
3.03 Create queues and shifts for workload management
3.04 Use war rooms for incident handling
SOAR Playbook Development
4.01 Configure FortiSOAR playbooks
On this site: FortiSOAR Playbooks, Jinja, and Connectors4.02 Configure FortiSOAR connectors
On this site: FortiSOAR Playbooks, Jinja, and Connectors4.03 Manipulate data using Jinja filters
On this site: FortiSOAR Playbooks, Jinja, and Connectors4.04 Debug and troubleshoot FortiSOAR playbooks
Public sources, used in good faith
These guides are independent study aids built from publicly available material: published exam blueprints, official product documentation, and vendor training catalogues. Product names, exam codes, and trademarks belong to their owners and are used only to identify the subject being taught. This site is not affiliated with or endorsed by any vendor named here. If you hold rights in material published on this page and believe it should be removed or corrected, please send the exact URL and a short note on the issue through the contact page; requests are reviewed promptly and in good faith. Read the full disclaimer →