Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Fortinet FCP_FAZ_AN-7.6 Fortinet NSE 5 - FortiAnalyzer 7.6 Analyst Exam Practice Test

Demo: 20 questions
Total 67 questions

Fortinet NSE 5 - FortiAnalyzer 7.6 Analyst Questions and Answers

Question 1

Which log will generate an event with the status Contained?

Options:

A.

An AV log with action=quarantine.

B.

An IPS log with action=pass.

C.

A WebFilter log will action=dropped.

D.

An AppControl log with action=blocked.

Question 2

(How does FortiAnalyzer block indicators? (Choose one answer))

Options:

A.

It uses an automation script to update FortiGate with the block list.

B.

It uses a FortiManager connector to send the block list.

C.

It uses a FortiClient EMS connector to send the block list.

D.

It uses a webhook to allow FortiGate to send the block list.

Question 3

(You created a playbook on FortiAnalyzer that uses a FortiOS connector. When you configure FortiGate, which type of trigger must you use so that the actions in an automation stitch are available in the FortiOS connector? (Choose one answer))

Options:

A.

FortiAnalyzer Event Handler

B.

Incoming webhook

C.

Fabric Connector event

D.

IP ban

Question 4

Which FortiAnalyzer feature allows you to use a proactive approach when managing your network security?

Options:

A.

FortiView Monitor

B.

Outbreak alert services

C.

Incidentsdashboard

D.

Threat hunting

Question 5

(In a FortiAnalyzer Fabric deployment, which three modules from Fabric members are available for analysis on the supervisor? (Choose three answers))

Options:

A.

Playbooks

B.

Indicators

C.

Logs

D.

Events

E.

Reports

Question 6

(An analyst is using FortiAI on FortiAnalyzer to simplify certain tasks but is worried about exceeding the monthly token limit. Which query will take the fewest FortiAI tokens? (Choose one answer))

Options:

A.

Show logs for 192.168.1.10 (past week)

B.

Show all logs from the past week

C.

Can you show me all the log entries for the endpoint 192.168.1.10?

D.

Show logs for 192.168.1.10

Question 7

Exhibit.

What does the data point at 12:20 indicate?

Options:

A.

The loginsert log time is increasing.

B.

FortiAnalyzer is using its cache to avoid dropping logs.

C.

The performance of FortiAnalyzer is below the baseline.

D.

The sqiplugind service is caught up with the logs

Question 8

Which statement about SQL SELECT queries is true?

Options:

A.

They can be used to purge log entries from the database.

B.

They must be followed immediately by a WHEREclause.

C.

They can be used to display the database schema.

D.

They are not used in macros.

Question 9

After generating a report, you notice the information you where expecting to see is not included in it. However, you confirm that the logs are there.

Options:

A.

Check the time frame covered by thereport.

B.

Disable auto-cache.

C.

Increase the report utilization quota.

D.

Test the dataset

Question 10

You are tasked with finding logs corresponding to a suspected attack on your network.

You need to use an interface where all identified threats within timeframe are listed and organized. You also need to be able to quickly export the information to a PDF file.

Where can you go to accomplish this task?

Options:

A.

Log Browse

B.

Log View

C.

Fabric View

D.

FortiView

Question 11

Exhibit.

What is the purpose of using the Chart Builder feature On FortiAnalyzer?

Options:

A.

To build a chart automatically based on the top 100 log entries

B.

To add charts directly to generatereports in the current ADOM.

C.

To add a new chart under FortiView to be used in new reports

D.

To build a dataset and chart based on the filtered search results

Question 12

What are the two methods you can use to send notifications when an event is generated by an event handler? (Choose two answers)

Options:

A.

Send SNMP trap.

B.

Send an alert through the FortiGuard server.

C.

Send an alert through Fabric connectors.

D.

Send SMS notification

Question 13

You need to move reports between two ADOMs.

Which two statements are true? (Choose two.)

Options:

A.

The ADOMs must be compatible types.

B.

The date and time will be appended to the original report name to avoid conflicts.

C.

All charts and datasets associated with the report will be imported together.

D.

You need to convert the reports into templates first.

Question 14

You mustfind a specific security event log in the FortiAnalyzer logs displayed in FortiView, but, so far, you have been uncuccessful.

Which two tasks should you perform to investigate why you are having this issue? (Choose two.)

Options:

A.

Open .gz log files in FortiView.

B.

Rebuild the SQL database and check FortiView.

C.

Review the ADOM data policy

D.

Check logs in the Log Browse

Question 15

(Refer to the exhibit.

Which two observations can you make after reviewing this log entry? (Choose two answers))

Options:

A.

This is a normalized log.

B.

This is a formatted view of the log.

C.

This is the original log that FortiAnalyzer received from FortiGate.

D.

This log is in a raw log format.

Question 16

Which statement describes archive logs on FortiAnalyzer?

Options:

A.

Logs that are indexed and stored in the SQL database

B.

Logs a FortiAnalyzer administrator can access in FortiView

C.

Logs compressed and saved in files with the .gz extension

D.

Logs previously collected from devices that are offline

Question 17

(Refer to the exhibit.

Which statement about the displayed event is correct? (Choose one answer))

Options:

A.

An incident was created from this event.

B.

The risk source is isolated.

C.

The security risk was escalated.

D.

The security event risk is considered open.

Question 18

Which statement about sending notifications with incident update is true?

Options:

A.

You can send notifications to multiple external platforms.

B.

Notifications can be sent only by email.

C.

If you use multiple fabric connectors, all connectors must have the same settings.

D.

Notifications can be sent only when an incident is updated or deleted.

Question 19

Aplaybook contains five tasks in total. An administrator runs the playbook and four out of five tasks finish successfully, but one task fails.

What will be the status of the playbook after it is run?

Options:

A.

Attention required

B.

Upstream_failed

C.

Failed

D.

Success

Question 20

After a generated a repot, you notice the information you were expecting to see in not included in it. However, you confirm that the logs are there:

Which two actions should you perform? (Choose two.)

Options:

A.

Check the time frame covered by the report.

B.

Disable auto-cache.

C.

Increase the report utilization quota.

D.

Test the dataset.

Demo: 20 questions
Total 67 questions