Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Fortinet FCP_FAZ_AN-7.6 Fortinet NSE 5 - FortiAnalyzer 7.6 Analyst Exam Practice Test

Demo: 23 questions
Total 79 questions

Fortinet NSE 5 - FortiAnalyzer 7.6 Analyst Questions and Answers

Question 1

Refer to the exhibit.

An analyst is using FortiView to look at the top threats recorded by FortiAnalyzer in the last 2 hours. What can the analyst conclude from the exhibit? (Choose one answer)

Options:

A.

There are cross-site scripting (XSS) attacks on an Apache web server.

B.

The attacks that have CVE IDs attached require priority attention.

C.

Only IPS threats constitute genuine threats.

D.

There are no critical level threats.

Question 2

Exhibit.

What can you conclude from this output?

Options:

A.

There is no disk quota allocated to quarantining files.

B.

FGT_B is the Security Fabric root.

C.

The allocated disk quota to ADOM1 is 3 GB.

D.

Archive logs are using more space than analytic logs.

Question 3

Exhibit.

What is the analyst trying to create?

Options:

A.

The analyst is trying to create a trigger variable to the used in the playbook.

B.

The analyst is trying to create an output variable to be used in the playbook.

C.

The analyst is trying to create a report in the playbook.

D.

The analyst is trying to create a SOC report in the playbook.

Question 4

(Which two parameters does FortiAnalyzer use to identify an indicator of compromise (IOC)? (Choose two answers)

Options:

A.

IP address

B.

URL

C.

Policy ID

D.

Application category

Question 5

Which three types of logs does FortiAnalyzer collect from FortiGate devices for normalization? (Choose three.)

Options:

A.

Security

B.

Event

C.

Traffic

D.

Firewall

E.

System

Question 6

Exhibit.

Laptop1 is used by several administrators to manage FortiAnalyzer. You want to configure a generic text filter that matches all login attempts to the web interface generated by any user other than admin’’, and coming from Laptop1.

Which filter will achieve the desired result?

Options:

A.

Operation-login and performed_on==’’GUI(10.1.1.100)’ and user!=admin

B.

Operation-login and performed_on==’’GU (10.1.1.120)’ and user!=admin

C.

Operation-login and srcip== 10.1.1.100 and dstip==10.1.1.1.210 and user==admin

D.

Operation-login and dstip==10.1.1.210 and user!-admin

Question 7

After generating a report, you notice the information you were expecting to see is not included in it. However, you confirm that the logs are there:

Which two actions should you perform? (Choose two.)

Options:

A.

Check the time frame covered by the report.

B.

Disable auto-cache.

C.

Increase the report utilization quota.

D.

Test the dataset.

Question 8

Exhibit.

What can you conclude about the output?

Options:

A.

The message rate being lower that the log rate is normal.

B.

Both messages and logs are almost finished indexing.

C.

There are more traffic logs than event logs.

D.

The output is ADOM-specific

Question 9

A playbook contains five tasks in total. An administrator runs the playbook and four out of five tasks finish successfully, but one task fails.

What will be the status of the playbook after it is run?

Options:

A.

Attention required

B.

Upstream_failed

C.

Failed

D.

Success

Question 10

Which two statements about local logs on FortiAnalyzer are true? (Choose two.)

Options:

A.

They are not supported in FortiView.

B.

You can view playbook logs for all ADOMs in the root ADOM.

C.

Event logs show system-wide information, whereas application logs are ADOM-specific.

D.

Event logs are available only in the root ADOM.

Question 11

Exhibit.

What can you conclude about these search results? (Choose two.)

Options:

A.

They can be downloaded to a file.

B.

They are sortable by columns and customizable.

C.

They are not available for analysis in FortiView.

D.

They were searched by using text mode.

Question 12

(Which two statements about FortiAnalyzer Fabric deployments are true? (Choose two answers)

Options:

A.

Supervisors can be in high availability (HA) for redundancy purposes only.

B.

Fabric members can operate in analyzer mode only.

C.

Fabric members do not forward their logs to the supervisor.

D.

Supervisors and members must be in the same time zone.

Question 13

Which two statements regarding FortiAnalyzer operating modes are true? (Choose two.)

Options:

A.

When running in collector mode, FortiAnalyzer can forward logs to a syslog server.

B.

FortiAnalyzer runs in collector mode by default unless it is configured for HA.

C.

You can create and edit reports when FortiAnalyzer is running in collector mode.

D.

A topology with FortiAnalyzer devices running in both modes can improve their performance.

Question 14

Which statement correctly describes one Difference between templates and reports?

Options:

A.

Reports provide more configuration options than templates

B.

Templates can be cloned, but reports cannot be cloned.

C.

Reports support macros, but templates do not.

D.

Template are mapped to device groups. while reports are mapped to ADOMs

Question 15

What is the purpose of playbook trigger variables?

Options:

A.

To display statistics about the playbook runtime

B.

To use information from the trigger to filter the action in a task

C.

To provide the trigger information to make the playbook start running

D.

To store the start the times of playbooks with On_Schedule triggers

Question 16

Which three tasks can be performed on FortiAnalyzer using FortiAI? (Choose three.)

Options:

A.

Configure site-to-site VPN using FortiAI.

B.

Perform Incident investigation and response.

C.

Identify potential impacts and recommend remediation.

D.

Configure SD-WAN overlay using FortiAI.

E.

Perform threat hunting.

Question 17

What is the purpose of running the command diagnose sql status sqlreportd?

Options:

A.

To view a list of scheduled reports

B.

To list the current SQL processes running

C.

To display the SQL query connections and hcache status

D.

To identify the database log insertion status

Question 18

What happens when the indicator of compromise (IOC) engine on FortiAnalyzer finds web logs that match blacklisted IP addresses?

Options:

A.

FortiAnalyzer flags the associated host for further analysis.

B.

A new infected entry is added for the corresponding endpoint under Compromised Hosts.

C.

The detection engine classifies those logs as Suspicious.

D.

The endpoint is marked as Compromised and, optionally, can be put in quarantine.

Question 19

Which statement about SQL SELECT queries is true?

Options:

A.

They can be used to purge log entries from the database.

B.

They must be followed immediately by a WHERE clause.

C.

They can be used to display the database schema.

D.

They are not used in macros.

Question 20

Which statement about automation connectors in FortiAnalyzer is true?

Options:

A.

An ADOM with the Fabric type comes with multiple connectors configured.

B.

The local connector becomes available after you configured any external connector.

C.

The local connector becomes available after you connectors are displayed.

D.

The actions available with FortiOS connectors are determined by automation rules configured on FortiGate.

Question 21

Exhibit.

Based on the partial outputs displayed, which devices can be members of a FortiAnalyzer Fabric?

Options:

A.

FortiAnalyzer1 and FortiAnalyzer3

B.

FortiAnalyzer1 and FortiAnalyzer2

C.

FortiAnalyzer2 and FortiAnalyzer3

D.

All devices listed can be members.

Question 22

Refer to the exhibit.

An analyst is trying to create a dataset to pull all gambling websites that were visited by end users.

Which SQL query on FortiAnalyzer will give the result shown in the exhibit?

Options:

A.

[Selected] select srcip as " SourceIP " , dstip as " DestIP " , url from $log where catdesc = ' Gambling '

B.

select srcip as " SourceIPv6 " , dstip as " DestIPv6 " , url from $log where catdesc = ' Gambling '

C.

select srcip as " SourceIP " , dstip as " DestIP " , url from $log where catdesc = ' Dating '

D.

select srcip as " SourceIP " , dstip as " DestIP " , url from ' Gambling ' where catdesc = $log

Question 23

What are the two methods you can use to send notifications when an event is generated by an event handler? (Choose two answers)

Options:

A.

Send SNMP trap.

B.

Send an alert through the FortiGuard server.

C.

Send an alert through Fabric connectors.

D.

Send SMS notification

Demo: 23 questions
Total 79 questions