Summer Special - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: top65certs

Free and Premium Fortinet FCP_FAZ_AN-7.4 Dumps Questions Answers

FCP - FortiAnalyzer 7.4 Analyst Questions and Answers

Question 1

Exhibit.

Assume these are all the events that exist on the FortiAnalyzer device.

How many events will be added to the incident created after running this playbook?

Options:

A.

Eleven events will be added.

B.

Seven events will be added

C.

No events will be added.

D.

Four events will be added.

Buy Now
Question 2

Which statement about SQL SELECT queries is true?

Options:

A.

They can be used to purge log entries from the database.

B.

They must be followed immediately by a WHERE clause.

C.

They can be used to display the database schema.

D.

They are not used in macros.

Question 3

Which statement regarding macros on FortiAnalyzer is true?

Options:

A.

Macros are predefined templates for reports and cannot be customized.

B.

Macros are useful in generating excel log files automatically based on the report settings.

C.

Macros are ADOM-specific and each ADOM type have unique macros relevant to that ADOM.

D.

Macros are supported only on the FortiGate ADOMs.

Question 4

You must find a specific security event log in the FortiAnalyzer logs displayed in FortiView, but, so far, you have been uncuccessful.

Which two tasks should you perform to investigate why you are having this issue? (Choose two.)

Options:

A.

Open .gz log files in FortiView.

B.

Rebuild the SQL database and check FortiView.

C.

Review the ADOM data policy

D.

Check logs in the Log Browse

Question 5

You find that as part of your role as an analyst, you frequently search log View using the same parameters.

Instead of defining your search filters repeatedly, what can you do to save time?

Options:

A.

Configure a custom dashboard.

B.

Configure a custom view.

C.

Configure a data selector.

D.

Configure a marco and apply it to device groups.

Question 6

After generating a report, you notice the information you where expecting to see is not included in it. However, you confirm that the logs are there.

Options:

A.

Check the time frame covered by the report.

B.

Disable auto-cache.

C.

Increase the report utilization quota.

D.

Test the dataset

Question 7

Which log will generate an event with the status Unhandled?

Options:

A.

An AV log with action=quarantine.

B.

An IPS log with action=pass.

C.

A WebFilter log will action=dropped.

D.

An AppControl log with action=blocked.

Question 8

Exhibit.

What can you conclude about these search results? (Choose two.)

Options:

A.

They can be downloaded to a file.

B.

They are sortable by columns and customizable.

C.

They are not available for analysis in FortiView.

D.

They were searched by using text mode.

Question 9

Which two statements about exporting and importing playbacks are true? (Choose two.)

Options:

A.

A playbook that was disabled when it was exported mil be disabled when it is imported.

B.

Playbooks can so imported 10 a different FortiAnayzer device, but only if the connectors already exist

C.

You can import a playbook even if there is another one win the same name in the destination

D.

You can export only one playbook at a time.

Question 10

Exhibit.

What is the purpose of using the Chart Builder feature On FortiAnalyzer?

Options:

A.

To build a chart automatically based on the top 100 log entries

B.

To add charts directly to generate reports in the current ADOM.

C.

To add a new chart under FortiView to be used in new reports

D.

To build a dataset and chart based on the filtered search results

Question 11

Which statement about exporting items in Report Definitions is true?

Options:

A.

Templates can be exported.

B.

Template exports contain associated charts and datasets.

C.

Chart exports contain associated datasets.

D.

Datasets can be exported.

Question 12

Which two statements regarding FortiAnalyzer operating modes are true? (Choose two.)

Options:

A.

When running in collector mode, FortiAnalyzer can forward logs to a syslog server.

B.

FortiAnalyzer runs in collector mode by default unless it is configured for HA.

C.

You can create and edit reports when FortiAnalyzer is running in collector mode.

D.

A topology with FortiAnalyzeer devices running in both modes can improve their performance.

Question 13

What is the purpose of using data selectors when configuring event handlers?

Options:

A.

They filter the types of logs that FortiAnalyzer can accept from registered devices.

B.

They download new filters can be used in event handlers.

C.

They apply their filter criteria to the entire event handler so that you don’t have to configure the same criteria in the individual rules.

D.

They are common filters that can be applied simultaneously to all event handlers.

Question 14

After a generated a repot, you notice the information you were expecting to see in not included in it. However, you confirm that the logs are there:

Which two actions should you perform? (Choose two.)

Options:

A.

Check the time frame covered by the report.

B.

Disable auto-cache.

C.

Increase the report utilization quota.

D.

Test the dataset.

Question 15

What is the purpose of running the command diagnose sql status sqlreportd?

Options:

A.

To view a list of scheduled reports

B.

To list the current SQL processes running

C.

To display the SQL query connections and hcache status

D.

To identify the database log insertion status

Question 16

Exhibit.

What can you conclude from this output?

Options:

A.

There is not disk quota allocated to quarantining files.

B.

FGT_B is the Security Fabric root.

C.

The allocated disk quote to ADOM1 is 3 GB.

D.

Archive logs are using more space than analytic logs.