New Year Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free and Premium Fortinet FCP_FAZ_AN-7.6 Dumps Questions Answers

Fortinet NSE 5 - FortiAnalyzer 7.6 Analyst Questions and Answers

Question 1

You created a playbook on FortiAnalyzer that uses a FortiOS connector.

When configuring the FortiGate side, which type of trigger must be used so that the actions in an automation stich are available in the FortiOS connector?

Options:

A.

FortiAnalyzer Event Handler

B.

Fabric Connector event

C.

FortiOS Event Log

D.

Incoming webhook

Buy Now
Question 2

After generating a report, you notice the information you where expecting to see is not included in it. However, you confirm that the logs are there.

Options:

A.

Check the time frame covered by thereport.

B.

Disable auto-cache.

C.

Increase the report utilization quota.

D.

Test the dataset

Question 3

(An analyst is using FortiAI on FortiAnalyzer to simplify certain tasks but is worried about exceeding the monthly token limit. Which query will take the fewest FortiAI tokens? (Choose one answer))

Options:

A.

Show logs for 192.168.1.10 (past week)

B.

Show all logs from the past week

C.

Can you show me all the log entries for the endpoint 192.168.1.10?

D.

Show logs for 192.168.1.10

Question 4

As part of your analysis, you discover that a Medium severity level incident is fully remediated.

You change the incident status to Closed:Remediated.

Which statement about your update is true?

Options:

A.

The incident can no longer be deleted.

B.

The corresponding event will be marked as Mitigated.

C.

The incident dashboard will be updated.

D.

The incident severity will be lowered.

Question 5

Which two statements about playbook execution are true? (Choose two)

Options:

A.

FortiAnalyzer will not commit changes made by a Failed playbook

B.

The Playbook Monitor provides troubleshooting logs

C.

You can run the default debugging playbook to investigate playbook errors.

D.

Even I the playbook status is Failed, individual tasks may have succeeded.

Question 6

What are two effects of enabling auto-cache in a FortiAnalyzer report? (Choose two.)

Options:

A.

The generation time for reports is decreased.

B.

When new logs are received, the hard-cache data is updated automatically.

C.

FortiAnalyzer local cache is used to store generated reports.

D.

The size of newly generated reports is optimized to conserve disk space.

Question 7

Exhibit.

What can you conclude about the output?

Options:

A.

The message ratebeing lower that the log rate is normal.

B.

Both messages and logs are almost finished indexing.

C.

There are more traffic logs than event logs.

D.

The output is ADOM specific

Question 8

Why must you wait for several minutes before you run a playbook that you just created?

Options:

A.

FortiAnalyzer needs that time to parse the new playbook.

B.

FortiAnalyzer needs that time to debug the new playbook.

C.

FortiAnalyzer needs that time to back up the current playbooks.

D.

FortiAnalyzer needs that time to ensure there are no other playbooks running.

Question 9

Refer to the exhibit.

What can you conclude about the output?

Options:

A.

The low indexing values require investigation.

B.

The output is not ADOM specific.

C.

There are more event logs thantraffic logs.

D.

The log rate higher than the message rate is not normal.

Question 10

You mustfind a specific security event log in the FortiAnalyzer logs displayed in FortiView, but, so far, you have been uncuccessful.

Which two tasks should you perform to investigate why you are having this issue? (Choose two.)

Options:

A.

Open .gz log files in FortiView.

B.

Rebuild the SQL database and check FortiView.

C.

Review the ADOM data policy

D.

Check logs in the Log Browse

Question 11

What is the purpose of using data selectors when configuring event handlers?

Options:

A.

They filter the types of logs that FortiAnalyzer can accept from registered devices.

B.

They download new filters can be used in event handlers.

C.

They apply their filter criteria to the entire event handler so that you don’t have to configure the same criteria in the individual rules.

D.

They are common filters that can be appliedsimultaneously to all event handlers.

Question 12

(Which two statements about FortiAnalyzer Fabric deployments are true? (Choose two answers))

Options:

A.

Supervisors can be in high availability (HA) for redundancy purposes only.

B.

Fabric members can operate in analyzer mode only.

C.

Fabric members do not forward their logs to the supervisor.

D.

Supervisors and members must be in the same time zone.

Question 13

Which statement regarding macros on FortiAnalyzer is true?

Options:

A.

Macros are predefined templates for reports and cannot be customized.

B.

Macros are useful in generating excel log files automatically based on the report settings.

C.

Macros are ADOM-specific and each ADOM type have unique macros relevant to that ADOM.

D.

Macros are supported only on the FortiGate ADOMs.

Question 14

Refer to Exhibit:

Whatdoes the data point at 21:20 indicate?

Options:

A.

FortiAnalyzer is indexing logs faster than logs are being received.

B.

The fortilogd daemon is ahead in indexing by one log.

C.

The SQL database requires a rebuild because of high receive lag.

D.

FortiAnalyzer is temporarily buffering received logs so older logs can be indexed first.

Question 15

Exhibit.

What does the data point at 12:20 indicate?

Options:

A.

The loginsert log time is increasing.

B.

FortiAnalyzer is using its cache to avoid dropping logs.

C.

The performance of FortiAnalyzer is below the baseline.

D.

The sqiplugind service is caught up with the logs

Question 16

Which statement correctly describes one Difference between templates and reports?

Options:

A.

Reports provide mora configuration options than templates

B.

Templates can becloned, but reports cannot be cloned.

C.

Reports support macros, but templates do not.

D.

Template are mapped to device groups. while reports are mapped to ADOMs

Question 17

Which SQL query is in the correct order to query to database in the FortiAnalyzer?

Options:

A.

SELECT devid FROM $log GROUP BY devid WHERE ‘user’,,’ users1’

B.

SELECT FROM $log WHERE devid ‘user’,, USER1’ GROUP BY devid

C.

SELCT devid WHERE ’user’-‘ USER1’ FROM $log GROUP By devid

D.

SELECT devid FROM $log WHERE ‘user’=’ GROUP BY devid