New Year Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

FCP_FAZ_AN-7.6 Questions Bank

Fortinet NSE 5 - FortiAnalyzer 7.6 Analyst Questions and Answers

Question 9

Refer to the exhibit.

What can you conclude about the output?

Options:

A.

The low indexing values require investigation.

B.

The output is not ADOM specific.

C.

There are more event logs thantraffic logs.

D.

The log rate higher than the message rate is not normal.

Question 10

You mustfind a specific security event log in the FortiAnalyzer logs displayed in FortiView, but, so far, you have been uncuccessful.

Which two tasks should you perform to investigate why you are having this issue? (Choose two.)

Options:

A.

Open .gz log files in FortiView.

B.

Rebuild the SQL database and check FortiView.

C.

Review the ADOM data policy

D.

Check logs in the Log Browse

Question 11

What is the purpose of using data selectors when configuring event handlers?

Options:

A.

They filter the types of logs that FortiAnalyzer can accept from registered devices.

B.

They download new filters can be used in event handlers.

C.

They apply their filter criteria to the entire event handler so that you don’t have to configure the same criteria in the individual rules.

D.

They are common filters that can be appliedsimultaneously to all event handlers.

Question 12

(Which two statements about FortiAnalyzer Fabric deployments are true? (Choose two answers))

Options:

A.

Supervisors can be in high availability (HA) for redundancy purposes only.

B.

Fabric members can operate in analyzer mode only.

C.

Fabric members do not forward their logs to the supervisor.

D.

Supervisors and members must be in the same time zone.