Pre-Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > Fortinet > Fortinet Certified Professional Security Operations > FCP_FAZ_AN-7.6

FCP_FAZ_AN-7.6 Fortinet NSE 5 - FortiAnalyzer 7.6 Analyst Question and Answers

Question # 4

Which statement about automation connectors in FortiAnalyzer is true?

A.

An ADOM with the Fabric type comes with multiple connectors configured.

B.

The local connector becomes available after you configured any external connector.

C.

The local connector becomes available after you connectors are displayed.

D.

The actions available with FortiOS connectors are determined by automation rules configured on FortiGate.

Full Access
Question # 5

Which log will generate an event with the status Unhandled?

A.

An AV log with action=quarantine.

B.

An IPS log with action=pass.

C.

A WebFilter log with action=dropped.

D.

An AppControl log with action=blocked.

Full Access
Question # 6

Which two actions should an administrator take to view Compromised Hosts on FortiAnalyzer? (Choose two.)

A.

Enable device detection on the FortiGate devices that are sending logs to FortiAnalyzer.

B.

Enable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent to FortiAnalyzer.

C.

Make sure all endpoints are reachable by FortiAnalyzer.

D.

Subscribe FortiAnalyzer to FortiGuard to keep its local threat database up to date.

Full Access
Question # 7

Exhibit.

A FortiAnalyzer analyst is customizing a SQL query to use in a report.

Which SQL query should the analyst run to get the expected results?

A)

B)

C)

D)

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 8

(In a FortiAnalyzer Fabric deployment, which three modules from Fabric members are available for analysis on the supervisor? (Choose three answers))

A.

Playbooks

B.

Indicators

C.

Logs

D.

Events

E.

Reports

Full Access
Question # 9

(When there are no matching parsers for a device log, what does FortiAnalyzer do? (Choose one answer)

A.

Drops the log

B.

Applies the generic SYSLOG parser

C.

Stores the log but doesn’t normalize it

D.

Archives the log for future analysis

Full Access
Question # 10

What are the two methods you can use to send notifications when an event is generated by an event handler? (Choose two answers)

A.

Send SNMP trap.

B.

Send an alert through the FortiGuard server.

C.

Send an alert through Fabric connectors.

D.

Send SMS notification

Full Access
Question # 11

You are trying to configure a task in the playbook editor to run a report.

However, when you try to select the desired playbook, you do to see it listed.

What is the reason?

A.

The report does not have auto-cache and extended log filtering enabled.

B.

The playbook is currently running and will be available after it is finished.

C.

You must create a trigger to run the report first.

D.

The report has no result and must be reconfigured.

Full Access
Question # 12

An administrator on your team has configured multiple reports to run periodically. Management has an additional request that all new generated reports be sent to a company email inbox for accessibility. The mail server has already been configured on FortiAnalyzer.

Which item must configure on FortiAnalyzer so that emails are sent when the reports are generated?

A.

Enable the option to email all reports under the mail server.

B.

Add a mailto: < email address > option within the report layouts.

C.

Enable email notification under the report calendar.

D.

Enable an output profile on the reports.

Full Access
Question # 13

(How does FortiAnalyzer block indicators? (Choose one answer)

A.

It uses an automation script to update FortiGate with the block list.

B.

It uses a FortiManager connector to send the block list.

C.

It uses a FortiClient EMS connector to send the block list.

D.

It uses a webhook to allow FortiGate to send the block list.

Full Access
Question # 14

You created a playbook on FortiAnalyzer that uses a FortiOS connector.

When configuring the FortiGate side, which type of trigger must be used so that the actions in an automation stitch are available in the FortiOS connector?

A.

FortiAnalyzer Event Handler

B.

Fabric Connector event

C.

FortiOS Event Log

D.

Incoming webhook

Full Access
Question # 15

(Which two statements about FortiAnalyzer Fabric deployments are true? (Choose two answers)

A.

Supervisors can be in high availability (HA) for redundancy purposes only.

B.

Fabric members can operate in analyzer mode only.

C.

Fabric members do not forward their logs to the supervisor.

D.

Supervisors and members must be in the same time zone.

Full Access
Question # 16

After generating a report, you notice the information you were expecting to see is not included in it. However, you confirm that the logs are there:

Which two actions should you perform? (Choose two.)

A.

Check the time frame covered by the report.

B.

Disable auto-cache.

C.

Increase the report utilization quota.

D.

Test the dataset.

Full Access
Question # 17

Exhibit.

Laptop1 is used by several administrators to manage FortiAnalyzer. You want to configure a generic text filter that matches all login attempts to the web interface generated by any user other than admin’’, and coming from Laptop1.

Which filter will achieve the desired result?

A.

Operation-login and performed_on==’’GUI(10.1.1.100)’ and user!=admin

B.

Operation-login and performed_on==’’GU (10.1.1.120)’ and user!=admin

C.

Operation-login and srcip== 10.1.1.100 and dstip==10.1.1.1.210 and user==admin

D.

Operation-login and dstip==10.1.1.210 and user!-admin

Full Access
Question # 18

Which statement about the FortiSIEM management extension is correct?

A.

It allows you to manage the entire life cycle of a threat or breach.

B.

It can be installed as a dedicated VM.

C.

Its use of the available disk space is capped at 50%.

D.

It requires a licensed FortiSIEM supervisor.

Full Access
Question # 19

Which statement describes archive logs on FortiAnalyzer?

A.

Logs that are indexed and stored in the SQL database

B.

Logs a FortiAnalyzer administrator can access in FortiView

C.

Logs compressed and saved in files with the .gz extension

D.

Logs previously collected from devices that are offline

Full Access
Question # 20

Exhibit.

What is the purpose of using the Chart Builder feature on FortiAnalyzer?

A.

To build a chart automatically based on the top 100 log entries

B.

To add charts directly to generate reports in the current ADOM.

C.

To add a new chart under FortiView to be used in new reports

D.

To build a dataset and chart based on the filtered search results

Full Access
Question # 21

You are tasked with finding logs corresponding to a suspected attack on your network.

You need to use an interface where all identified threats within a timeframe are listed and organized. You also need to be able to quickly export the information to a PDF file.

Where can you go to accomplish this task?

A.

Log Browse

B.

Log View

C.

Fabric View

D.

FortiView

Full Access
Question # 22

Which two statements regarding the outbreak detection service are true? (Choose two.)

A.

An additional license is required.

B.

It automatically downloads new event handlers and reports.

C.

Outbreak alerts are available on the root ADOM only.

D.

New alerts are received by email.

Full Access
Question # 23

Exhibit.

What does the data point at 12:20 indicate?

A.

The log insert log time is increasing.

B.

FortiAnalyzer is using its cache to avoid dropping logs.

C.

The performance of FortiAnalyzer is below the baseline.

D.

The sqiplugind service is caught up with the logs

Full Access