Week end Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70special

Fortinet FCP_FAZ_AN-7.6 Fortinet NSE 5 - FortiAnalyzer 7.6 Analyst Exam Practice Test

Fortinet NSE 5 - FortiAnalyzer 7.6 Analyst Questions and Answers

Testing Engine

  • Product Type: Testing Engine
$37.5  $124.99

PDF Study Guide

  • Product Type: PDF Study Guide
$33  $109.99
Question 1

What is the purpose of running the command diagnose sql status sqlreportd?

Options:

A.

To view a list of scheduled reports

B.

To list the current SQL processes running

C.

To display the SQL query connections and hcache status

D.

To identify the database log insertion status

Question 2

(Refer to the exhibit.

Which statement about the displayed event is correct? (Choose one answer))

Options:

A.

The security risk was dropped.

B.

The risk source is isolated.

C.

The security risk was blocked.

D.

The security event risk is from an application control log.

Question 3

(Which two parameters does FortiAnalyzer use to identify an indicator of compromise (IOC)? (Choose two answers))

Options:

A.

IP address

B.

URL

C.

Policy ID

D.

Application category

Question 4

As part of your analysis, you discover that an incident is a false positive.

You change the incident status to Closed: False Positive.

Which statement about your update is true?

Options:

A.

The audit history log will be updated.

B.

The corresponding event will be marked as mitigated.

C.

The incident will bedeleted.

D.

The incident number will be changed

Question 5

Exhibit.

What can you conclude about the output?

Options:

A.

The message ratebeing lower that the log rate is normal.

B.

Both messages and logs are almost finished indexing.

C.

There are more traffic logs than event logs.

D.

The output is ADOM specific

Question 6

Which statement about SQL SELECT queries is true?

Options:

A.

They can be used to purge log entries from the database.

B.

They must be followed immediately by a WHEREclause.

C.

They can be used to display the database schema.

D.

They are not used in macros.

Question 7

What is the purpose of playbook trigger variables?

Options:

A.

To display statistics about the playbook runtime

B.

To use information from the trigger to filter the action in a task

C.

To provide the trigger information to make the playbook start running

D.

To store the start the times of playbooks with On_Schedule triggers

Question 8

You mustfind a specific security event log in the FortiAnalyzer logs displayed in FortiView, but, so far, you have been uncuccessful.

Which two tasks should you perform to investigate why you are having this issue? (Choose two.)

Options:

A.

Open .gz log files in FortiView.

B.

Rebuild the SQL database and check FortiView.

C.

Review the ADOM data policy

D.

Check logs in the Log Browse

Question 9

(When there are no matching parsers for a device log, what does FortiAnalyzer do? (Choose one answer))

Options:

A.

Drops the log

B.

Applies the generic SYSLOG parser

C.

Stores the log but doesn’t normalize it

D.

Archives the log for future analysis

Question 10

Which statement describes archive logs on FortiAnalyzer?

Options:

A.

Logs that are indexed and stored in the SQL database

B.

Logs a FortiAnalyzer administrator can access in FortiView

C.

Logs compressed and saved in files with the .gz extension

D.

Logs previously collected from devices that are offline

Question 11

Which two statement regarding the outbreak detection service are true? (Choose two.)

Options:

A.

An additional license is required.

B.

It automatically downloads new event handlers and reports.

C.

Outbreak alerts are available on the root ADOM only.

D.

New alerts are received by email.

Question 12

You are tasked with finding logs corresponding to a suspected attack on your network.

You need to use an interface where all identified threats within timeframe are listed and organized. You also need to be able to quickly export the information to a PDF file.

Where can you go to accomplish this task?

Options:

A.

Log Browse

B.

Log View

C.

Fabric View

D.

FortiView

Question 13

(Refer to the exhibit.

Which two observations can you make after reviewing this log entry? (Choose two answers))

Options:

A.

This is a normalized log.

B.

This is a formatted view of the log.

C.

This is the original log that FortiAnalyzer received from FortiGate.

D.

This log is in a raw log format.

Question 14

Which statement about automation connectors in FortiAnalyzer is true?

Options:

A.

An ADOM with the Fabric type comes with multiple connectors configured.

B.

The local connector becomes available after you configured any external connector.

C.

The local connector becomes available after you connectors are displayed.

D.

The actions available with FortiOS connectors are determined by automation rules configured on FortiGate.

Question 15

Exhibit.

Which statement about the event displayed is correct?

Options:

A.

The risk source is isolated.

B.

The security risk was blocked or dropped.

C.

The security event risk is considered open.

D.

An incident was created from this event.

Question 16

Which two statements about playbook execution are true? (Choose two)

Options:

A.

FortiAnalyzer will not commit changes made by a Failed playbook

B.

The Playbook Monitor provides troubleshooting logs

C.

You can run the default debugging playbook to investigate playbook errors.

D.

Even I the playbook status is Failed, individual tasks may have succeeded.

Question 17

Which statement about exporting items in Report Definitions is true?

Options:

A.

Templates can be exported.

B.

Template exports contain associated charts and datasets.

C.

Chart exports contain associated datasets.

D.

Datasets can be exported.

Question 18

Refer to Exhibit:

Whatdoes the data point at 21:20 indicate?

Options:

A.

FortiAnalyzer is indexing logs faster than logs are being received.

B.

The fortilogd daemon is ahead in indexing by one log.

C.

The SQL database requires a rebuild because of high receive lag.

D.

FortiAnalyzer is temporarily buffering received logs so older logs can be indexed first.

Question 19

(Which two statements about FortiAnalyzer Fabric deployments are true? (Choose two answers))

Options:

A.

Supervisors can be in high availability (HA) for redundancy purposes only.

B.

Fabric members can operate in analyzer mode only.

C.

Fabric members do not forward their logs to the supervisor.

D.

Supervisors and members must be in the same time zone.

Question 20

After generating a report, you notice the information you where expecting to see is not included in it. However, you confirm that the logs are there.

Options:

A.

Check the time frame covered by thereport.

B.

Disable auto-cache.

C.

Increase the report utilization quota.

D.

Test the dataset