Weekend Special Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Fortinet FCP_FAZ_AD-7.4 FCP - FortiAnalyzer 7.4 Administrator Exam Practice Test

Page: 1 / 18
Total 178 questions

FCP - FortiAnalyzer 7.4 Administrator Questions and Answers

Question 1

What is Log Insert Lag Time on FortiAnalyzer?

Options:

A.

The number of times in the logs where end users experienced slowness while accessing resources.

B.

The amount of lag time that occurs when the administrator is rebuilding the ADOM database.

C.

The amount of time that passes between the time a log was received and when it was indexed on FortiAnalyzer.

D.

The amount of time FortiAnalyzer takes to receive logs from a registered device

Question 2

You have recently grouped multiple FortiGate devices into a single ADOM. System Settings > Storage Info

shows the quota used.

What does the disk quota refer to?

Options:

A.

The maximum disk utilization for each device in the ADOM

B.

The maximum disk utilization for the FortiAnalyzer model

C.

The maximum disk utilization for the ADOM type

D.

The maximum disk utilization for all devices in the ADOM

Question 3

A playbook contains five tasks in total. An administrator runs the playbook and four out of five tasks finish successfully, but one task fails. What will be the status of the playbook after it is run?

Options:

A.

Running

B.

Failed

C.

Upstream_failed

D.

Success

Question 4

Which two statements are correct regarding the export and import of playbooks? (Choose two.)

Options:

A.

You can export only one playbook at a time.

B.

You can import a playbook even if there is another one with the same name in the destination.

C.

Playbooks can be exported and imported only within the same FortiAnaryzer.

D.

A playbook that was disabled when it was exported, will be disabled when it is imported.

Question 5

In the FortiAnalyzer FortiView, source and destination IP addresses from FortiGate devices are not resolving to a hostname.

How can you resolve the source and destination IP addresses, without introducing any additional performance impact to FortiAnalyzer?

Options:

A.

Resolve IP addresses on a per-ADOM basis to reduce delay on FortiView while IPs resolve

B.

Configure # set resolve-ip enable in the system FortiView settings

C.

Configure local DNS servers on FortiAnalyzer

D.

Resolve IP addresses on FortiGate

Question 6

Which two statements about high availability (HA) on FortiAnalyzer are true? (Choose two.)

Options:

A.

FortiAnalyzer HA supports synchronization of logs as well as some system and configuration settings.

B.

FortiAnalyzer HA active-passive mode can function without VRRP.

C.

All devices in a FortiAnalyzer HA cluster must run in the same operation mode, either analyzer mode or collector mode.

D.

All devices in a FortiAnalyzer HA cluster must have the same available disk space.

Question 7

What is the recommended method of expanding disk space on a FortiAnalyzer VM?

Options:

A.

From the VM host manager, add an additional virtual disk and use the #execute lvm extend command to expand the storage

B.

From the VM host manager, expand the size of the existing virtual disk

C.

From the VM host manager, expand the size of the existing virtual disk and use the # execute format disk command to reformat the disk

D.

From the VM host manager, add an additional virtual disk and rebuild your RAID array

Question 8

What are analytics logs on FortiAnalyzer?

Options:

A.

Logs that are saved in the active log file with the. log extension.

B.

Logs that are compressed and saved to a log file with the, gz extension.

C.

Logs that are rolled over when the log file reaches a specific size.

D.

Logs that are indexed and stored in the SQL database.

Question 9

Refer to the exhibit.

Question # 9

What is the purpose of using the Chart Builder feature on FortiAnalyzer?

Options:

A.

In Log View, this feature allows you to build a dataset and chart automatically, based on the filtered search results.

B.

In Log View, this feature allows you to build a chart and chart automatically, on the top 100 log entries.

C.

This feature allows you to build a chart under FortiView.

D.

You can add charts to generated reports using this feature.

Question 10

If you upgrade your FortiAnalyzer firmware, what report elements can be affected?

Options:

A.

Output profiles

B.

Report settings

C.

Report scheduling

D.

Custom datasets

Question 11

How does FortiAnalyzer retrieve specific log data from the database?

Options:

A.

SQL FROM statement

B.

SQL GET statement

C.

SQL SELECT statement

D.

SQL EXTRACT statement

Question 12

You are trying to initiate an authorization request from FortiGate to FortiAnalyzer, but the Security Fabric window does not open when you click Authorize.

Which two reasons can cause this to happen? (Choose two.)

Options:

A.

A pre-shared key needs to be established on both sides.

B.

The management computer does not have connectivity to the authorization IP address and port combination.

C.

The Security Fabric root is unauthorized and needs to be added as a trusted host.

D.

The fabric authorization settings on FortiAnalyzer are misconfigured.

Question 13

What is required to authorize a FortiGate on FortiAnalyzer using Fabric authorization?

Options:

A.

A FortiGate ADOM

B.

The FortiGate serial number

C.

A pre-shared key

D.

Valid FortiAnalyzer credentials

Question 14

Which SQL query is in the correct order to query the database in the FortiAnslyzer?

Options:

A.

SELECT devid FROM Slog GROOP BY devid WHERE * user' =* USERl'

B.

SELECT devid WHERE 'u3er'='USERl' FROM $ log GROUP BY devid

C.

SELECT devid FROM Slog- WHERE *user' =' USERl' GROUP BY devid

D.

FROM Slog WHERE 'user* =' USERl' SELECT devid GROUP BY devid

Question 15

For which two SAML roles can the FortiAnalyzer be configured? (Choose two.)

Options:

A.

Principal

B.

Service provider

C.

Identity collector

D.

Identity provider

Question 16

Which two statements regarding FortiAnalyzer log forwarding modes are true? (Choose two.)

Options:

A.

Both modes, forwarding and aggregation, support encryption of logs between devices.

B.

In aggregation mode, you can forward logs to syslog and CEF servers.

C.

Forwarding mode forwards logs in real time only to other FortiAnalyzer devices.

D.

Aggregation mode stores logs and content files and uploads them to another FortiAnalyzer device at a scheduled time.

Question 17

Refer to the exhibits.

Question # 17

Question # 17

How many events will be added to the incident created after running this playbook?

Options:

A.

Ten events will be added.

B.

No events will be added.

C.

Five events will be added.

D.

Thirteen events will be added.

Question 18

Which two statements are true regarding FortiAnalyzer operating modes? (Choose two.)

Options:

A.

When in collector mode, FortiAnalyzer collects logs from multiple devices and forwards these logs in the original binary format.

B.

Collector mode is the default operating mode.

C.

When in collector mode. FortiAnalyzer supports event management and reporting features.

D.

By deploying different FortiAnalyzer devices with collector and analyzer mode in a network, you can improve the overall performance of log receiving, analysis, and reporting

Question 19

Which two statements are true regarding log fetching on FortiAnalyzer? (Choose two.)

Options:

A.

A FortiAnalyzer device can perform either the fetch server or client role, and it can perform two roles at the same time with the same FortiAnalyzer devices at the other end.

B.

Log fetching can be done only on two FortiAnalyzer devices that are running the same firmware version.

C.

Log fetching allows the administrator to fetch analytics logs from another FortiAnalyzer for redundancy.

D.

Log fetching allows the administrator to run queries and reports against historical data by retrieving archived logs from one FortiAnalyzer device and sending them to another FortiAnalyzer device.

Question 20

Which process is responsible for enforcing the log file size?

Options:

A.

oftpd

B.

miglogd

C.

sqlplugind

D.

logfiled

Question 21

What does the disk status Degraded mean for RAID management?

Options:

A.

One or more drives are missing from the FortiAnalyzer unit. The drive is no longer available to the operating system.

B.

The FortiAnalyzer device is writing to all the hard drives on the device in order to make the array fault tolerant.

C.

The FortiAnalyzer device is writing data to a newly added hard drive in order to restore the hard drive to an optimal state.

D.

The hard driveiIs no longer being used by the RAID controller

Question 22

Which two actions should an administrator take to view Compromised Hosts on FortiAnalyzer? (Choose two.)

Options:

A.

Enable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent to FortiAnalyzer.

B.

Make sure all endpoints are reachable by FortiAnalyzer.

C.

Enable device detection on an interface on the FortiGate devices that are connected to the FortiAnalyzer device.

D.

Subscribe FortiAnalyzer to FortiGuard to keep its local threat database up to date.

Question 23

Which two statements are true regarding the outbreak detection service? (Choose two.)

Options:

A.

New alerts are received by email.

B.

Outbreak alerts are available on the root ADOM only.

C.

An additional license is required.

D.

It automatically downloads new event handlers and reports.

Question 24

Which statements are correct regarding FortiAnalyzer reports? (Choose two)

Options:

A.

FortiAnalyzer provides the ability to create custom reports.

B.

FortiAnalyzer glows you to schedule reports to run.

C.

FortiAnalyzer includes pre-defined reports only.

D.

FortiAnalyzer allows reporting for FortiGate devices only.

Question 25

Which statement about the FortiSOAR management extension is correct?

Options:

A.

It requires a FortiManager configured to manage FortiGate

B.

It requires a dedicated FortiSOAR device or VM.

C.

It does not include a limited trial by default.

D.

It runs as a docker container on FortiAnalyzer

Question 26

Which clause is considered mandatory in SELECT statements used by the FortiAnalyzer to generate reports?

Options:

A.

FROM

B.

LIMIT

C.

WHERE

D.

ORDER BY

Question 27

Which statement correctly describes the management extensions available on FortiAnalyzer?

Options:

A.

Management extensions do not require additional licenses.

B.

Management extensions allow FortiAnalyzer to act as a ForbSIEM supervisor.

C.

Management extensions require a dedicated VM for best performance.

D.

Management extensions may require a minimum number of CPU cores to run.

Question 28

Refer to the exhibit.

Question # 28

Which image corresponds to the packet capture shown in the exhibit?

Question # 28

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 29

A rogue administrator was accessing FortiAnalyzer without permission, and you are tasked to see what activity was performed by that rogue administrator on FortiAnalyzer.

What can you do on FortiAnalyzer to accomplish this?

Options:

A.

Click FortiView and generate a report for that administrator.

B.

Click Task Monitor and view the tasks performed by that administrator.

C.

Click Log View and generate a report for that administrator.

D.

View the tasks performed by the rogue administrator in Fabric View.

Question 30

Which statement when you are upgrading the firmware on an HA cluster made up of three FortiAnalyzer devices is true?

Options:

A.

You can perform the firmware upgrade using only a console connection.

B.

All FortiAnalyzer devices will be upgraded at the same time.

C.

Enabling uninterruptible-upgrade prevents normal operations from being interrupted during the upgrade.

D.

First, upgrade the secondary devices, and then upgrade the primary device.

Question 31

Refer to the exhibit.

Question # 31

Which two statements are true regarding enabling auto-cache on FortiAnalyzer? (Choose two.)

Options:

A.

Report size will be optimized to conserve disk space on FortiAnalyzer.

B.

Reports will be cached in the memory.

C.

This feature is automatically enabled for scheduled reports.

D.

Enabling auto-cache reduces report generation time for reports that require a long time to assemble datasets.

Question 32

Which two statements are true regarding FortiAnalyzer log forwarding? (Choose two.)

Options:

A.

Both modes, forwarding and aggregation, support encryption of logs between devices.

B.

In aggregation mode, you can forward logs to syslog and CEF servers as well.

C.

Aggregation mode stores logs and content files and uploads them to another FortiAnalyzer device at a scheduled time.

D.

Forwarding mode forwards logs in real time only to other FortiAnalyzer devices.

Question 33

What is the best approach to handle a hard disk failure on a FortiAnalyzer that supports hardware RAID?

Options:

A.

There is no need to do anything because the disk will self-recover.

B.

Run execute format disk to format and restart the FortiAnalyzer device.

C.

Perform a hot swap of the disk.

D.

Shut down FortiAnalyzer and replace the disk.

Question 34

Which two of the available registration methods place the device automatically in its assigned ADOM? {Choose two.)

Options:

A.

Serial number

B.

Pre-shared key

C.

Fabric Authorization

D.

Request from the device

Question 35

Which statements are true regarding securing communications between FortiAnalyzer and FortiGate with SSL? (Choose two.)

Options:

A.

SSL is the default setting.

B.

SSL communications are auto-negotiated between the two devices.

C.

SSL can send logs in real-time only.

D.

SSL encryption levels are globally set on FortiAnalyzer.

E.

FortiAnalyzer encryption level must be equal to, or higher than, FortiGate.

Question 36

An administrator, fortinet, can view logs and perform device management tasks, such as adding and removing registered devices. However, administrator fortinet is not able to create a mail server that can be used to send alert emails.

What can be the problem?

Options:

A.

ADOM mode is configured with Advanced mode.

B.

A trusted host is configured.

C.

fortinet is assigned the default Standard_User administrative profile.

D.

fortinet is assigned the default Restricted_User administrative profile.

Question 37

Which two parameters are used to calculate the Total Quota value available on FortiAnalyzer? (Choose two.)

Options:

A.

Used storage

B.

Retention policy

C.

Reserved space

D.

Total system storage

Question 38

Refer to the exhibit.

Question # 38

Based on the output, what can you conclude about the FortiAnalyzer logging status?

Options:

A.

The connection between FortiGate and FortiAnalyzer is overloaded.

B.

FortiGate has logs to send, but FortiAnalyzer is unavailable.

C.

FortiGate is configured to send logs in batches.

D.

FortiGate is sending logs again after it performed a reboot.

Question 39

If you upgrade the FortiAnalyzer firmware, which report element can be affected?

Options:

A.

Custom datasets

B.

Report scheduling

C.

Report settings

D.

Output profiles

Question 40

A play book contains five tasks in total. An administrator executed the playbook and four out of five tasks finished successfully, but one task failed. What will be the status of the playbook after its execution?

Options:

A.

Success

B.

Failed

C.

Running

D.

Upstream_failed

Question 41

Which two statement are true regardless initial Logs sync and Log Data Sync for Ha on FortiAnalyzer?

Options:

A.

By default, Log Data Sync is disabled on all backup devise.

B.

Log Data Sync provides real-time log synchronization to all backup devices.

C.

With initial Logs Sync, when you add a unit to an HA cluster, the primary device synchronizes its logs with the backup device.

D.

When Logs Data Sync is turned on, the backup device will reboot and then rebuilt the log database with the synchronized logs.

Question 42

Which two statements regarding ADOM modes are true? (Choose two.)

Options:

A.

In normal mode, the disk quota of the ADOM is fixed and cannot be modified, but in advanced mode, the disk quota of the ADOM is flexible.

B.

You can change ADOM modes only through the CLI.

C.

In an advanced mode ADOM, you can assign FortiGate VDOMs from a single FortiGate device to multiple FortiAnalyzer ADOMs.

D.

Normal mode is the default ADOM mode.

Question 43

Which daemon is responsible for enforcing the log file size?

Options:

A.

sqlplugind

B.

logfiled

C.

miglogd

D.

ofrpd

Question 44

Which two methods can you use to send event notifications when an event occurs that matches a configured

event handler? (Choose two.)

Options:

A.

SMS

B.

Email

C.

SNMP

D.

IM

Question 45

Which two statements about log forwarding are true? (Choose two.)

Options:

A.

Forwarded logs cannot be filtered to match specific criteria.

B.

Logs are forwarded in real-time only.

C.

The client retains a local copy of the logs after forwarding.

D.

You can use aggregation mode only with another FortiAnalyzer.

Question 46

What is the purpose of the FortiAnalyzer command diagnose system print netstat?

Options:

A.

It provides network statistics for active connections, including the protocols, IP addresses, and connection states.

B.

It provides the complete routing table, including directly connected routes.

C.

It provides the static DNS table, including the host names and their expiration timers.

D.

It provides NTP server information, including server IPs. stratum, poll time, and latency.

Question 47

An administrator has moved a FortiGate device from the root ADOM to ADOM1.

Which two statements are true regarding logs? (Choose two.)

Options:

A.

Analytics logs will be moved to ADOM1 from the root ADOM automatically.

B.

Archived logs will be moved to ADOM1 from the root ADOM automatically.

C.

Logs will be present in both ADOMs immediately after the move.

D.

Analytics logs will be moved to ADOM1 from the root ADOM after you rebuild the database.

Question 48

Which FortiAnalyzer feature allows you to use a proactive approach when managing your network security?

Options:

A.

Incidents dashboards

B.

Threat hunting

C.

FortiView Monitor

D.

Outbreak alert services

Question 49

Which two methods are the most common methods to control and restrict administrative access on FortiAnalyzer? (Choose two.)

Options:

A.

Virtual domains

B.

Administrative access profiles

C.

Trusted hosts

D.

Security Fabric

Question 50

Which two settings must you configure on FortiAnalyzer to allow non-local administrators to authenticate to FortiAnalyzer with any user account in a single LDAP group? (Choose two.)

Options:

A.

A local wildcard administrator account

B.

A remote LDAP server

C.

A trusted host profile that restricts access to the LDAP group

D.

An administrator group

Question 51

Logs are being deleted from one of the ADOMs earlier than the configured setting for archiving in the data

policy.

What is the most likely problem?

Options:

A.

CPU resources are too high

B.

Logs in that ADOM are being forwarded, in real-time, to another FortiAnalyzer device

C.

The total disk space is insufficient and you need to add other disk

D.

The ADOM disk quota is set too low, based on log rates

Question 52

Which statements are true regarding securing communications between FortiAnalyzer and FortiGate with IPsec? (Choose two.)

Options:

A.

Must configure the FortiAnalyzer end of the tunnel only--the FortiGate end is auto-negotiated.

B.

Must establish an IPsec tunnel ID and pre-shared key.

C.

IPsec cannot be enabled if SSL is enabled as well.

D.

IPsec is only enabled through the CLI on FortiAnalyzer.

Question 53

Which two elements are contained in a system backup created on FortiAnalyzer? (Choose two.)

Options:

A.

System information

B.

Logs from registered devices

C.

Report information

D.

Database snapshot

Page: 1 / 18
Total 178 questions