Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: geek65

FCP_FAZ_AD-7.4 FCP - FortiAnalyzer 7.4 Administrator Questions and Answers

Questions 4

Which two statements are true regarding log fetching on FortiAnalyzer? (Choose two.)

Options:

A.

A FortiAnalyzer device can perform either the fetch server or client role, and it can perform two roles at the same time with the same FortiAnalyzer devices at the other end.

B.

Log fetching can be done only on two FortiAnalyzer devices that are running the same firmware version.

C.

Log fetching allows the administrator to fetch analytics logs from another FortiAnalyzer for redundancy.

D.

Log fetching allows the administrator to run queries and reports against historical data by retrieving archived logs from one FortiAnalyzer device and sending them to another FortiAnalyzer device.

Buy Now
Questions 5

What is the purpose of using prefilters when configuring event handlers?

Options:

A.

They limit which logs are checked for matches by the other filters.

B.

They can filter the logs before they are processed by FortiAnalyzer

C.

They download new filters to be used in event handlers.

D.

They are common filters applied simultaneously to all event handlers.

Buy Now
Questions 6

Which two parameters impact the amount of reserved disk space required by FortiAnalyzer? (Choose two.)

Options:

A.

Total quota

B.

License type

C.

RAID level

D.

Disk size

Buy Now
Questions 7

Which two statements are true regarding FortiAnalyzer operating modes? (Choose two.)

Options:

A.

When in collector mode, FortiAnalyzer collects logs from multiple devices and forwards these logs in the original binary format.

B.

Collector mode is the default operating mode.

C.

When in collector mode. FortiAnalyzer supports event management and reporting features.

D.

By deploying different FortiAnalyzer devices with collector and analyzer mode in a network, you can improve the overall performance of log receiving, analysis, and reporting

Buy Now
Questions 8

An administrator has moved a registered logging device out of one ADOM and into a new ADOM.

What is the purpose of running the following command: execute sql-local rebuild-adom ?

Options:

A.

To remove the analytics logs of the device from the old database

B.

To populate the new ADOM with analytical logs for the moved device, so you can run reports

C.

To reset the ADOM disk quota enforcement to its default value

D.

To migrate the archive logs to the new ADOM

Buy Now
Questions 9

Why run the command diagnose sql status sqlplugind?

Options:

A.

To list the current SQL processes running

B.

To check what is the database log insertion status

C.

To display the SOL query connections and hcache status

D.

To view the current hcache size

Buy Now
Questions 10

Which log will generate an event with the status Contained?

Options:

A.

An IPS log with action=pass.

B.

A WebFilter log with action=dropped.

C.

An AV log with action=quarantine.

D.

An AppControl log with action=blocked.

Buy Now
Questions 11

Which statement is true regarding Macros on FortiAnalyzer?

Options:

A.

Macros are ADOM specific and each ADOM will have unique macros relevant to that ADOM.

B.

Macros are supported only on the FortiGate ADOM.

C.

Macros are useful in generating excel log files automatically based on the reports settings.

D.

Macros are predefined templates for reports and cannot be customized.

Buy Now
Questions 12

Refer to the exhibit.

Based on the partial outputs displayed, which devices can be members of a FortiAnalyzer Fabric?

Options:

A.

FortiAnalyzerl and FortiAnalyzer3

B.

FortiAnalyzer1 and FortiAnalyzer2

C.

All devices listed can be members

D.

FortiAnalyzer2 and FortiAnalyzer3

Buy Now
Questions 13

An administrator has configured the following settings:

What is the purpose of executing these commands?

Options:

A.

To record the hash value and authentication code of log files.

B.

To encrypt log transfer between FortiAnalyzer and other devices.

C.

To create the secure channel used by the OFTP process.

D.

To verify the integrity of the log files received.

Buy Now
Questions 14

Which two settings must you configure on FortiAnalyzer to allow non-local administrators to authenticate to FortiAnalyzer with any user account in a single LDAP group? (Choose two.)

Options:

A.

A local wildcard administrator account

B.

A remote LDAP server

C.

A trusted host profile that restricts access to the LDAP group

D.

An administrator group

Buy Now
Questions 15

Which process caches logs on FortiGate when FortiAnalyzer is not reachable?

Options:

A.

logfiled

B.

miglogd

C.

sqlplugind

D.

oftpd

Buy Now
Questions 16

Which statements are true regarding securing communications between FortiAnalyzer and FortiGate with IPsec? (Choose two.)

Options:

A.

Must configure the FortiAnalyzer end of the tunnel only--the FortiGate end is auto-negotiated.

B.

Must establish an IPsec tunnel ID and pre-shared key.

C.

IPsec cannot be enabled if SSL is enabled as well.

D.

IPsec is only enabled through the CLI on FortiAnalyzer.

Buy Now
Questions 17

Refer to the exhibit.

The exhibit shows the creation of a new administrator on FortiAnalyzer. The new account uses the credentials stored on an LDAP server.

Why would an administrator configure a password for this account?

Options:

A.

This password is used if the authentication server becomes unreachable.

B.

This password authenticates FortiAnalyzer aqainst the LDAP server.

C.

This password is set to comply with FortiAnalvzer password policy

D.

This password is required because this is a restricted user.

Buy Now
Questions 18

Which daemon is responsible for enforcing the log file size?

Options:

A.

sqlplugind

B.

logfiled

C.

miglogd

D.

ofrpd

Buy Now
Questions 19

When working with FortiAnalyzer reports, what is the purpose of a dataset?

Options:

A.

To provide the layout used for reports

B.

To define the chart type to be used

C.

To retrieve data from the database

D.

To set the data included in templates

Buy Now
Questions 20

Why should you use an NTP server on FortiAnalyzer and all registered devices that log into FortiAnalyzer?

Options:

A.

To properly correlate logs

B.

To use real-time forwarding

C.

To resolve host names

D.

To improve DNS response times

Buy Now
Questions 21

You’ve moved a registered logging device out of one ADOM and into a new ADOM. What happens when you rebuild the new ADOM database?

Options:

A.

FortiAnalyzer resets the disk quota of the new ADOM to default.

B.

FortiAnalyzer migrates archive logs to the new ADOM.

C.

FortiAnalyzer migrates analytics logs to the new ADOM.

D.

FortiAnalyzer removes logs from the old ADOM.

Buy Now
Questions 22

FortiAnalyzer reports are dropping analytical data from 15 days ago, even though the data policy setting for

analytics logs is 60 days.

What is the most likely problem?

Options:

A.

Quota enforcement is acting on analytical data before a report is complete

B.

Logs are rolling before the report is run

C.

CPU resources are too high

D.

Disk utilization for archive logs is set for 15 days

Buy Now
Questions 23

Which two methods can you use to send event notifications when an event occurs that matches a configured

event handler? (Choose two.)

Options:

A.

SMS

B.

Email

C.

SNMP

D.

IM

Buy Now
Questions 24

Which statement correctly describes the management extensions available on FortiAnalyzer?

Options:

A.

Management extensions do not require additional licenses.

B.

Management extensions allow FortiAnalyzer to act as a ForbSIEM supervisor.

C.

Management extensions require a dedicated VM for best performance.

D.

Management extensions may require a minimum number of CPU cores to run.

Buy Now
Questions 25

FortiAnalyzer uses the Optimized Fabric Transfer Protocok (OFTP) over SSL for what purpose?

Options:

A.

To upload logs to an SFTP server

B.

To prevent log modification during backup

C.

To send an identical set of logs to a second logging server

D.

To encrypt log communication between devices

Buy Now
Questions 26

For which two purposes would you use the command set log checksum? (Choose two.)

Options:

A.

To help protect against man-in-the-middle attacks during log upload from FortiAnalyzer to an SFTP server

B.

To prevent log modification or tampering

C.

To encrypt log communications

D.

To send an identical set of logs to a second logging server

Buy Now
Questions 27

Refer to the exhibit.

What does the data point at 12:20 indicate?

Options:

A.

The performance of FortiAnalyzer is below the baseline.

B.

FortiAnalyzer is using its cache to avoid dropping logs.

C.

The log insert lag time is increasing.

D.

The sqlplugind service is caught up with new logs.

Buy Now
Questions 28

An administrator has configured the following settings:

config system global

set log-checksum md5-auth

end

What is the significance of executing this command?

Options:

A.

This command records the log file MD5 hash value.

B.

This command records passwords in log files and encrypts them.

C.

This command encrypts log transfer between FortiAnalyzer and other devices.

D.

This command records the log file MD5 hash value and authentication code.

Buy Now
Questions 29

What is the recommended method of expanding disk space on a FortiAnalyzer VM?

Options:

A.

From the VM host manager, add an additional virtual disk and use the #execute lvm extend command to expand the storage

B.

From the VM host manager, expand the size of the existing virtual disk

C.

From the VM host manager, expand the size of the existing virtual disk and use the # execute format disk command to reformat the disk

D.

From the VM host manager, add an additional virtual disk and rebuild your RAID array

Buy Now
Questions 30

You are trying to initiate an authorization request from FortiGate to FortiAnalyzer, but the Security Fabric window does not open when you click Authorize.

Which two reasons can cause this to happen? (Choose two.)

Options:

A.

A pre-shared key needs to be established on both sides.

B.

The management computer does not have connectivity to the authorization IP address and port combination.

C.

The Security Fabric root is unauthorized and needs to be added as a trusted host.

D.

The fabric authorization settings on FortiAnalyzer are misconfigured.

Buy Now
Questions 31

Which two constraints can impact the amount of reserved disk space required by FortiAnalyzer? (Choose

two.)

Options:

A.

License type

B.

Disk size

C.

Total quota

D.

RAID level

Buy Now
Questions 32

Which statement is true about sending notifications with incident updates?

Options:

A.

Notifications can be sent only when an incident is updated or deleted.

B.

If you use multiple fabric connectors, all connectors must have the same notification settings

C.

Notifications can be sent only by email.

D.

You can send notifications to multiple external platforms

Buy Now
Questions 33

Which two statements are true regarding fabric connectors? (Choose two.)

Options:

A.

Configuring fabric connectors to send notification to ITSM platform upon incident creation Is more efficient than third-party information from the FortiAnalyzer API.

B.

Fabric connectors allow to save storage costs and improve redundancy.

C.

Storage connector service does not require a separate license to send logs to cloud platform.

D.

Cloud-Out connections allow you to send real-time logs to pubic cloud accounts like Amazon S3, Azure Blob , and Google Cloud.

Buy Now
Questions 34

What does the disk status Degraded mean for RAID management?

Options:

A.

The hard drive is no longer being used by the RAID controller.

B.

One or more drives are missing from the FortiAnalyzer unit.

C.

The device is writing data to the disk to restore the volume to an optimal state.

D.

FortiAnalyzer determined that the parity data in the disk is not valid.

Buy Now
Questions 35

Which process is responsible for enforcing the archive file size?

Options:

A.

oftpd

B.

logfiled

C.

miglogd

D.

sqlplugind

Buy Now
Questions 36

What FortiView tool can you use to automatically build a dataset and chart based on a filtered search result?

Options:

A.

Chart Builder

B.

Export to Report Chart

C.

Dataset Library

D.

Custom View

Buy Now
Questions 37

Refer to the exhibit.

What is the purpose of using the Chart Builder feature on FortiAnalyzer?

Options:

A.

To add a new chart under FortiView to be used in new reports

B.

To build a dataset and chart automatically, based on the filtered search results

C.

To add charts directly to generate reports in the current ADOM

D.

To build a chart automatically based on the top 100 log entries

Buy Now
Questions 38

Which tabs do not appear when FortiAnalyzer is operating in Collector mode?

Options:

A.

FortiView

B.

Event Management

C.

Device Manger

D.

Reporting

Buy Now
Questions 39

Which daemon is responsible for enforcing raw log file size?

Options:

A.

logfiled

B.

oftpd

C.

sqlplugind

D.

miglogd

Buy Now
Questions 40

Which two purposes does the auto cache setting on reports serve? (Choose two.)

Options:

A.

It automatically updates the hcache when new logs arrive.

B.

It provides diagnostics on report generation time.

C.

It reduces the log insert lag rate.

D.

It reduces report generation time.

Buy Now
Questions 41

You finished registering a FortiGate device. After traffic starts to flow through FortiGate, you notice that only some of the logs expected are being received on FortiAnalyzer.

What could be the reason for the logs not arriving on FortiAnalyzer?

Options:

A.

FortiGate was added to the wrong ADOM type.

B.

This FortiGate model is not fully supported.

C.

FortiGate does not have logging configured correctly.

D.

This FortiGate is part of an HA cluster but it is the secondary device.

Buy Now
Questions 42

What is the purpose of the FortiAnalyzer command execute format disk?

Options:

A.

To reset all settings from flash except the current IP addresses and routes.

B.

To erase all device settings and images, databases, and log data from the disk, but preserve the IP and routing info.

C.

To perform a low-level format of the disk overwriting the hard disk with random data.

D.

To reset to factory default settings from flash.

Buy Now
Questions 43

Which item must you configure on FortiAnalyzer to email generated reports automatically?

Options:

A.

Output profile

B.

Report scheduling

C.

SFTP server

D.

SNMP server

Buy Now
Questions 44

For which two SAML roles can the FortiAnalyzer be configured? (Choose two.)

Options:

A.

Principal

B.

Service provider

C.

Identity collector

D.

Identity provider

Buy Now
Questions 45

Which FortiAnalyzer feature allows you to use a proactive approach when managing your network security?

Options:

A.

Incidents dashboards

B.

Threat hunting

C.

FortiView Monitor

D.

Outbreak alert services

Buy Now
Questions 46

By default, what happens when a log file reaches its maximum file size?

Options:

A.

FortiAnalyzer overwrites the log files.

B.

FortiAnalyzer stops logging.

C.

FortiAnalyzer rolls the active log by renaming the file.

D.

FortiAnalyzer forwards logs to syslog.

Buy Now
Questions 47

What FortiGate process caches logs when FortiAnalyzer is not reachable?

Options:

A.

logfiled

B.

sqlplugind

C.

oftpd

D.

miglogd

Buy Now
Questions 48

Which statement regarding the FortiAnalyzer Fabric is true?

Options:

A.

The Fabric supervisor collects logs from the Fabric members.

B.

Logging devices can register to the Fabric supervisor or to Fabric members.

C.

Fabric members support HA.

D.

Administrators can create new incidents from the Fabric supervisor.

Buy Now
Questions 49

If you upgrade your FortiAnalyzer firmware, what report elements can be affected?

Options:

A.

Output profiles

B.

Report settings

C.

Report scheduling

D.

Custom datasets

Buy Now
Questions 50

What are two of the key features of FortiAnalyzer? (Choose two.)

Options:

A.

Centralized log repository

B.

Cloud-based management

C.

Reports

D.

Virtual domains (VDOMs)

Buy Now
Questions 51

In Log View, you can use the Chart Builder feature to build a dataset and chart based on the filtered search results.

Similarly, which feature you can use for FortiView?

Options:

A.

Export to Report Chart

B.

Export to PDF

C.

Export to Chart Builder

D.

Export to Custom Chart

Buy Now
Questions 52

What are two benefits of using fabric connectors? (Choose two.)

Options:

A.

They allow FortiAnalyzer to send logs in real-time to public cloud accounts.

B.

You do not need an additional license to send logs to the cloud platform.

C.

Fabric connectors allow you to improve redundancy.

D.

Using fabric connectors is more efficient than using third-party polling with API.

Buy Now
Questions 53

What is the purpose of a predefined template on the FortiAnalyzer?

Options:

A.

It can be edited and modified as required

B.

It specifies the report layout which contains predefined texts, charts, and macros

C.

It specifies report settings which contains time period, device selection, and schedule

D.

It contains predefined data to generate mock reports

Buy Now
Questions 54

Which statement is true when you are upgrading the firmware on an HA cluster made up of two FortiAnalyzer devices?

Options:

A.

First, upgrade the secondary device, and then upgrade the primary device.

B.

Both FortiAnalyzer devices will be upgraded at the same time.

C.

You can enable uninterruptible-upgrade so that the normal FortiAnalyzer operations are not interrupted while the cluster firmware upgrades.

D.

You can perform the firmware upgrade using only a console connection.

Buy Now
Exam Code: FCP_FAZ_AD-7.4
Exam Name: FCP - FortiAnalyzer 7.4 Administrator
Last Update: Aug 17, 2025
Questions: 183
FCP_FAZ_AD-7.4 pdf

FCP_FAZ_AD-7.4 PDF

$29.75  $84.99
FCP_FAZ_AD-7.4 Engine

FCP_FAZ_AD-7.4 Testing Engine

$35  $99.99
FCP_FAZ_AD-7.4 PDF + Engine

FCP_FAZ_AD-7.4 PDF + Testing Engine

$47.25  $134.99