Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: geek65

FCP_FAZ_AN-7.4 FCP - FortiAnalyzer 7.4 Analyst Questions and Answers

Questions 4

Which statement regarding macros on FortiAnalyzer is true?

Options:

A.

Macros are predefined templates for reports and cannot be customized.

B.

Macros are useful in generating excel log files automatically based on the report settings.

C.

Macros are ADOM-specific and each ADOM type have unique macros relevant to that ADOM.

D.

Macros are supported only on the FortiGate ADOMs.

Buy Now
Questions 5

What is the purpose of running the command diagnose sql status sqlreportd?

Options:

A.

To view a list of scheduled reports

B.

To list the current SQL processes running

C.

To display the SQL query connections and hcache status

D.

To identify the database log insertion status

Buy Now
Questions 6

You are trying to configure a task in the playbook editor to run a report.

However, when you try to select the desired playbook, you do to see it listed.

What is the reason?

Options:

A.

The report does not have auto-cache and extended log filtering enabled.

B.

The playbook is currently running and will be available after it is finished.

C.

You must create a trigger to run the report first.

D.

The report has no result and must be reconfigured.

Buy Now
Questions 7

Which log will generate an event with the status Contained?

Options:

A.

An AV log with action=quarantine.

B.

An IPS log with action=pass.

C.

A WebFilter log will action=dropped.

D.

An AppControl log with action=blocked.

Buy Now
Questions 8

Why must you wait for several minutes before you run a playbook that you just created?

Options:

A.

FortiAnalyzer needs that time to parse the new playbook.

B.

FortiAnalyzer needs that time to debug the new playbook.

C.

FortiAnalyzer needs that time to back up the current playbooks.

D.

FortiAnalyzer needs that time to ensure there are no other playbooks running.

Buy Now
Questions 9

Refer to Exhibit:

What does the data point at 21:20 indicate?

Options:

A.

FortiAnalyzer is indexing logs faster than logs are being received.

B.

The fortilogd daemon is ahead in indexing by one log.

C.

The SQL database requires a rebuild because of high receive lag.

D.

FortiAnalyzer is temporarily buffering received logs so older logs can be indexed first.

Buy Now
Questions 10

Exhibit.

Which statement about the event displayed is correct?

Options:

A.

The risk source is isolated.

B.

The security risk was blocked or dropped.

C.

The security event risk is considered open.

D.

An incident was created from this event.

Buy Now
Questions 11

Refer to the exhibit.

What can you conclude about the output?

Options:

A.

The low indexing values require investigation.

B.

The output is not ADOM specific.

C.

There are more event logs than traffic logs.

D.

The log rate higher than the message rate is not normal.

Buy Now
Questions 12

What happens when the indicator of compromise (IOC) engine on FortiAnalyzer finds web logs that match blacklisted IP addresses?

Options:

A.

FortiAnalyzer flags the associated host for further analysis.

B.

A new infected entry is added for the corresponding endpoint under Compromised Hosts.

C.

The detection engine classifies those logs as Suspicious.

D.

The endpoint is marked as Compromised and, optionally, can be put in quarantine.

Buy Now
Questions 13

Exhibit.

What can you conclude from this output?

Options:

A.

There is not disk quota allocated to quarantining files.

B.

FGT_B is the Security Fabric root.

C.

The allocated disk quote to ADOM1 is 3 GB.

D.

Archive logs are using more space than analytic logs.

Buy Now
Questions 14

When managing incidents on FortiAnlyzer, what must an analyst be aware of?

Options:

A.

You can manually attach generated reports to incidents.

B.

The status of the incident is always linked to the status of the attach event.

C.

Severity incidents rated with the level High have an initial service-level agreement (SLA) response time of 1 hour.

D.

Incidents must be acknowledged before they can be analyzed.

Buy Now
Questions 15

Which two statement regarding the outbreak detection service are true? (Choose two.)

Options:

A.

An additional license is required.

B.

It automatically downloads new event handlers and reports.

C.

Outbreak alerts are available on the root ADOM only.

D.

New alerts are received by email.

Buy Now
Questions 16

Which FortiAnalyzer feature allows you to use a proactive approach when managing your network security?

Options:

A.

FortiView Monitor

B.

Outbreak alert services

C.

Incidents dashboard

D.

Threat hunting

Buy Now
Exam Code: FCP_FAZ_AN-7.4
Exam Name: FCP - FortiAnalyzer 7.4 Analyst
Last Update: Aug 17, 2025
Questions: 56
FCP_FAZ_AN-7.4 pdf

FCP_FAZ_AN-7.4 PDF

$29.75  $84.99
FCP_FAZ_AN-7.4 Engine

FCP_FAZ_AN-7.4 Testing Engine

$35  $99.99
FCP_FAZ_AN-7.4 PDF + Engine

FCP_FAZ_AN-7.4 PDF + Testing Engine

$47.25  $134.99