New Year Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: clap70

FCP_FAZ_AN-7.6 Fortinet NSE 5 - FortiAnalyzer 7.6 Analyst Questions and Answers

Questions 4

Which statement about exporting items in Report Definitions is true?

Options:

A.

Templates can be exported.

B.

Template exports contain associated charts and datasets.

C.

Chart exports contain associated datasets.

D.

Datasets can be exported.

Buy Now
Questions 5

Exhibit.

What is the purpose of using the Chart Builder feature On FortiAnalyzer?

Options:

A.

To build a chart automatically based on the top 100 log entries

B.

To add charts directly to generatereports in the current ADOM.

C.

To add a new chart under FortiView to be used in new reports

D.

To build a dataset and chart based on the filtered search results

Buy Now
Questions 6

Which statement describes archive logs on FortiAnalyzer?

Options:

A.

Logs that are indexed and stored in the SQL database

B.

Logs a FortiAnalyzer administrator can access in FortiView

C.

Logs compressed and saved in files with the .gz extension

D.

Logs previously collected from devices that are offline

Buy Now
Questions 7

When managing incidents on FortiAnlyzer, what must an analyst be aware of?

Options:

A.

You can manually attach generated reports to incidents.

B.

The status of the incident is always linked to the status of the attach event.

C.

Severity incidents rated with the level High have an initial service-level agreement (SLA) response time of 1 hour.

D.

Incidents must be acknowledged before they can be analyzed.

Buy Now
Questions 8

Aplaybook contains five tasks in total. An administrator runs the playbook and four out of five tasks finish successfully, but one task fails.

What will be the status of the playbook after it is run?

Options:

A.

Attention required

B.

Upstream_failed

C.

Failed

D.

Success

Buy Now
Questions 9

Which log will generate an event with the status Contained?

Options:

A.

An AV log with action=quarantine.

B.

An IPS log with action=pass.

C.

A WebFilter log will action=dropped.

D.

An AppControl log with action=blocked.

Buy Now
Questions 10

Refer to Exhibit:

Whatdoes the data point at 21:20 indicate?

Options:

A.

FortiAnalyzer is indexing logs faster than logs are being received.

B.

The fortilogd daemon is ahead in indexing by one log.

C.

The SQL database requires a rebuild because of high receive lag.

D.

FortiAnalyzer is temporarily buffering received logs so older logs can be indexed first.

Buy Now
Questions 11

(When there are no matching parsers for a device log, what does FortiAnalyzer do? (Choose one answer))

Options:

A.

Drops the log

B.

Applies the generic SYSLOG parser

C.

Stores the log but doesn’t normalize it

D.

Archives the log for future analysis

Buy Now
Questions 12

Which statement regarding macros on FortiAnalyzer is true?

Options:

A.

Macros are predefined templates for reports and cannot be customized.

B.

Macros are useful in generating excel log files automatically based on the report settings.

C.

Macros are ADOM-specific and each ADOM type have unique macros relevant to that ADOM.

D.

Macros are supported only on the FortiGate ADOMs.

Buy Now
Questions 13

Exhibit.

What can you conclude about the output?

Options:

A.

The message ratebeing lower that the log rate is normal.

B.

Both messages and logs are almost finished indexing.

C.

There are more traffic logs than event logs.

D.

The output is ADOM specific

Buy Now
Questions 14

Exhibit.

What does the data point at 12:20 indicate?

Options:

A.

The loginsert log time is increasing.

B.

FortiAnalyzer is using its cache to avoid dropping logs.

C.

The performance of FortiAnalyzer is below the baseline.

D.

The sqiplugind service is caught up with the logs

Buy Now
Questions 15

As part of your analysis, you discover that a Medium severity level incident is fully remediated.

You change the incident status to Closed:Remediated.

Which statement about your update is true?

Options:

A.

The incident can no longer be deleted.

B.

The corresponding event will be marked as Mitigated.

C.

The incident dashboard will be updated.

D.

The incident severity will be lowered.

Buy Now
Questions 16

(An analyst is using FortiAI on FortiAnalyzer to simplify certain tasks but is worried about exceeding the monthly token limit. Which query will take the fewest FortiAI tokens? (Choose one answer))

Options:

A.

Show logs for 192.168.1.10 (past week)

B.

Show all logs from the past week

C.

Can you show me all the log entries for the endpoint 192.168.1.10?

D.

Show logs for 192.168.1.10

Buy Now
Questions 17

You are trying to configure a task in the playbook editor to run a report.

However, when you try to select the desired playbook, you do to see it listed.

What is the reason?

Options:

A.

The report does not have auto-cache and extended log filtering enabled.

B.

The playbook is currently running and will be available after it is finished.

C.

You must create a trigger to run the report first.

D.

The report has no result and must be reconfigured.

Buy Now
Questions 18

An administrator on your team has configured multiple reports to run periodically. Management has an additional request that all new generated reports be sent to a company email inbox for accessibility. The mail server has already been configured on FortiAnalyzer.

Which item must configure on FortiAnalyzer so that emails are sent when the reports are generated?

Options:

A.

Enable the option to email all repots under the mail server.

B.

Add amailto: option within the report layouts.

C.

Enable email notification under the report calendar.

D.

Enable an output profile on the reports.

Buy Now
Questions 19

Which SQL query is in the correct order to query to database in the FortiAnalyzer?

Options:

A.

SELECT devid FROM $log GROUP BY devid WHERE ‘user’,,’ users1’

B.

SELECT FROM $log WHERE devid ‘user’,, USER1’ GROUP BY devid

C.

SELCT devid WHERE ’user’-‘ USER1’ FROM $log GROUP By devid

D.

SELECT devid FROM $log WHERE ‘user’=’ GROUP BY devid

Buy Now