New Year Sale Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Fortinet FCP_FAZ_AN-7.6 Fortinet NSE 5 - FortiAnalyzer 7.6 Analyst Exam Practice Test

Fortinet NSE 5 - FortiAnalyzer 7.6 Analyst Questions and Answers

Question 1

After generating a report, you notice the information you where expecting to see is not included in it. However, you confirm that the logs are there.

Options:

A.

Check the time frame covered by thereport.

B.

Disable auto-cache.

C.

Increase the report utilization quota.

D.

Test the dataset

Question 2

Exhibit.

Question # 2

Based on the partial outputs displayed, which devices can be members of a FotiAnalyzer Fabric?

Options:

A.

FortiAnalayzer1 and FortiAnalyzer3

B.

FortiAnalyzer1 and FortiAnalyzer2

C.

FortiAnalyzer2 and FortiAnalyzer3

D.

All devices listed can be members.

Question 3

Exhibit.

What can you conclude about these search results? (Choose two.)

Options:

A.

They can be downloaded to a file.

B.

They are sortable by columns and customizable.

C.

They are not available for analysis in FortiView.

D.

They were searched by using textmode.

Question 4

After a generated a repot, you notice the information you were expecting to see in not included in it. However, you confirm that the logs are there:

Which two actions should you perform? (Choose two.)

Options:

A.

Check the time frame covered by the report.

B.

Disable auto-cache.

C.

Increase the report utilization quota.

D.

Test the dataset.

Question 5

Which statement about sending notifications with incident update is true?

Options:

A.

You can send notifications to multiple external platforms.

B.

Notifications can be sent only by email.

C.

If you use multiple fabric connectors, all connectors must have the same settings.

D.

Notifications can be sent only when an incident is updated or deleted.

Question 6

(An analyst is using FortiAI on FortiAnalyzer to simplify certain tasks but is worried about exceeding the monthly token limit. Which query will take the fewest FortiAI tokens? (Choose one answer))

Options:

A.

Show logs for 192.168.1.10 (past week)

B.

Show all logs from the past week

C.

Can you show me all the log entries for the endpoint 192.168.1.10?

D.

Show logs for 192.168.1.10

Question 7

Whathappens when the indicator of compromise (IOC) engine on FortiAnalyzer finds web logs that match blacklisted IP addresses?

Options:

A.

FortiAnalyzer flags the associated host for further analysis.

B.

A new infected entry is added for the corresponding endpoint under Compromised Hosts.

C.

The detection engine classifies those logs as Suspicious.

D.

The endpoint is marked as Compromised and, optionally, can be put in quarantine.

Question 8

In firmware version 7.6, how does on-premises FortiAnalyzer store logs? (Choose one answer)

Options:

A.

Uses ClickHouse database

B.

Uses MySQL database

C.

Uses Postgres SQL database

D.

Uses ElasticSeach database

Question 9

Exhibit.

What is the purpose of using the Chart Builder feature On FortiAnalyzer?

Options:

A.

To build a chart automatically based on the top 100 log entries

B.

To add charts directly to generatereports in the current ADOM.

C.

To add a new chart under FortiView to be used in new reports

D.

To build a dataset and chart based on the filtered search results

Question 10

Which log will generate an event with the status Unhandled?

Options:

A.

An AV log with action=quarantine.

B.

An IPS log with action=pass.

C.

A WebFilter log willaction=dropped.

D.

An AppControl log with action=blocked.

Question 11

As part of your analysis, you discover that a Medium severity level incident is fully remediated.

You change the incident status to Closed:Remediated.

Which statement about your update is true?

Options:

A.

The incident can no longer be deleted.

B.

The corresponding event will be marked as Mitigated.

C.

The incident dashboard will be updated.

D.

The incident severity will be lowered.

Question 12

When managing incidents on FortiAnlyzer, what must an analyst be aware of?

Options:

A.

You can manually attach generated reports to incidents.

B.

The status of the incident is always linked to the status of the attach event.

C.

Severity incidents rated with the level High have an initial service-level agreement (SLA) response time of 1 hour.

D.

Incidents must be acknowledged before they can be analyzed.

Question 13

Refer to the exhibit.

What can you conclude about the output?

Options:

A.

The low indexing values require investigation.

B.

The output is not ADOM specific.

C.

There are more event logs thantraffic logs.

D.

The log rate higher than the message rate is not normal.

Question 14

Which statement about the FortiSOAR management extension is correct?

Options:

A.

It requires a FortiManager configured to manage FortiGate.

B.

It runs as a docker container on FortiAnalyzer.

C.

It requires a dedicated FortiSOAR device or VM.

D.

It does not include a limited trial by default.

Question 15

Why must you wait for several minutes before you run a playbook that you just created?

Options:

A.

FortiAnalyzer needs that time to parse the new playbook.

B.

FortiAnalyzer needs that time to debug the new playbook.

C.

FortiAnalyzer needs that time to back up the current playbooks.

D.

FortiAnalyzer needs that time to ensure there are no other playbooks running.

Question 16

(How does FortiAnalyzer block indicators? (Choose one answer))

Options:

A.

It uses an automation script to update FortiGate with the block list.

B.

It uses a FortiManager connector to send the block list.

C.

It uses a FortiClient EMS connector to send the block list.

D.

It uses a webhook to allow FortiGate to send the block list.

Question 17

What is the purpose of running the command diagnose sql status sqlreportd?

Options:

A.

To view a list of scheduled reports

B.

To list the current SQL processes running

C.

To display the SQL query connections and hcache status

D.

To identify the database log insertion status

Question 18

What is the purpose of using data selectors when configuring event handlers?

Options:

A.

They filter the types of logs that FortiAnalyzer can accept from registered devices.

B.

They download new filters can be used in event handlers.

C.

They apply their filter criteria to the entire event handler so that you don’t have to configure the same criteria in the individual rules.

D.

They are common filters that can be appliedsimultaneously to all event handlers.

Question 19

(In a FortiAnalyzer Fabric deployment, which three modules from Fabric members are available for analysis on the supervisor? (Choose three answers))

Options:

A.

Playbooks

B.

Indicators

C.

Logs

D.

Events

E.

Reports

Question 20

Which statement about the FortiSIEM management extension is correct?

Options:

A.

It allows you to manage the entire life cycle of a threat or breach.

B.

It can be installed as a dedicated VM.

C.

Its use of the available disk space is capped at 50%.

D.

It requires a licensed FortiSIEM supervisor.