Which two statements about high availability (HA) on FortiAnalyzer are true? (Choose two.)
Which daemon is responsible for enforcing the log file size?
How does FortiAnalyzer retrieve specific log data from the database?
Which two parameters are used to calculate the Total Quota value available on FortiAnalyzer? (Choose two.)
Which log type does the FortiAnalyzer indicators of compromise feature use to identify infected hosts?
Refer to the exhibit.
What does the data point at 14:55 tell you?
What is Log Insert Lag Time on FortiAnalyzer?
Refer to the exhibit.
What is the purpose of using the Chart Builder feature on FortiAnalyzer?
Which two settings must you configure on FortiAnalyzer to allow non-local administrators to authenticate to FortiAnalyzer with any user account in a single LDAP group? (Choose two.)
Which two statements are true regarding high availability (HA) on FortiAnalyzer? (Choose two.)
What must you consider when using log fetching? (Choose two.)
Which statement about the communication between FortiGate high availability (HA) clusters and FortiAnalyzer is true?
Why should you use an NTP server on FortiAnalyzer and all registered devices that log into FortiAnalyzer?
Which statement is true when you are upgrading the firmware on an HA cluster made up of two FortiAnalyzer devices?
Refer to the exhibit.
Laptopt is used by several administrators to manage FortiAnalyzer. You want to configure a generic text filter that matches all login attempts to the web interface generated by any user other than "admin" and coming from Laptop1:
Which filter will achieve the desired result?
What are two advantages of setting up fabric ADOM? (Choose two.)
What happens when the IOC breach detection engine on FortiAnalyzer finds web logs that match a blocklisted IP address?
What are offline logs on FortiAnalyzer?
FortiAnalyzer uses the Optimized Fabric Transfer Protocok (OFTP) over SSL for what purpose?
Which two statements are correct regarding the export and import of playbooks? (Choose two.)
How can you configure FortiAnalyzer to permit administrator logins from only specific locations?
If you upgrade the FortiAnalyzer firmware, which report element can be affected?
After you have moved a registered logging device out of one ADOM and into a new ADOM, what is the
purpose of running the following CLI command?
execute sql-local rebuild-adom
A rogue administrator was accessing FortiAnalyzer without permission, and you are tasked to see what activity was performed by that rogue administrator on FortiAnalyzer.
What can you do on FortiAnalyzer to accomplish this?
What does the disk status Degraded mean for RAID management?
Refer to the exhibit.
Based on the partial outputs displayed, which devices can be members of a FortiAnalyzer Fabric?
Which two statements regarding ADOM modes are true? (Choose two.)
What are offline logs on FortiAnalyzer?
Consider the CLI command:
What is the purpose of the command?
You have recently grouped multiple FortiGate devices into a single ADOM. System Settings > Storage Info
shows the quota used.
What does the disk quota refer to?
Which two statements are true regarding fabric connectors? (Choose two.)
Which two methods can you use to send event notifications when an event occurs that matches a configured
event handler? (Choose two.)
Refer to the exhibit, which shows the HA configuration settings of a FortiAnalyzer device.
The administrator wants to join this FortiAnalyzer to an existing HA cluster. What can you conclude from the configuration displayed?
What FortiGate process caches logs when FortiAnalyzer is not reachable?
A play book contains five tasks in total. An administrator executed the playbook and four out of five tasks finished successfully, but one task failed. What will be the status of the playbook after its execution?
Which statement about the FortiSIEM management extension is correct?
What are two effects of enabling auto-cache in a FortiAnalyzer report? (Choose two.)
How do you restrict an administrator’s access to a subset of your organization’s ADOMs?
You are trying to initiate an authorization request from FortiGate to FortiAnalyzer, but the Security Fabric window does not open when you click Authorize.
Which two reasons can cause this to happen? (Choose two.)
Which two statements about FortiAnalyzer operating modes are true? (Choose two.)
You finished registering a FortiGate device. After traffic starts to flow through FortiGate, you notice that only some of the logs expected are being received on FortiAnalyzer.
What could be the reason for the logs not arriving on FortiAnalyzer?
Which two statement are true regardless initial Logs sync and Log Data Sync for Ha on FortiAnalyzer?
Which FortiAnalyzer feature allows you to retrieve the archived logs matching a specific timeframe from
another FortiAnalyzer device?
Refer to the exhibit.
Based on the output, what can you conclude about the FortiAnalyzer logging status?
What purposes does the auto-cache setting on reports serve? (Choose two.)
Which daemon is responsible for enforcing raw log file size?
Which two actions should an administrator take to view Compromised Hosts on FortiAnalyzer? (Choose two.)
Which statement when you are upgrading the firmware on an HA cluster made up of three FortiAnalyzer devices is true?
Logs are being deleted from one of the ADOMs earlier than the configured setting for archiving in the data
policy.
What is the most likely problem?
Refer to the exhibit.
The exhibit shows the creation of a new administrator on FortiAnalyzer.
What are two effects of enabling the choice Match all users on remote server when configuring a new administrator? (Choose two.)
Which SQL query is in the correct order to query the database in the FortiAnslyzer?