New Year Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Fortinet FCP_FAZ_AD-7.4 FCP - FortiAnalyzer 7.4 Administrator Exam Practice Test

Demo: 51 questions
Total 171 questions

FCP - FortiAnalyzer 7.4 Administrator Questions and Answers

Question 1

Which two statements about high availability (HA) on FortiAnalyzer are true? (Choose two.)

Options:

A.

FortiAnalyzer HA supports synchronization of logs as well as some system and configuration settings.

B.

FortiAnalyzer HA active-passive mode can function without VRRP.

C.

All devices in a FortiAnalyzer HA cluster must run in the same operation mode, either analyzer mode or collector mode.

D.

All devices in a FortiAnalyzer HA cluster must have the same available disk space.

Question 2

Which daemon is responsible for enforcing the log file size?

Options:

A.

sqlplugind

B.

logfiled

C.

miglogd

D.

ofrpd

Question 3

How does FortiAnalyzer retrieve specific log data from the database?

Options:

A.

SQL FROM statement

B.

SQL GET statement

C.

SQL SELECT statement

D.

SQL EXTRACT statement

Question 4

Which two parameters are used to calculate the Total Quota value available on FortiAnalyzer? (Choose two.)

Options:

A.

Used storage

B.

Retention policy

C.

Reserved space

D.

Total system storage

Question 5

Which log type does the FortiAnalyzer indicators of compromise feature use to identify infected hosts?

Options:

A.

Antivirus logs

B.

Web filter logs

C.

IPS logs

D.

Application control logs

Question 6

Refer to the exhibit.

What does the data point at 14:55 tell you?

Options:

A.

The received rate is almost at its maximum for this device

B.

The sqlplugind daemon is behind in log indexing by two logs

C.

Logs are being dropped

D.

Raw logs are reaching FortiAnalyzer faster than they can be indexed

Question 7

What is Log Insert Lag Time on FortiAnalyzer?

Options:

A.

The number of times in the logs where end users experienced slowness while accessing resources.

B.

The amount of lag time that occurs when the administrator is rebuilding the ADOM database.

C.

The amount of time that passes between the time a log was received and when it was indexed on FortiAnalyzer.

D.

The amount of time FortiAnalyzer takes to receive logs from a registered device

Question 8

Refer to the exhibit.

What is the purpose of using the Chart Builder feature on FortiAnalyzer?

Options:

A.

To add a new chart under FortiView to be used in new reports

B.

To build a dataset and chart automatically, based on the filtered search results

C.

To add charts directly to generate reports in the current ADOM

D.

To build a chart automatically based on the top 100 log entries

Question 9

Which two settings must you configure on FortiAnalyzer to allow non-local administrators to authenticate to FortiAnalyzer with any user account in a single LDAP group? (Choose two.)

Options:

A.

A local wildcard administrator account

B.

A remote LDAP server

C.

A trusted host profile that restricts access to the LDAP group

D.

An administrator group

Question 10

Which two statements are true regarding high availability (HA) on FortiAnalyzer? (Choose two.)

Options:

A.

FortiAnalyzer HA can function without VRRP. and VRRP is required only if you have more than two FortiAnalyzer devices in a cluster.

B.

FortiAnalyzer HA supports synchronization of logs as well as some system and configuration settings.

C.

All devices in a FortiAnalyzer HA cluster must run in the same operation mode: analyzer or collector.

D.

FortiAnalyzer HA implementation is supported by many public cloud infrastructures such as AWS, Microsoft Azure, and Google Cloud.

Question 11

What must you consider when using log fetching? (Choose two.)

Options:

A.

The fetch client can retrieve logs from devices that are not added to its local Device Manager

B.

You can use filters to include only logs from a single device.

C.

The fetching profile must include a user with the Super_User profile.

D.

The archive logs retrieved from the server become archive logs in the client.

Question 12

Which statement about the communication between FortiGate high availability (HA) clusters and FortiAnalyzer is true?

Options:

A.

If devices were registered to FortiAnalyzer before forming a cluster, you can manually add them together.

B.

FortiAnalyzer distinguishes each cluster member by the IP addresses in log message headers.

C.

If the HA primary device becomes unavailable, you must remove it from the HA cluster list on FortiAnalyzer.

D.

The FortiGate HA cluster must be in active-passive mode in order to avoid conflict.

Question 13

Why should you use an NTP server on FortiAnalyzer and all registered devices that log into FortiAnalyzer?

Options:

A.

To properly correlate logs

B.

To use real-time forwarding

C.

To resolve host names

D.

To improve DNS response times

Question 14

Which statement is true when you are upgrading the firmware on an HA cluster made up of two FortiAnalyzer devices?

Options:

A.

First, upgrade the secondary device, and then upgrade the primary device.

B.

Both FortiAnalyzer devices will be upgraded at the same time.

C.

You can enable uninterruptible-upgrade so that the normal FortiAnalyzer operations are not interrupted while the cluster firmware upgrades.

D.

You can perform the firmware upgrade using only a console connection.

Question 15

Refer to the exhibit.

Laptopt is used by several administrators to manage FortiAnalyzer. You want to configure a generic text filter that matches all login attempts to the web interface generated by any user other than "admin" and coming from Laptop1:

Which filter will achieve the desired result?

Options:

A.

operation-login & performed_on=="GUI(10.1.1.100)" & user!=admin

B.

operation-login & srcip==10.1.1.100 & dstip==10.1.1.210 & user==admin

C.

operation-login & dstip==10.1.1.210 & userl-admin

D.

operation-login & performed_on=="GUI(10.1.1.210)' & user!=admin

Question 16

What are two advantages of setting up fabric ADOM? (Choose two.)

Options:

A.

It can be used for fast data processing and log correlation

B.

It can be used to facilitate communication between devices in same Security Fabric

C.

It can include all Fortinet devices that are part of the same Security Fabric

D.

It can include only FortiGate devices that are part of the same Security Fabric

Question 17

What happens when the IOC breach detection engine on FortiAnalyzer finds web logs that match a blocklisted IP address?

Options:

A.

The endpoint is marked as Compromised and. optionally, can be put in quarantine.

B.

FortiAnalyzer flags the associated host for further analysis.

C.

A new Infected entry is added for the corresponding endpoint.

D.

The detection engine classifies those logs as Suspicious

Question 18

What are offline logs on FortiAnalyzer?

Options:

A.

Compressed logs, which are also known as archive logs, are considered to be offline logs.

B.

When you restart FortiAnalyzer. all stored logs are considered to be offline logs.

C.

Logs that are indexed and stored in the SQL database.

D.

Logs that are collected from offline devices after they boot up.

Question 19

FortiAnalyzer uses the Optimized Fabric Transfer Protocok (OFTP) over SSL for what purpose?

Options:

A.

To upload logs to an SFTP server

B.

To prevent log modification during backup

C.

To send an identical set of logs to a second logging server

D.

To encrypt log communication between devices

Question 20

Which two statements are correct regarding the export and import of playbooks? (Choose two.)

Options:

A.

You can export only one playbook at a time.

B.

You can import a playbook even if there is another one with the same name in the destination.

C.

Playbooks can be exported and imported only within the same FortiAnaryzer.

D.

A playbook that was disabled when it was exported, will be disabled when it is imported.

Question 21

How can you configure FortiAnalyzer to permit administrator logins from only specific locations?

Options:

A.

Use static routes

B.

Use administrative profiles

C.

Use trusted hosts

D.

Use secure protocols

Question 22

If you upgrade the FortiAnalyzer firmware, which report element can be affected?

Options:

A.

Custom datasets

B.

Report scheduling

C.

Report settings

D.

Output profiles

Question 23

After you have moved a registered logging device out of one ADOM and into a new ADOM, what is the

purpose of running the following CLI command?

execute sql-local rebuild-adom

Options:

A.

To reset the disk quota enforcement to default

B.

To remove the analytics logs of the device from the old database

C.

To migrate the archive logs to the new ADOM

D.

To populate the new ADOM with analytical logs for the moved device, so you can run reports

Question 24

A rogue administrator was accessing FortiAnalyzer without permission, and you are tasked to see what activity was performed by that rogue administrator on FortiAnalyzer.

What can you do on FortiAnalyzer to accomplish this?

Options:

A.

Click FortiView and generate a report for that administrator.

B.

Click Task Monitor and view the tasks performed by that administrator.

C.

Click Log View and generate a report for that administrator.

D.

View the tasks performed by the rogue administrator in Fabric View.

Question 25

What does the disk status Degraded mean for RAID management?

Options:

A.

The hard drive is no longer being used by the RAID controller.

B.

One or more drives are missing from the FortiAnalyzer unit.

C.

The device is writing data to the disk to restore the volume to an optimal state.

D.

FortiAnalyzer determined that the parity data in the disk is not valid.

Question 26

Refer to the exhibit.

Based on the partial outputs displayed, which devices can be members of a FortiAnalyzer Fabric?

Options:

A.

FortiAnalyzer1 and FortiAnalyzer3

B.

All devices listed can be members.

C.

FortiAnalyzer1 and FortiAnalyzer2

D.

FortiAnalyzer2 and FortiAnalyzer3

Question 27

Which two statements regarding ADOM modes are true? (Choose two.)

Options:

A.

In normal mode, the disk quota of the ADOM is fixed and cannot be modified, but in advanced mode, the disk quota of the ADOM is flexible.

B.

You can change ADOM modes only through the CLI.

C.

In an advanced mode ADOM, you can assign FortiGate VDOMs from a single FortiGate device to multiple FortiAnalyzer ADOMs.

D.

Normal mode is the default ADOM mode.

Question 28

What are offline logs on FortiAnalyzer?

Options:

A.

Compressed logs, also known as archive logs

B.

Logs that are indexed and stored in the SQL database

C.

Any logs collected from offline devices after they boot up

D.

Real-time logs that are not yet indexed

Question 29

Consider the CLI command:

What is the purpose of the command?

Options:

A.

To add a unique tag to each log to prove that it came from this FortiAnalyzer

B.

To add the MD5 hash value and authentication code

C.

To add a log file checksum

D.

To encrypt log communications

Question 30

You have recently grouped multiple FortiGate devices into a single ADOM. System Settings > Storage Info

shows the quota used.

What does the disk quota refer to?

Options:

A.

The maximum disk utilization for each device in the ADOM

B.

The maximum disk utilization for the FortiAnalyzer model

C.

The maximum disk utilization for the ADOM type

D.

The maximum disk utilization for all devices in the ADOM

Question 31

Which two statements are true regarding fabric connectors? (Choose two.)

Options:

A.

Configuring fabric connectors to send notification to ITSM platform upon incident creation Is more efficient than third-party information from the FortiAnalyzer API.

B.

Fabric connectors allow to save storage costs and improve redundancy.

C.

Storage connector service does not require a separate license to send logs to cloud platform.

D.

Cloud-Out connections allow you to send real-time logs to pubic cloud accounts like Amazon S3, Azure Blob , and Google Cloud.

Question 32

Which two methods can you use to send event notifications when an event occurs that matches a configured

event handler? (Choose two.)

Options:

A.

SMS

B.

Email

C.

SNMP

D.

IM

Question 33

Refer to the exhibit, which shows the HA configuration settings of a FortiAnalyzer device.

The administrator wants to join this FortiAnalyzer to an existing HA cluster. What can you conclude from the configuration displayed?

Options:

A.

After joining the cluster, this FortiAnalyzer will forward received logs to its peers.

B.

This FortiAnalyzer will trigger a failover after losing communication with its peers for 10 seconds.

C.

This FortiAnalyzer is configured to route HA traffic through a gateway.

D.

This FortiAnalyzer will join the existing HA cluster as the secondary.

Question 34

What FortiGate process caches logs when FortiAnalyzer is not reachable?

Options:

A.

logfiled

B.

sqlplugind

C.

oftpd

D.

miglogd

Question 35

A play book contains five tasks in total. An administrator executed the playbook and four out of five tasks finished successfully, but one task failed. What will be the status of the playbook after its execution?

Options:

A.

Success

B.

Failed

C.

Running

D.

Upstream_failed

Question 36

Which statement about the FortiSIEM management extension is correct?

Options:

A.

Allows you to manage the entire life cycle of a threat or breach.

B.

Its use of the available disk space is capped at 50%.

C.

It requires a licensed FortiSIEM supervisor.

D.

It can be installed as a dedicated VM.

Question 37

What are two effects of enabling auto-cache in a FortiAnalyzer report? (Choose two.)

Options:

A.

The size of newly generated reports is optimized to conserve disk space.

B.

FortiAnalyzer local cache is used to store generated reports.

C.

When new logs are received, the hard-cache data is updated automatically.

D.

The generation time for reports is decreased.

Question 38

How do you restrict an administrator’s access to a subset of your organization’s ADOMs?

Options:

A.

Set the ADOM mode to Advanced

B.

Assign the ADOMs to the administrator’s account

C.

Configure trusted hosts

D.

Assign the default Super_User administrator profile

Question 39

You are trying to initiate an authorization request from FortiGate to FortiAnalyzer, but the Security Fabric window does not open when you click Authorize.

Which two reasons can cause this to happen? (Choose two.)

Options:

A.

A pre-shared key needs to be established on both sides.

B.

The management computer does not have connectivity to the authorization IP address and port combination.

C.

The Security Fabric root is unauthorized and needs to be added as a trusted host.

D.

The fabric authorization settings on FortiAnalyzer are misconfigured.

Question 40

Which two statements about FortiAnalyzer operating modes are true? (Choose two.)

Options:

A.

When in collector mode, FortiAnalyzer offloads the log receiving task to the analyzer.

B.

When in analyzer mode, FortiAnalyzer supports event management and reporting features.

C.

For the collector, you should allocate most of the disk space to analytics logs.

D.

Analyzer mode is the default operating mode.

Question 41

You finished registering a FortiGate device. After traffic starts to flow through FortiGate, you notice that only some of the logs expected are being received on FortiAnalyzer.

What could be the reason for the logs not arriving on FortiAnalyzer?

Options:

A.

FortiGate was added to the wrong ADOM type.

B.

This FortiGate model is not fully supported.

C.

FortiGate does not have logging configured correctly.

D.

This FortiGate is part of an HA cluster but it is the secondary device.

Question 42

Which two statement are true regardless initial Logs sync and Log Data Sync for Ha on FortiAnalyzer?

Options:

A.

By default, Log Data Sync is disabled on all backup devise.

B.

Log Data Sync provides real-time log synchronization to all backup devices.

C.

With initial Logs Sync, when you add a unit to an HA cluster, the primary device synchronizes its logs with the backup device.

D.

When Logs Data Sync is turned on, the backup device will reboot and then rebuilt the log database with the synchronized logs.

Question 43

Which FortiAnalyzer feature allows you to retrieve the archived logs matching a specific timeframe from

another FortiAnalyzer device?

Options:

A.

Log upload

B.

Indicators of Compromise

C.

Log forwarding an aggregation mode

D.

Log fetching

Question 44

Refer to the exhibit.

Based on the output, what can you conclude about the FortiAnalyzer logging status?

Options:

A.

The connection between FortiGate and FortiAnalyzer is overloaded.

B.

FortiGate has logs to send, but FortiAnalyzer is unavailable.

C.

FortiGate is configured to send logs in batches.

D.

FortiGate is sending logs again after it performed a reboot.

Question 45

What purposes does the auto-cache setting on reports serve? (Choose two.)

Options:

A.

To reduce report generation time

B.

To automatically update the hcache when new logs arrive

C.

To reduce the log insert lag rate

D.

To provide diagnostics on report generation time

Question 46

Which daemon is responsible for enforcing raw log file size?

Options:

A.

logfiled

B.

oftpd

C.

sqlplugind

D.

miglogd

Question 47

Which two actions should an administrator take to view Compromised Hosts on FortiAnalyzer? (Choose two.)

Options:

A.

Enable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent to FortiAnalyzer.

B.

Make sure all endpoints are reachable by FortiAnalyzer.

C.

Enable device detection on an interface on the FortiGate devices that are connected to the FortiAnalyzer device.

D.

Subscribe FortiAnalyzer to FortiGuard to keep its local threat database up to date.

Question 48

Which statement when you are upgrading the firmware on an HA cluster made up of three FortiAnalyzer devices is true?

Options:

A.

You can perform the firmware upgrade using only a console connection.

B.

All FortiAnalyzer devices will be upgraded at the same time.

C.

Enabling uninterruptible-upgrade prevents normal operations from being interrupted during the upgrade.

D.

First, upgrade the secondary devices, and then upgrade the primary device.

Question 49

Logs are being deleted from one of the ADOMs earlier than the configured setting for archiving in the data

policy.

What is the most likely problem?

Options:

A.

CPU resources are too high

B.

Logs in that ADOM are being forwarded, in real-time, to another FortiAnalyzer device

C.

The total disk space is insufficient and you need to add other disk

D.

The ADOM disk quota is set too low, based on log rates

Question 50

Refer to the exhibit.

The exhibit shows the creation of a new administrator on FortiAnalyzer.

What are two effects of enabling the choice Match all users on remote server when configuring a new administrator? (Choose two.)

Options:

A.

It allows user accounts in the LDAP server to use two-factor authentication.

B.

It creates a wildcard administrator using an LDAP server.

C.

User Remote-Admin from the LDAP server will be able to log in to FortiAnalyzer at any time.

D.

Administrators can log in to FortiAnalyzer using their credentials on the remote LDAP server.

Question 51

Which SQL query is in the correct order to query the database in the FortiAnslyzer?

Options:

A.

SELECT devid FROM Slog GROOP BY devid WHERE * user' =* USERl'

B.

SELECT devid WHERE 'u3er'='USERl' FROM $ log GROUP BY devid

C.

SELECT devid FROM Slog- WHERE *user' =' USERl' GROUP BY devid

D.

FROM Slog WHERE 'user* =' USERl' SELECT devid GROUP BY devid

Demo: 51 questions
Total 171 questions