FCP - FortiAnalyzer 7.4 Administrator Questions and Answers
What are the operating modes of FortiAnalyzer? (Choose two)
An administrator has configured the following settings:
config system fortiview settings
set resolve-ip enable
end
What is the significance of executing this command?
Which item must you configure on FortiAnalyzer to email generated reports automatically?
What remote authentication servers can you configure to validate your FortiAnalyzer administrator logons? (Choose three)
In a Fortinet Security Fabric, what can make an upstream FortiGate create traffic logs associated with sessions initiated on downstream FortiGate devices?
Which three RAID configurations provide fault tolerance on FortiAnalyzer? (Choose three.)
Which two parameters are used to calculate the Total Quota value available on FortiAnalyzer? (Choose two.)
Which two purposes does the auto cache setting on reports serve? (Choose two.)
How do you restrict an administrator’s access to a subset of your organization’s ADOMs?
Refer to the exhibit.
The exhibit shows the creation of a new administrator on FortiAnalyzer.
What are two effects of enabling the choice Match all users on remote server when configuring a new administrator? (Choose two.)
A rogue administrator was accessing FortiAnalyzer without permission, and you are tasked to see what activity was performed by that rogue administrator on FortiAnalyzer.
What can you do on FortiAnalyzer to accomplish this?
You crested a playbook on FortiAnalyzer that uses a FortiOS connector
When configuring the FortiGate side, which type of trigger must be used so that the actions in an automation stitch are available in the FortiOS connector?
An administrator, fortinet, can view logs and perform device management tasks, such as adding and removing registered devices. However, administrator fortinet is not able to create a mail server that can be used to send alert emails.
What can be the problem?
Which process is responsible for enforcing the log file size?
Which two statements are true regarding log fetching on FortiAnalyzer? (Choose two.)
After generating a report, you notice the information you were expecting to see is not included in it. What are two possible reasons for this scenario? (Choose two.)
Refer to the exhibit.
Laptopt is used by several administrators to manage FortiAnalyzer. You want to configure a generic text filter that matches all login attempts to the web interface generated by any user other than "admin" and coming from Laptop1:
Which filter will achieve the desired result?
Why should you use an NTP server on FortiAnalyzer and all registered devices that log into FortiAnalyzer?
Refer to the exhibit.
Based on the output, what can you conclude about the FortiAnalyzer logging status?
Refer to the exhibits.
How many events will be added to the incident created after running this playbook?
Which two methods can you use to send event notifications when an event occurs that matches a configured
event handler? (Choose two.)
Refer to the exhibit.
What does the data point at 12:20 indicate?
Which daemon is responsible for enforcing raw log file size?
Refer to the exhibit.
Which two statements are true regarding enabling auto-cache on FortiAnalyzer? (Choose two.)
What are offline logs on FortiAnalyzer?
What FortiGate process caches logs when FortiAnalyzer is not reachable?
Which two elements are contained in a system backup created on FortiAnalyzer? (Choose two.)
Which statements are true of Administrative Domains (ADOMs) in FortiAnalyzer? (Choose two.)
By default, what happens when a log file reaches its maximum file size?
Which statement about the FortiSIEM management extension is correct?
Logs are being deleted from one of your ADOMs earlier that the configured setting for archiving in your data policy. What is the most likely problem?
Logs are being deleted from one of the ADOMs earlier than the configured setting for archiving in the data
policy.
What is the most likely problem?
In FortiAnalyzer’s FormView, source and destination IP addresses from FortiGate devices are not resolving to
a hostname. How can you resolve the source and destination IPs, without introducing any additional
performance impact to FortiAnalyzer?
Which two statements regarding FortiAnalyzer log forwarding modes are true? (Choose two.)
Which two statements are true regarding high availability (HA) on FortiAnalyzer? (Choose two.)
Refer to the exhibit.
Based on the partial outputs displayed, which devices can be members of a FortiAnalyzer Fabric?
You need to upgrade your FortiAnalyzer firmware.
What happens to the logs being sent to FortiAnalyzer from FortiGate during the time FortiAnalyzer is
temporarily unavailable?
Which two statements are correct regarding the export and import of playbooks? (Choose two.)
What is required to authorize a FortiGate on FortiAnalyzer using Fabric authorization?
You are using RAID with a FortiAnalyzer that supports software RAID, and one of the hard disks on
FortiAnalyzer has failed.
What is the recommended method to replace the disk?
Which tabs do not appear when FortiAnalyzer is operating in Collector mode?
A play book contains five tasks in total. An administrator executed the playbook and four out of five tasks finished successfully, but one task failed. What will be the status of the playbook after its execution?
What is the purpose of a predefined template on the FortiAnalyzer?
On the RAID management page, the disk status is listed as Initializing.
What does the status Initializing indicate about what the FortiAnalyzer is currently doing?
Which two methods can you use to restrict administrative access on FortiAnalyzer? (Choose two.)
View the exhibit.
Why is the total quota less than the total system storage?
What are two benefits of using fabric connectors? (Choose two.)
What is the purpose of the following CLI command?
An administrator has moved a FortiGate device from the root ADOM to ADOM1.
Which two statements are true regarding logs? (Choose two.)
How can you configure FortiAnalyzer to permit administrator logins from only specific locations?
Which statement about the FortiSOAR management extension is correct?