Winter Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dumps65

Fortinet NSE5_FAZ-7.2 Dumps

Page: 1 / 14
Total 137 questions

Fortinet NSE 5 - FortiAnalyzer 7.2 Questions and Answers

Question 1

Which item must you configure on FortiAnalyzer to email generated reports automatically?

Options:

A.

Output profile

B.

Report scheduling

C.

SFTP server

D.

SNMP server

Question 2

What are offline logs on FortiAnalyzer?

Options:

A.

Compressed logs, which are also known as archive logs, are considered to be offline logs.

B.

When you restart FortiAnalyzer. all stored logs are considered to be offline logs.

C.

Logs that are indexed and stored in the SQL database.

D.

Logs that are collected from offline devices after they boot up.

Question 3

What remote authentication servers can you configure to validate your FortiAnalyzer administrator logons? (Choose three)

Options:

A.

RADIUS

B.

Local

C.

LDAP

D.

PKI

E.

TACACS+

Question 4

Which two statements are true regarding the outbreak detection service? (Choose two.)

Options:

A.

New alerts are received by email.

B.

Outbreak alerts are available on the root ADOM only.

C.

An additional license is required.

D.

It automatically downloads new event handlers and reports.

Question 5

When working with FortiAnalyzer reports, what is the purpose of a dataset?

Options:

A.

To provide the layout used for reports

B.

To define the chart type to be used

C.

To retrieve data from the database

D.

To set the data included in templates

Question 6

A playbook contains five tasks in total. An administrator runs the playbook and four out of five tasks finish successfully, but one task fails. What will be the status of the playbook after it is run?

Options:

A.

Running

B.

Failed

C.

Upstream_failed

D.

Success

Question 7

By default, what happens when a log file reaches its maximum file size?

Options:

A.

FortiAnalyzer overwrites the log files.

B.

FortiAnalyzer stops logging.

C.

FortiAnalyzer rolls the active log by renaming the file.

D.

FortiAnalyzer forwards logs to syslog.

Question 8

An administrator has configured the following settings:

config system fortiview settings

set resolve-ip enable

end

What is the significance of executing this command?

Options:

A.

Use this command only if the source IP addresses are not resolved on FortiGate.

B.

It resolves the source and destination IP addresses to a hostname in FortiView on FortiAnalyzer.

C.

You must configure local DNS servers on FortiGate for this command to resolve IP addresses on Forti Analyzer.

D.

It resolves the destination IP address to a hostname in FortiView on FortiAnalyzer.

Question 9

How does FortiAnalyzer retrieve specific log data from the database?

Options:

A.

SQL FROM statement

B.

SQL GET statement

C.

SQL SELECT statement

D.

SQL EXTRACT statement

Question 10

FortiAnalyzer reports are dropping analytical data from 15 days ago, even though the data policy setting for

analytics logs is 60 days.

What is the most likely problem?

Options:

A.

Quota enforcement is acting on analytical data before a report is complete

B.

Logs are rolling before the report is run

C.

CPU resources are too high

D.

Disk utilization for archive logs is set for 15 days

Question 11

You’ve moved a registered logging device out of one ADOM and into a new ADOM. What happens when you rebuild the new ADOM database?

Options:

A.

FortiAnalyzer resets the disk quota of the new ADOM to default.

B.

FortiAnalyzer migrates archive logs to the new ADOM.

C.

FortiAnalyzer migrates analytics logs to the new ADOM.

D.

FortiAnalyzer removes logs from the old ADOM.

Question 12

Which two settings must you configure on FortiAnalyzer to allow non-local administrators to authenticate to FortiAnalyzer with any user account in a single LDAP group? (Choose two.)

Options:

A.

A local wildcard administrator account

B.

A remote LDAP server

C.

A trusted host profile that restricts access to the LDAP group

D.

An administrator group

Question 13

The admin administrator is failing to register a FortiClient EMS on the FortiAnalyzer device.

What can be the reason for this failure?

Options:

A.

FortiAnalyzer is in an HA cluster.

B.

ADOM mode should be set to advanced, in order to register the FortiClient EMS device.

C.

ADOMs are not enabled on FortiAnalyzer.

D.

A separate license is required on FortiAnalyzer in order to register the FortiClient EMS device.

Question 14

What are the operating modes of FortiAnalyzer? (Choose two)

Options:

A.

Standalone

B.

Manager

C.

Analyzer

D.

Collector

Question 15

Which two actions should an administrator take to view Compromised Hosts on FortiAnalyzer? (Choose two.)

Options:

A.

Enable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent to FortiAnalyzer.

B.

Make sure all endpoints are reachable by FortiAnalyzer.

C.

Enable device detection on an interface on the FortiGate devices that are connected to the FortiAnalyzer device.

D.

Subscribe FortiAnalyzer to FortiGuard to keep its local threat database up to date.

Question 16

When you perform a system backup, what does the backup configuration contain? (Choose two.)

Options:

A.

Generated reports

B.

Device list

C.

Authorized devices logs

D.

System information

Question 17

Refer to the exhibit.

as

Which two statements are true regarding enabling auto-cache on FortiAnalyzer? (Choose two.)

Options:

A.

Report size will be optimized to conserve disk space on FortiAnalyzer.

B.

Reports will be cached in the memory.

C.

This feature is automatically enabled for scheduled reports.

D.

Enabling auto-cache reduces report generation time for reports that require a long time to assemble datasets.

Question 18

In the FortiAnalyzer FortiView, source and destination IP addresses from FortiGate devices arenotresolving to a hostname.

How can you resolve the source and destination IP addresses, without introducing any additional performance impact to FortiAnalyzer?

Options:

A.

Resolve IP addresses on a per-ADOM basis to reduce delay on FortiView while IPs resolve

B.

Configure# set resolve-ip enablein the system FortiView settings

C.

Configure local DNS servers on FortiAnalyzer

D.

Resolve IP addresses on FortiGate

Question 19

View the exhibit.

as

Why is the total quota less than the total system storage?

Options:

A.

3.6% of the system storage is already being used.

B.

Some space is reserved for system use, such as storage of compression files, upload files, and temporary report files

C.

The oftpd process has not archived the logs yet

D.

The logfiled process is just estimating the total quota

Question 20

What statements are true regarding FortiAnalyzer 's treatment of high availability (HA) dusters? (Choose two)

Options:

A.

FortiAnalyzer distinguishes different devices by their serial number.

B.

FortiAnalyzer receives logs from d devices in a duster.

C.

FortiAnalyzer receives bgs only from the primary device in the cluster.

D.

FortiAnalyzer only needs to know (he serial number of the primary device in the cluster-it automaticaly discovers the other devices.

Question 21

Which statement is true when you are upgrading the firmware on an HA cluster made up of two FortiAnalyzer devices?

Options:

A.

First, upgrade the secondary device, and then upgrade the primary device.

B.

Both FortiAnalyzer devices will be upgraded at the same time.

C.

You can enable uninterruptible-upgrade so that the normal FortiAnalyzer operations are not interrupted while the cluster firmware upgrades.

D.

You can perform the firmware upgrade using only a console connection.

Question 22

Which two elements are contained in a system backup created on FortiAnalyzer? (Choose two.)

Options:

A.

System information

B.

Logs from registered devices

C.

Report information

D.

Database snapshot

Question 23

What is the purpose of trigger variables?

Options:

A.

To display statistics about the playbook runtime

B.

To use information from the trigger to filter the action in a task

C.

To provide the trigger information to make the playbook start running

D.

To store the start times of playbooks with On_Schedule triggers

Question 24

How do you restrict an administrator’s access to a subset of your organization’s ADOMs?

Options:

A.

Set the ADOM mode toAdvanced

B.

Assign the ADOMs to the administrator’s account

C.

Configure trusted hosts

D.

Assign the defaultSuper_Useradministrator profile

Question 25

Which statement is true regarding Macros on FortiAnalyzer?

Options:

A.

Macros are ADOM specific and each ADOM will have unique macros relevant to that ADOM.

B.

Macros are supported only on the FortiGate ADOM.

C.

Macros are useful in generating excel log files automatically based on the reports settings.

D.

Macros are predefined templates for reports and cannot be customized.

Question 26

Refer to the exhibit.

as

What does the data point at 14:55 tell you?

Options:

A.

The received rate is almost at its maximum for this device

B.

The sqlplugind daemon is behind in log indexing by two logs

C.

Logs are being dropped

D.

Raw logs are reaching FortiAnalyzer faster than they can be indexed

Question 27

Which statement about sending notifications with incident updates is true?

Options:

A.

Notifications can be sent only when an incident is created or deleted.

B.

You must configure an output profile to send notifications by email.

C.

Each incident can send notifications to a single external platform.

D.

Each connector used can have different notification settings.

Question 28

Which two statement are true regardless initial Logs sync and Log Data Sync for Ha on FortiAnalyzer?

Options:

A.

By default, Log Data Sync is disabled on all backup devise.

B.

Log Data Sync provides real-time log synchronization to all backup devices.

C.

With initial Logs Sync, when you add a unit to an HA cluster, the primary device synchronizes its logs with the backup device.

D.

When Logs Data Sync is turned on, the backup device will reboot and then rebuilt the log database with the synchronized logs.

Question 29

Which statements are true regarding securing communications between FortiAnalyzer and FortiGate with SSL? (Choose two.)

Options:

A.

SSL is the default setting.

B.

SSL communications are auto-negotiated between the two devices.

C.

SSL can send logs in real-time only.

D.

SSL encryption levels are globally set on FortiAnalyzer.

E.

FortiAnalyzer encryption level must be equal to, or higher than, FortiGate.

Question 30

After generating a report, you notice the information you were expecting to see is not included in it. What are two possible reasons for this scenario? (Choose two.)

Options:

A.

You enabled auto-cache with extended log filtering.

B.

The logfiled service has not indexed all the expected logs.

C.

The logs were overwritten by the data retention policy.

D.

The time frame selected in the report is wrong.

Question 31

On FortiAnalyzer, what is a wildcard administrator account?

Options:

A.

An account that permits access to members of an LDAP group

B.

An account that allows guest access with read-only privileges

C.

An account that requires two-factor authentication

D.

An account that validates against any user account on a FortiAuthenticator

Question 32

What is Log Insert Lag Time on FortiAnalyzer?

Options:

A.

The number of times in the logs where end users experienced slowness while accessing resources.

B.

The amount of lag time that occurs when the administrator is rebuilding the ADOM database.

C.

The amount of time that passes between the time a log was received and when it was indexed on FortiAnalyzer.

D.

The amount of time FortiAnalyzer takes to receive logs from a registered device

Question 33

Which FortiAnalyzer feature allows you to use a proactive approach when managing your network security?

Options:

A.

Incidents dashboards

B.

Threat hunting

C.

FortiView Monitor

D.

Outbreak alert services

Question 34

Which tabs do not appear when FortiAnalyzer is operating in Collector mode?

Options:

A.

FortiView

B.

Event Management

C.

Device Manger

D.

Reporting

Question 35

On the RAID management page, the disk status is listed asInitializing.

What does the statusInitializingindicate about what the FortiAnalyzer is currently doing?

Options:

A.

FortiAnalyzer is ensuring that the parity data of a redundant drive is valid

B.

FortiAnalyzer is writing data to a newly added hard drive to restore it to an optimal state

C.

FortiAnalyzer is writing to all of its hard drives to make the array fault tolerant

D.

FortiAnalyzer is functioning normally

Question 36

View the exhibit:

as

What does the 1000MB maximum for disk utilization refer to?

Options:

A.

The disk quota for the FortiAnalyzer model

B.

The disk quota for all devices in the ADOM

C.

The disk quota for each device in the ADOM

D.

The disk quota for the ADOM type

Question 37

What purposes does the auto-cache setting on reports serve? (Choose two.)

Options:

A.

To reduce report generation time

B.

To automatically update the hcache when new logs arrive

C.

To reduce the log insert lag rate

D.

To provide diagnostics on report generation time

Question 38

In FortiAnalyzer’s FormView, source and destination IP addresses from FortiGate devices are not resolving to

a hostname. How can you resolve the source and destination IPs, without introducing any additional

performance impact to FortiAnalyzer?

Options:

A.

Configure local DNS servers on FortiAnalyzer

B.

Resolve IPs on FortiGate

C.

Configure # set resolve-ip enable in the system FortiView settings

D.

Resolve IPs on a per-ADOM basis to reduce delay on FortiView while IPs resolve

Question 39

Which FortiAnalyzer feature allows you to retrieve the archived logs matching a specific timeframe from

another FortiAnalyzer device?

Options:

A.

Log upload

B.

Indicators of Compromise

C.

Log forwarding an aggregation mode

D.

Log fetching

Question 40

What are two benefits of using fabric connectors? (Choose two.)

Options:

A.

They allow FortiAnalyzer to send logs in real-time to public cloud accounts.

B.

You do not need an additional license to send logs to the cloud platform.

C.

Fabric connectors allow you to improve redundancy.

D.

Using fabric connectors is more efficient than using third-party polling with API.

Question 41

For proper log correlation between the logging devices and FortiAnalyzer, FortiAnalyzer and all registered

devices should:

Options:

A.

Use DNS

B.

Use host name resolution

C.

Use real-time forwarding

D.

Use an NTP server

Page: 1 / 14
Total 137 questions