Summer Special Discount 60% Offer - Ends in 0d 00h 00m 00s - Coupon code: brite60

ExamsBrite Dumps

FCP - FortiAnalyzer 7.4 Administrator Question and Answers

FCP - FortiAnalyzer 7.4 Administrator

Last Update Sep 12, 2025
Total Questions : 183

We are offering FREE FCP_FAZ_AD-7.4 Fortinet exam questions. All you do is to just go and sign up. Give your details, prepare FCP_FAZ_AD-7.4 free exam questions and then go for complete pool of FCP - FortiAnalyzer 7.4 Administrator test questions that will help you more.

FCP_FAZ_AD-7.4 pdf

FCP_FAZ_AD-7.4 PDF

$42  $104.99
FCP_FAZ_AD-7.4 Engine

FCP_FAZ_AD-7.4 Testing Engine

$50  $124.99
FCP_FAZ_AD-7.4 PDF + Engine

FCP_FAZ_AD-7.4 PDF + Testing Engine

$66  $164.99
Questions 1

Logs are being deleted from one of your ADOMs earlier that the configured setting for archiving in your data policy. What is the most likely problem?

Options:

A.  

The total disk space is insufficient and you need to add other disk.

B.  

CPU resources are too high.

C.  

The ADOM disk quota is set too low based on log rates.

D.  

Logs in that ADOM are being forwarded in real-time to another FortiAnalyzer device.

Discussion 0
Questions 2

FortiAnalyzer uses the Optimized Fabric Transfer Protocok (OFTP) over SSL for what purpose?

Options:

A.  

To upload logs to an SFTP server

B.  

To prevent log modification during backup

C.  

To send an identical set of logs to a second logging server

D.  

To encrypt log communication between devices

Discussion 0
Questions 3

What must you configure on FortiAnalyzer to upload a FortiAnalyzer report to a supported external server?

(Choose two.)

Options:

A.  

SFTP, FTP, or SCP server

B.  

Mail server

C.  

Output profile

D.  

Report scheduling

Discussion 0
Questions 4

NO: 5

Which FortiAnalyzer feature allows you to retrieve the archived logs matching a specific timeframe from

another FortiAnalyzer device?

Options:

A.  

Log upload

B.  

Indicators of Compromise

C.  

Log forwarding an aggregation mode

D.  

Log fetching

Discussion 0
Questions 5

What are the operating modes of FortiAnalyzer? (Choose two)

Options:

A.  

Standalone

B.  

Manager

C.  

Analyzer

D.  

Collector

Discussion 0
Questions 6

Which statement about sending notifications with incident updates is true?

Options:

A.  

Notifications can be sent only when an incident is created or deleted.

B.  

You must configure an output profile to send notifications by email.

C.  

Each incident can send notifications to a single external platform.

D.  

Each connector used can have different notification settings.

Discussion 0
Questions 7

If you upgrade your FortiAnalyzer firmware, what report elements can be affected?

Options:

A.  

Output profiles

B.  

Report settings

C.  

Report scheduling

D.  

Custom datasets

Discussion 0
Questions 8

Refer to the exhibit.

The exhibit shows the creation of a new administrator on FortiAnalyzer. The new account uses the credentials stored on an LDAP server.

Why would an administrator configure a password for this account?

Options:

A.  

This password is used if the authentication server becomes unreachable.

B.  

This password authenticates FortiAnalyzer aqainst the LDAP server.

C.  

This password is set to comply with FortiAnalvzer password policy

D.  

This password is required because this is a restricted user.

Discussion 0
Questions 9

Refer to the exhibit.

The capture displayed was taken on a FortiAnalyzer.

Why is a single IP address shown as the source for all logs received?

Options:

A.  

FortiAnalyzer is using the device MAC addresses to differentiate their logs.

B.  

The logs belong to devices that are part of a high availability (HA) cluster.

C.  

FortiAnalyzer is receiving logs from the root FortiGate of a Security Fabric.

D.  

The device sending logs has two VDOMs in the same ADOM.

Discussion 0
Questions 10

You are trying to initiate an authorization request from FortiGate to FortiAnalyzer, but the Security Fabric window does not open when you click Authorize.

Which two reasons can cause this to happen? (Choose two.)

Options:

A.  

A pre-shared key needs to be established on both sides.

B.  

The management computer does not have connectivity to the authorization IP address and port combination.

C.  

The Security Fabric root is unauthorized and needs to be added as a trusted host.

D.  

The fabric authorization settings on FortiAnalyzer are misconfigured.

Discussion 0
Questions 11

An administrator has configured the following settings:

config system fortiview settings

set resolve-ip enable

end

What is the significance of executing this command?

Options:

A.  

Use this command only if the source IP addresses are not resolved on FortiGate.

B.  

It resolves the source and destination IP addresses to a hostname in FortiView on FortiAnalyzer.

C.  

You must configure local DNS servers on FortiGate for this command to resolve IP addresses on Forti Analyzer.

D.  

It resolves the destination IP address to a hostname in FortiView on FortiAnalyzer.

Discussion 0
Questions 12

An administrator has configured the following settings:

config system global

set log-checksum md5-auth

end

What is the significance of executing this command?

Options:

A.  

This command records the log file MD5 hash value.

B.  

This command records passwords in log files and encrypts them.

C.  

This command encrypts log transfer between FortiAnalyzer and other devices.

D.  

This command records the log file MD5 hash value and authentication code.

Discussion 0
Questions 13

Refer to the exhibit.

Which two statements are true regarding enabling auto-cache on FortiAnalyzer? (Choose two.)

Options:

A.  

Report size will be optimized to conserve disk space on FortiAnalyzer.

B.  

Reports will be cached in the memory.

C.  

This feature is automatically enabled for scheduled reports.

D.  

Enabling auto-cache reduces report generation time for reports that require a long time to assemble datasets.

Discussion 0
Questions 14

Which log will generate an event with the status Contained?

Options:

A.  

An IPS log with action=pass.

B.  

A WebFilter log with action=dropped.

C.  

An AV log with action=quarantine.

D.  

An AppControl log with action=blocked.

Discussion 0
Questions 15

If you upgrade the FortiAnalyzer firmware, which report element can be affected?

Options:

A.  

Custom datasets

B.  

Report scheduling

C.  

Report settings

D.  

Output profiles

Discussion 0
Questions 16

A rogue administrator was accessing FortiAnalyzer without permission, and you are tasked to see what activity was performed by that rogue administrator on FortiAnalyzer.

What can you do on FortiAnalyzer to accomplish this?

Options:

A.  

Click FortiView and generate a report for that administrator.

B.  

Click Task Monitor and view the tasks performed by that administrator.

C.  

Click Log View and generate a report for that administrator.

D.  

View the tasks performed by the rogue administrator in Fabric View.

Discussion 0
Questions 17

Which daemon is responsible for enforcing the log file size?

Options:

A.  

sqlplugind

B.  

logfiled

C.  

miglogd

D.  

ofrpd

Discussion 0
Questions 18

What are two effects of enabling auto-cache in a FortiAnalyzer report? (Choose two.)

Options:

A.  

The size of newly generated reports is optimized to conserve disk space.

B.  

FortiAnalyzer local cache is used to store generated reports.

C.  

When new logs are received, the hard-cache data is updated automatically.

D.  

The generation time for reports is decreased.

Discussion 0
Questions 19

Which two statements express the advantages of grouping similar reports? (Choose two.)

Options:

A.  

Improve report completion time.

B.  

Conserve disk space on FortiAnalyzer by grouping multiple similar reports.

C.  

Reduce the number of hcache tables and improve auto-hcache completion time.

D.  

Provides a better summary of reports.

Discussion 0
Questions 20

An administrator has moved FortiGate A from the root ADOM to ADOM1.

Which two statements are true regarding logs? (Choose two.)

Options:

A.  

Analytics logs will be moved to ADOM1 from the root ADOM automatically.

B.  

Archived logs will be moved to ADOM1 from the root ADOM automatically.

C.  

Logs will be presented in both ADOMs immediately after the move.

D.  

Analytics logs will be moved to ADOM1 from the root ADOM after you rebuild the ADOM1 SQL database.

Discussion 0
Questions 21

For which two purposes would you use the command set log-checksum? (Choose two.)

Options:

A.  

To encrypt log communications and data

B.  

To prevent log modification or tampering

C.  

To send an identical set of logs to a second logging server

D.  

To protect log data from man-in-the-middle attacks

Discussion 0
Questions 22

Refer to the exhibit.

Laptop1 is used by several administrators to manage FortiAnalyzer. You want to configure a generic text filter that matches all login attempts to the web interface generated by any user other than "admin", and coming from Laptop1.

Which filter will achieve the desired result?

Options:

A.  

operation-login & dstip==10.1.1.210 & user!-admin

B.  

operation-login & srcip==10.1.1.100 & dstip==10.1.1.210 & user==admin

C.  

operation-login & performed_on=="GUI(10.1.1.210)" & user!=admin

D.  

operation-login & performed_on=="GUI(10.1.1.100)" & user!=admin

Discussion 0
Questions 23

What is the purpose of the FortiAnalyzer command execute format disk?

Options:

A.  

To reset all settings from flash except the current IP addresses and routes.

B.  

To erase all device settings and images, databases, and log data from the disk, but preserve the IP and routing info.

C.  

To perform a low-level format of the disk overwriting the hard disk with random data.

D.  

To reset to factory default settings from flash.

Discussion 0
Questions 24

Refer to the exhibit.

Which image corresponds to the packet capture shown in the exhibit?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 25

Which statement is true regarding Macros on FortiAnalyzer?

Options:

A.  

Macros are ADOM specific and each ADOM will have unique macros relevant to that ADOM.

B.  

Macros are supported only on the FortiGate ADOM.

C.  

Macros are useful in generating excel log files automatically based on the reports settings.

D.  

Macros are predefined templates for reports and cannot be customized.

Discussion 0
Questions 26

What is Log Insert Lag Time on FortiAnalyzer?

Options:

A.  

The number of times in the logs where end users experienced slowness while accessing resources.

B.  

The amount of lag time that occurs when the administrator is rebuilding the ADOM database.

C.  

The amount of time that passes between the time a log was received and when it was indexed on FortiAnalyzer.

D.  

The amount of time FortiAnalyzer takes to receive logs from a registered device

Discussion 0
Questions 27

What is the main purpose of using an NTP server on FortiAnalyzer and all of its registered devices?

Options:

A.  

Log correlation

B.  

Host name resolution

C.  

Log collection

D.  

Real-time forwarding

Discussion 0
Questions 28

What remote authentication servers can you configure to validate your FortiAnalyzer administrator logons? (Choose three)

Options:

A.  

RADIUS

B.  

Local

C.  

LDAP

D.  

PKI

E.  

TACACS+

Discussion 0
Questions 29

Which SQL query is in the correct order to query the database in the FortiAnslyzer?

Options:

A.  

SELECT devid FROM Slog GROOP BY devid WHERE * user' =* USERl'

B.  

SELECT devid WHERE 'u3er'='USERl' FROM $ log GROUP BY devid

C.  

SELECT devid FROM Slog- WHERE *user' =' USERl' GROUP BY devid

D.  

FROM Slog WHERE 'user* =' USERl' SELECT devid GROUP BY devid

Discussion 0
Questions 30

Which two statements are true about FortiAnalyzer log forwarding modes? (Choose two.)

Options:

A.  

Both modes, forwarding and aggregation send logs as soon as they are received.

B.  

Aggregation mode requires two FortiAnalyzer devices.

C.  

Forwarding mode forwards logs to other FortiAnalyzer devices syslog servers, or CEF servers.

D.  

Forwarding mode requires configuration on the server side.

Discussion 0
Questions 31

Which two elements are contained in a system backup created on FortiAnalyzer? (Choose two.)

Options:

A.  

System information

B.  

Logs from registered devices

C.  

Report information

D.  

Database snapshot

Discussion 0
Questions 32

The connection status of a new device on FortiAnalyzer is listed as Unauthorized.

What does that status mean?

Options:

A.  

It is a device whose registration has not yet been accepted in FortiAnalvzer.

B.  

It is a device that has not yet been assigned an ADOM.

C.  

It is a device that is waiting for you to configure a pre-shared key.

D.  

It is a device that FortiAnalvzer does not support.

Discussion 0
Questions 33

In a Fortinet Security Fabric, what can make an upstream FortiGate create traffic logs associated with sessions initiated on downstream FortiGate devices?

Options:

A.  

The traffic destination is another FortiGate in the fabric.

B.  

The upstream FortiGate is configured to do NAT

C.  

Log redundancy is configured in the fabric.

D.  

The downstream device cannot connect to FortiAnalyzer.

Discussion 0
Questions 34

You crested a playbook on FortiAnalyzer that uses a FortiOS connector

When configuring the FortiGate side, which type of trigger must be used so that the actions in an automation stitch are available in the FortiOS connector?

Options:

A.  

FortiAnalyzer Event Handler

B.  

Incoming webhook

C.  

FortiOS Event Log

D.  

Fabric Connector event

Discussion 0
Questions 35

Which process caches logs on FortiGate when FortiAnalyzer is not reachable?

Options:

A.  

logfiled

B.  

miglogd

C.  

sqlplugind

D.  

oftpd

Discussion 0
Questions 36

FortiAnalyzer centralizes which functions? (Choose three)

Options:

A.  

Network analysis

B.  

Graphical reporting

C.  

Content archiving / data mining

D.  

Vulnerability assessment

E.  

Security log analysis / forensics

Discussion 0
Questions 37

Which statement correctly describes RAID 10 (1+0) on FortiAnalyzer?

Options:

A.  

A configuration with four disks, each with 2 TB of capacity, provides a total space of 4 TB.B It combines mirroring striping and distributed parity to provide performance and fault tolerance

B.  

A configuration with four disks, each with 2 TB of capacity, provides a total space of 2 T

B.  

C.  

It uses striping to provide performance and fault tolerance.

Discussion 0
Questions 38

Which FortiAnalyzer feature allows you to use a proactive approach when managing your network security?

Options:

A.  

Incidents dashboards

B.  

Threat hunting

C.  

FortiView Monitor

D.  

Outbreak alert services

Discussion 0
Questions 39

Which item must you configure on FortiAnalyzer to email generated reports automatically?

Options:

A.  

Output profile

B.  

Report scheduling

C.  

SFTP server

D.  

SNMP server

Discussion 0
Questions 40

For which two SAML roles can the FortiAnalyzer be configured? (Choose two.)

Options:

A.  

Principal

B.  

Service provider

C.  

Identity collector

D.  

Identity provider

Discussion 0
Questions 41

Which statement describes online logs on FortiAnalyzer?

Options:

A.  

Logs that reached a specific size and were rolled over

B.  

Logs that can be used to create reports

C.  

Logs that can be viewed using Log Browse

D.  

Logs that are saved to disk, compressed, and available in FortiView

Discussion 0
Questions 42

What is the purpose of output variables?

Options:

A.  

To store playbook execution statistics

B.  

To use the output of the previous task as the input of the current task

C.  

To display details of the connectors used by a playbook

D.  

To save all the task settings when a playbook is exported

Discussion 0
Questions 43

Which two parameters impact the amount of reserved disk space required by FortiAnalyzer? (Choose two.)

Options:

A.  

Total quota

B.  

License type

C.  

RAID level

D.  

Disk size

Discussion 0
Questions 44

You have recently grouped multiple FortiGate devices into a single ADOM. System Settings > Storage Info

shows the quota used.

What does the disk quota refer to?

Options:

A.  

The maximum disk utilization for each device in the ADOM

B.  

The maximum disk utilization for the FortiAnalyzer model

C.  

The maximum disk utilization for the ADOM type

D.  

The maximum disk utilization for all devices in the ADOM

Discussion 0
Questions 45

Which two constraints can impact the amount of reserved disk space required by FortiAnalyzer? (Choose

two.)

Options:

A.  

License type

B.  

Disk size

C.  

Total quota

D.  

RAID level

Discussion 0
Questions 46

If a hard disk fails on a FortiAnalyzer that supports software RAID, what should you do to bring the

FortiAnalyzer back to functioning normally, without losing data?

Options:

A.  

Hot swap the disk

B.  

Replace the disk and rebuild the RAID manually

C.  

Take no action if the RAID level supports a failed disk

D.  

Shut down FortiAnalyzer and replace the disk

Discussion 0
Questions 47

Which two statement are true regardless initial Logs sync and Log Data Sync for Ha on FortiAnalyzer?

Options:

A.  

By default, Log Data Sync is disabled on all backup devise.

B.  

Log Data Sync provides real-time log synchronization to all backup devices.

C.  

With initial Logs Sync, when you add a unit to an HA cluster, the primary device synchronizes its logs with the backup device.

D.  

When Logs Data Sync is turned on, the backup device will reboot and then rebuilt the log database with the synchronized logs.

Discussion 0
Questions 48

Refer to the exhibit, which shows the HA configuration settings of a FortiAnalyzer device.

The administrator wants to join this FortiAnalyzer to an existing HA cluster. What can you conclude from the configuration displayed?

Options:

A.  

After joining the cluster, this FortiAnalyzer will forward received logs to its peers.

B.  

This FortiAnalyzer will trigger a failover after losing communication with its peers for 10 seconds.

C.  

This FortiAnalyzer is configured to route HA traffic through a gateway.

D.  

This FortiAnalyzer will join the existing HA cluster as the secondary.

Discussion 0
Questions 49

Refer to the exhibit.

The exhibit shows “remoteservergroup” is an authentication server group with LDAP and RADIUS servers.

Which two statements express the significance of enabling “Match all users on remote server” when configuring a new administrator? (Choose two.)

Options:

A.  

It creates a wildcard administrator using LDAP and RADIUS servers.

B.  

Administrator can log in to FortiAnalyzer using their credentials on remote servers LDAP and RADIUS.

C.  

Use remoteadmin from LDAP and RADIUS servers will be able to log in to FortiAnalyzer at anytime.

D.  

It allows administrators to use two-factor authentication.

Discussion 0
Questions 50

Refer to the exhibit.

What does the data point at 12:20 indicate?

Options:

A.  

The performance of FortiAnalyzer is below the baseline.

B.  

FortiAnalyzer is using its cache to avoid dropping logs.

C.  

The log insert lag time is increasing.

D.  

The sqlplugind service is caught up with new logs.

Discussion 0
Questions 51

Which statement regarding the FortiAnalyzer Fabric is true?

Options:

A.  

The Fabric supervisor collects logs from the Fabric members.

B.  

Logging devices can register to the Fabric supervisor or to Fabric members.

C.  

Fabric members support HA.

D.  

Administrators can create new incidents from the Fabric supervisor.

Discussion 0
Questions 52

Which two statements about creating ADOMs are true1? (Choose two.)

Options:

A.  

An administrator with the default standard_User profile can create ADOMs.

B.  

Disk quotas can be defined per device inside the ADOM.

C.  

FortiAnalyzer creates default ADOMs when ADOMs are enabled.

D.  

The ADOM type you create must match the device type you are planning to add.

Discussion 0
Questions 53

NO: 14

View the exhibit.

Why is the total quota less than the total system storage?

Options:

A.  

3.6% of the system storage is already being used.

B.  

Some space is reserved for system use, such as storage of compression files, upload files, and temporary report files

C.  

The oftpd process has not archived the logs yet

D.  

The logfiled process is just estimating the total quota

Discussion 0
Questions 54

Refer to the exhibit.

Which statement is correct regarding the event displayed?

Options:

A.  

The security risk was blocked or dropped.

B.  

The security event risk is considered open.

C.  

An incident was created from this event.

D.  

The risk source is isolated.

Discussion 0