Pre-Summer Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

Fortinet NSE 5 - FortiAnalyzer 7.6 Analyst Question and Answers

Fortinet NSE 5 - FortiAnalyzer 7.6 Analyst

Last Update May 31, 2026
Total Questions : 79

We are offering FREE FCP_FAZ_AN-7.6 Fortinet exam questions. All you do is to just go and sign up. Give your details, prepare FCP_FAZ_AN-7.6 free exam questions and then go for complete pool of Fortinet NSE 5 - FortiAnalyzer 7.6 Analyst test questions that will help you more.

FCP_FAZ_AN-7.6 pdf

FCP_FAZ_AN-7.6 PDF

$36.75  $104.99
FCP_FAZ_AN-7.6 Engine

FCP_FAZ_AN-7.6 Testing Engine

$43.75  $124.99
FCP_FAZ_AN-7.6 PDF + Engine

FCP_FAZ_AN-7.6 PDF + Testing Engine

$57.75  $164.99
Questions 1

Which statement about SQL SELECT queries is true?

Options:

A.  

They can be used to purge log entries from the database.

B.  

They must be followed immediately by a WHERE clause.

C.  

They can be used to display the database schema.

D.  

They are not used in macros.

Discussion 0
Questions 2

(When there are no matching parsers for a device log, what does FortiAnalyzer do? (Choose one answer)

Options:

A.  

Drops the log

B.  

Applies the generic SYSLOG parser

C.  

Stores the log but doesn’t normalize it

D.  

Archives the log for future analysis

Discussion 0
Questions 3

(Refer to the exhibit.

Which two observations can you make after reviewing this log entry? (Choose two answers)

Options:

A.  

This is a normalized log.

B.  

This is a formatted view of the log.

C.  

This is the original log that FortiAnalyzer received from FortiGate.

D.  

This log is in a raw log format.

Discussion 0
Questions 4

Which two actions should an administrator take to view Compromised Hosts on FortiAnalyzer? (Choose two.)

Options:

A.  

Enable device detection on the FortiGate devices that are sending logs to FortiAnalyzer.

B.  

Enable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent to FortiAnalyzer.

C.  

Make sure all endpoints are reachable by FortiAnalyzer.

D.  

Subscribe FortiAnalyzer to FortiGuard to keep its local threat database up to date.

Discussion 0
Questions 5

Which statement about sending notifications with incident updates is true?

Options:

A.  

Each connector used can have different notification settings

B.  

Each incident can send notification to a single external platform.

C.  

You must configure an output profile to send notifications by email.

D.  

Notifications can be sent only when an incident is created oi deleted.

Discussion 0
Questions 6

Which two statements about playbook execution are true? (Choose two.)

Options:

A.  

FortiAnalyzer will not commit changes made by a Failed playbook

B.  

The Playbook Monitor provides troubleshooting logs

C.  

You can run the default debugging playbook to investigate playbook errors.

D.  

Even if the playbook status is Failed, individual tasks may have succeeded.

Discussion 0
Questions 7

In firmware version 7.6, how does on-premises FortiAnalyzer store logs? (Choose one answer)

Options:

A.  

Uses ClickHouse database

B.  

Uses MySQL database

C.  

Uses Postgres SQL database

D.  

Uses Elasticsearch database

Discussion 0
Questions 8

What is the purpose of running the command diagnose sql status sqlreportd?

Options:

A.  

To view a list of scheduled reports

B.  

To list the current SQL processes running

C.  

To display the SQL query connections and hcache status

D.  

To identify the database log insertion status

Discussion 0
Questions 9

Why must you wait for several minutes before you run a playbook that you just created?

Options:

A.  

FortiAnalyzer needs that time to parse the new playbook.

B.  

FortiAnalyzer needs that time to debug the new playbook.

C.  

FortiAnalyzer needs that time to back up the current playbooks.

D.  

FortiAnalyzer needs that time to ensure there are no other playbooks running.

Discussion 0
Questions 10

A playbook contains five tasks in total. An administrator runs the playbook and four out of five tasks finish successfully, but one task fails.

What will be the status of the playbook after it is run?

Options:

A.  

Attention required

B.  

Upstream_failed

C.  

Failed

D.  

Success

Discussion 0
Questions 11

Refer to the exhibit.

An analyst is trying to create a dataset to pull all gambling websites that were visited by end users.

Which SQL query on FortiAnalyzer will give the result shown in the exhibit?

Options:

A.  

[Selected] select srcip as " SourceIP " , dstip as " DestIP " , url from $log where catdesc = ' Gambling '

B.  

select srcip as " SourceIPv6 " , dstip as " DestIPv6 " , url from $log where catdesc = ' Gambling '

C.  

select srcip as " SourceIP " , dstip as " DestIP " , url from $log where catdesc = ' Dating '

D.  

select srcip as " SourceIP " , dstip as " DestIP " , url from ' Gambling ' where catdesc = $log

Discussion 0
Questions 12

(Refer to the exhibit.

Which statement about the displayed event is correct? (Choose one answer)

Options:

A.  

The security risk was dropped.

B.  

The risk source is isolated.

C.  

The security risk was blocked.

D.  

The security event risk is from an application control log.

Discussion 0
Questions 13

Exhibit.

Assume these are all the events that exist on the FortiAnalyzer device.

How many events will be added to the incident created after running this playbook?

Options:

A.  

Eleven events will be added.

B.  

Seven events will be added

C.  

No events will be added.

D.  

Four events will be added.

Discussion 0
Questions 14

Refer to the exhibit with partial output:

Your colleague exported a playbook and has sent it to you for review. You open the file in a text editor and observer the output as shown in the exhibit.

Which statement about the export is true?

Options:

A.  

The export data type is zipped.

B.  

The playbook is misconfigured.

C.  

The option to include the connector was not selected.

D.  

Your colleague put a password on the export.

Discussion 0
Questions 15

(In a FortiAnalyzer Fabric deployment, which three modules from Fabric members are available for analysis on the supervisor? (Choose three answers))

Options:

A.  

Playbooks

B.  

Indicators

C.  

Logs

D.  

Events

E.  

Reports

Discussion 0
Questions 16

What are two effects of enabling auto-cache in a FortiAnalyzer report? (Choose two.)

Options:

A.  

The generation time for reports is decreased.

B.  

When new logs are received, the hard-cache data is updated automatically.

C.  

FortiAnalyzer local cache is used to store generated reports.

D.  

The size of newly generated reports is optimized to conserve disk space.

Discussion 0
Questions 17

Which two statements regarding FortiAnalyzer operating modes are true? (Choose two.)

Options:

A.  

When running in collector mode, FortiAnalyzer can forward logs to a syslog server.

B.  

FortiAnalyzer runs in collector mode by default unless it is configured for HA.

C.  

You can create and edit reports when FortiAnalyzer is running in collector mode.

D.  

A topology with FortiAnalyzer devices running in both modes can improve their performance.

Discussion 0
Questions 18

Exhibit.

What does the data point at 12:20 indicate?

Options:

A.  

The log insert log time is increasing.

B.  

FortiAnalyzer is using its cache to avoid dropping logs.

C.  

The performance of FortiAnalyzer is below the baseline.

D.  

The sqiplugind service is caught up with the logs

Discussion 0
Questions 19

Exhibit.

A FortiAnalyzer analyst is customizing a SQL query to use in a report.

Which SQL query should the analyst run to get the expected results?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 20

Refer to the exhibit.

What can you conclude about the output?

Options:

A.  

Both messages and logs are almost finished indexing.

B.  

There are more traffic logs than event logs.

C.  

The message rate being higher than the log rate is not normal.

D.  

The output is ADOM-specific.

Discussion 0
Questions 21

When managing incidents on FortiAnalyzer, what must an analyst be aware of?

Options:

A.  

You can manually attach generated reports to incidents.

B.  

The status of the incident is always linked to the status of the attached event.

C.  

Severity incidents rated with the level High have an initial service-level agreement (SLA) response time of 1 hour.

D.  

Incidents must be acknowledged before they can be analyzed.

Discussion 0
Questions 22

(Which two statements about FortiAnalyzer Fabric deployments are true? (Choose two answers)

Options:

A.  

Supervisors can be in high availability (HA) for redundancy purposes only.

B.  

Fabric members can operate in analyzer mode only.

C.  

Fabric members do not forward their logs to the supervisor.

D.  

Supervisors and members must be in the same time zone.

Discussion 0
Questions 23

Which two statements about exporting and importing playbooks are true? (Choose two.)

Options:

A.  

A playbook that was disabled when it was exported will be disabled when it is imported.

B.  

Playbooks can be imported to a different FortiAnalyzer device, but only if the connectors already exist

C.  

You can import a playbook even if there is another one with the same name in the destination

D.  

You can export only one playbook at a time.

Discussion 0