Labour Day Special 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

Fortinet NSE 5 - FortiAnalyzer 7.2 Analyst Question and Answers

Fortinet NSE 5 - FortiAnalyzer 7.2 Analyst

Last Update May 2, 2024
Total Questions : 137

We are offering FREE NSE5_FAZ-7.2 Fortinet exam questions. All you do is to just go and sign up. Give your details, prepare NSE5_FAZ-7.2 free exam questions and then go for complete pool of Fortinet NSE 5 - FortiAnalyzer 7.2 Analyst test questions that will help you more.

NSE5_FAZ-7.2 pdf

NSE5_FAZ-7.2 PDF

$35  $99.99
NSE5_FAZ-7.2 Engine

NSE5_FAZ-7.2 Testing Engine

$42  $119.99
NSE5_FAZ-7.2 PDF + Engine

NSE5_FAZ-7.2 PDF + Testing Engine

$56  $159.99
Questions 1

On FortiAnalyzer, what is a wildcard administrator account?

Options:

A.  

An account that permits access to members of an LDAP group

B.  

An account that allows guest access with read-only privileges

C.  

An account that requires two-factor authentication

D.  

An account that validates against any user account on a FortiAuthenticator

Discussion 0
Questions 2

Which two statements about log forwarding are true? (Choose two.)

Options:

A.  

Forwarded logs cannot be filtered to match specific criteria.

B.  

Logs are forwarded in real-time only.

C.  

The client retains a local copy of the logs after forwarding.

D.  

You can use aggregation mode only with another FortiAnalyzer.

Discussion 0
Questions 3

What are offline logs on FortiAnalyzer?

Options:

A.  

Compressed logs, which are also known as archive logs, are considered to be offline logs.

B.  

When you restart FortiAnalyzer. all stored logs are considered to be offline logs.

C.  

Logs that are indexed and stored in the SQL database.

D.  

Logs that are collected from offline devices after they boot up.

Discussion 0
Questions 4

An administrator fortinet, is able to view logs and perform device management tasks, such as adding and removing registered devices. However, administrator fortinet is not able to create a mall server that can be used to send email.

What could be the problem?

Options:

A.  

Fortinet is assigned the Standard_ User administrator profile.

B.  

A trusted host is configured.

C.  

ADOM mode is configured with Advanced mode.

D.  

Fortinet is assigned the Restricted_ User administrator profile.

Discussion 0
Questions 5

Which tabs do not appear when FortiAnalyzer is operating in Collector mode?

Options:

A.  

FortiView

B.  

Event Management

C.  

Device Manger

D.  

Reporting

Discussion 0
Questions 6

Which two of the following must you configure on FortiAnalyzer to email a FortiAnalyzer report externally?

(Choose two.)

Options:

A.  

Mail server

B.  

Output profile

C.  

SFTP server

D.  

Report scheduling

Discussion 0
Questions 7

FortiAnalyzer uses the Optimized Fabric Transfer Protocok (OFTP) over SSL for what purpose?

Options:

A.  

To upload logs to an SFTP server

B.  

To prevent log modification during backup

C.  

To send an identical set of logs to a second logging server

D.  

To encrypt log communication between devices

Discussion 0
Questions 8

For which two purposes would you use the commandset log checksum? (Choose two.)

Options:

A.  

To help protect against man-in-the-middle attacks during log upload from FortiAnalyzer to an SFTP server

B.  

To prevent log modification or tampering

C.  

To encrypt log communications

D.  

To send an identical set of logs to a second logging server

Discussion 0
Questions 9

What statements are true regarding the "store and upload" log transfer option between FortiAnalyzer and FortiGate? (Choose three.)

Options:

A.  

All FortiGates can send logs to FortiAnalyzer using the store and upload option.

B.  

Only FortiGate models with hard disks can send logs to FortiAnalyzer using the store and upload option.

C.  

Both secure communications methods (SSL and IPsec) allow the store and upload option.

D.  

Disk logging is enabled on the FortiGate through the CLI only.

E.  

Disk logging is enabled by default on the FortiGate.

Discussion 0
Questions 10

Refer to the exhibit.

Which image corresponds to the packet capture shown in the exhibit?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 11

Why should you use an NTP server on FortiAnalyzer and all registered devices that log into FortiAnalyzer?

Options:

A.  

To properly correlate logs

B.  

To use real-time forwarding

C.  

To resolve host names

D.  

To improve DNS response times

Discussion 0
Questions 12

Logs are being deleted from one of the ADOMs earlier than the configured setting for archiving in the data

policy.

What is the most likely problem?

Options:

A.  

CPU resources are too high

B.  

Logs in that ADOM are being forwarded, in real-time, to another FortiAnalyzer device

C.  

The total disk space is insufficient and you need to add other disk

D.  

The ADOM disk quota is set too low, based on log rates

Discussion 0
Questions 13

What remote authentication servers can you configure to validate your FortiAnalyzer administrator logons? (Choose three)

Options:

A.  

RADIUS

B.  

Local

C.  

LDAP

D.  

PKI

E.  

TACACS+

Discussion 0
Questions 14

Why must you wait for several minutes before you run a playbook that you just created?

Options:

A.  

FortiAnalyzer needs that time to parse the new playbook.

B.  

FortiAnalyzer needs that time to back up the current playbooks.

C.  

FortiAnalyzer needs that time to ensure there are no other playbooks running.

D.  

FortiAnalyzer needs that time to debug the new playbook.

Discussion 0
Questions 15

What is the purpose of a dataset query in FortiAnalyzer?

Options:

A.  

It sorts log data into tables

B.  

It extracts the database schema

C.  

It retrieves log data from the database

D.  

It injects log data into the database

Discussion 0
Questions 16

What happens when the IOC breach detection engine on FortiAnalyzer finds web logs that match a blocklisted IP address?

Options:

A.  

The endpoint is marked as Compromised and. optionally, can be put in quarantine.

B.  

FortiAnalyzer flags the associated host for further analysis.

C.  

A new Infected entry is added for the corresponding endpoint.

D.  

The detection engine classifies those logs as Suspicious

Discussion 0
Questions 17

What is the best approach to handle a hard disk failure on a FortiAnalyzer that supports hardware RAID?

Options:

A.  

Hot swap the disk.

B.  

There is no need to do anything because the disk will self-recover.

C.  

Run execute format disk to format and restart the FortiAnalyzer device.

D.  

Shut down FortiAnalyzer and replace the disk

Discussion 0
Questions 18

How do you restrict an administrator’s access to a subset of your organization’s ADOMs?

Options:

A.  

Set the ADOM mode toAdvanced

B.  

Assign the ADOMs to the administrator’s account

C.  

Configure trusted hosts

D.  

Assign the defaultSuper_Useradministrator profile

Discussion 0
Questions 19

Which statement about sending notifications with incident updates is true?

Options:

A.  

Notifications can be sent only when an incident is created or deleted.

B.  

You must configure an output profile to send notifications by email.

C.  

Each incident can send notifications to a single external platform.

D.  

Each connector used can have different notification settings.

Discussion 0
Questions 20

Which two methods can you use to send event notifications when an event occurs that matches a configured

event handler? (Choose two.)

Options:

A.  

SMS

B.  

Email

C.  

SNMP

D.  

IM

Discussion 0
Questions 21

By default, what happens when a log file reaches its maximum file size?

Options:

A.  

FortiAnalyzer overwrites the log files.

B.  

FortiAnalyzer stops logging.

C.  

FortiAnalyzer rolls the active log by renaming the file.

D.  

FortiAnalyzer forwards logs to syslog.

Discussion 0
Questions 22

Which two statements are true regarding high availability (HA) on FortiAnalyzer? (Choose two.)

Options:

A.  

FortiAnalyzer HA can function without VRRP. and VRRP is required only if you have more than two FortiAnalyzer devices in a cluster.

B.  

FortiAnalyzer HA supports synchronization of logs as well as some system and configuration settings.

C.  

All devices in a FortiAnalyzer HA cluster must run in the same operation mode: analyzer or collector.

D.  

FortiAnalyzer HA implementation is supported by many public cloud infrastructures such as AWS, Microsoft Azure, and Google Cloud.

Discussion 0
Questions 23

In FortiAnalyzer’s FormView, source and destination IP addresses from FortiGate devices are not resolving to

a hostname. How can you resolve the source and destination IPs, without introducing any additional

performance impact to FortiAnalyzer?

Options:

A.  

Configure local DNS servers on FortiAnalyzer

B.  

Resolve IPs on FortiGate

C.  

Configure # set resolve-ip enable in the system FortiView settings

D.  

Resolve IPs on a per-ADOM basis to reduce delay on FortiView while IPs resolve

Discussion 0
Questions 24

For which two SAML roles can the FortiAnalyzer be configured? (Choose two.)

Options:

A.  

Principal

B.  

Service provider

C.  

Identity collector

D.  

Identity provider

Discussion 0
Questions 25

Which two actions should an administrator take to view Compromised Hosts on FortiAnalyzer? (Choose two.)

Options:

A.  

Enable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent to FortiAnalyzer.

B.  

Make sure all endpoints are reachable by FortiAnalyzer.

C.  

Enable device detection on an interface on the FortiGate devices that are connected to the FortiAnalyzer device.

D.  

Subscribe FortiAnalyzer to FortiGuard to keep its local threat database up to date.

Discussion 0
Questions 26

Which clause is considered mandatory in SELECT statements used by the FortiAnalyzer to generate reports?

Options:

A.  

FROM

B.  

LIMIT

C.  

WHERE

D.  

ORDER BY

Discussion 0
Questions 27

What statements are true regarding disk log quota? (Choose two)

Options:

A.  

The FortiAnalyzer stops logging once the disk log quota is met.

B.  

The FortiAnalyzer automatically sets the disk log quota based on the device.

C.  

The FortiAnalyzer can overwrite the oldest logs or stop logging once the disk log quota is met.

D.  

The FortiAnalyzer disk log quota is configurable, but has a minimum o 100mb a maximum based on the reserved system space.

Discussion 0
Questions 28

What purposes does the auto-cache setting on reports serve? (Choose two.)

Options:

A.  

To reduce report generation time

B.  

To automatically update the hcache when new logs arrive

C.  

To reduce the log insert lag rate

D.  

To provide diagnostics on report generation time

Discussion 0
Questions 29

Which SQL query is in the correct order to query the database in the FortiAnslyzer?

Options:

A.  

SELECT devid FROM Slog GROOP BY devid WHERE * user' =* USERl'

B.  

SELECT devid WHERE 'u3er'='USERl' FROM $ log GROUP BY devid

C.  

SELECT devid FROM Slog- WHERE *user' =' USERl' GROUP BY devid

D.  

FROM Slog WHERE 'user* =' USERl' SELECT devid GROUP BY devid

Discussion 0
Questions 30

Which statement describes online logs on FortiAnalyzer?

Options:

A.  

Logs that reached a specific size and were rolled over

B.  

Logs that can be used to create reports

C.  

Logs that can be viewed using Log Browse

D.  

Logs that are saved to disk, compressed, and available in FortiView

Discussion 0
Questions 31

What is the purpose of output variables?

Options:

A.  

To store playbook execution statistics

B.  

To use the output of the previous task as the input of the current task

C.  

To display details of the connectors used by a playbook

D.  

To save all the task settings when a playbook is exported

Discussion 0
Questions 32

When working with FortiAnalyzer reports, what is the purpose of a dataset?

Options:

A.  

To provide the layout used for reports

B.  

To define the chart type to be used

C.  

To retrieve data from the database

D.  

To set the data included in templates

Discussion 0
Questions 33

What FortiGate process caches logs when FortiAnalyzer is not reachable?

Options:

A.  

logfiled

B.  

sqlplugind

C.  

oftpd

D.  

miglogd

Discussion 0
Questions 34

A play book contains five tasks in total. An administrator executed the playbook and four out of five tasks finished successfully, but one task failed. What will be the status of the playbook after its execution?

Options:

A.  

Success

B.  

Failed

C.  

Running

D.  

Upstream_failed

Discussion 0
Questions 35

Refer to the exhibit.

The exhibit shows “remoteservergroup” is an authentication server group with LDAP and RADIUS servers.

Which two statements express the significance of enabling “Match all users on remote server” when configuring a new administrator? (Choose two.)

Options:

A.  

It creates a wildcard administrator using LDAP and RADIUS servers.

B.  

Administrator can log in to FortiAnalyzer using their credentials on remote servers LDAP and RADIUS.

C.  

Use remoteadmin from LDAP and RADIUS servers will be able to log in to FortiAnalyzer at anytime.

D.  

It allows administrators to use two-factor authentication.

Discussion 0
Questions 36

Which FortiAnalyzer feature allows you to use a proactive approach when managing your network security?

Options:

A.  

Incidents dashboards

B.  

Threat hunting

C.  

FortiView Monitor

D.  

Outbreak alert services

Discussion 0
Questions 37

If the primary FortiAnalyzer in an HA cluster fails, how is the new primary elected?

Options:

A.  

The configured IP address is checked first.

B.  

The active port number is checked first.

C.  

The firmware version is checked first.

D.  

The configured priority is checked first

Discussion 0
Questions 38

Refer to the exhibit.

What does the data point at 14:55 tell you?

Options:

A.  

The received rate is almost at its maximum for this device

B.  

The sqlplugind daemon is behind in log indexing by two logs

C.  

Logs are being dropped

D.  

Raw logs are reaching FortiAnalyzer faster than they can be indexed

Discussion 0
Questions 39

Which two statements are true regarding log fetching on FortiAnalyzer? (Choose two.)

Options:

A.  

A FortiAnalyzer device can perform either the fetch server or client role, and it can perform two roles at the same time with the same FortiAnalyzer devices at the other end.

B.  

Log fetching can be done only on two FortiAnalyzer devices that are running the same firmware version.

C.  

Log fetching allows the administrator to fetch analytics logs from another FortiAnalyzer for redundancy.

D.  

Log fetching allows the administrator to run queries and reports against historical data by retrieving archived logs from one FortiAnalyzer device and sending them to another FortiAnalyzer device.

Discussion 0
Questions 40

If you upgrade your FortiAnalyzer firmware, what report elements can be affected?

Options:

A.  

Output profiles

B.  

Report settings

C.  

Report scheduling

D.  

Custom datasets

Discussion 0
Questions 41

What are two benefits of using fabric connectors? (Choose two.)

Options:

A.  

They allow FortiAnalyzer to send logs in real-time to public cloud accounts.

B.  

You do not need an additional license to send logs to the cloud platform.

C.  

Fabric connectors allow you to improve redundancy.

D.  

Using fabric connectors is more efficient than using third-party polling with API.

Discussion 0