Summer Special Discount 60% Offer - Ends in 0d 00h 00m 00s - Coupon code: brite60

ExamsBrite Dumps

Fortinet NSE 5 - FortiAnalyzer 7.2 Question and Answers

Fortinet NSE 5 - FortiAnalyzer 7.2

Last Update Sep 22, 2025
Total Questions : 137

We are offering FREE NSE5_FAZ-7.2 Fortinet exam questions. All you do is to just go and sign up. Give your details, prepare NSE5_FAZ-7.2 free exam questions and then go for complete pool of Fortinet NSE 5 - FortiAnalyzer 7.2 test questions that will help you more.

NSE5_FAZ-7.2 pdf

NSE5_FAZ-7.2 PDF

$42  $104.99
NSE5_FAZ-7.2 Engine

NSE5_FAZ-7.2 Testing Engine

$50  $124.99
NSE5_FAZ-7.2 PDF + Engine

NSE5_FAZ-7.2 PDF + Testing Engine

$66  $164.99
Questions 1

What must you consider when using log fetching? (Choose two.)

Options:

A.  

The fetch client can retrieve logs from devices that are not added to its local Device Manager

B.  

You can use filters to include only logs from a single device.

C.  

The fetching profile must include a user with the Super_User profile.

D.  

The archive logs retrieved from the server become archive logs in the client.

Discussion 0
Questions 2

A rogue administrator was accessing FortiAnalyzer without permission, and you are tasked to see what activity was performed by that rogue administrator on FortiAnalyzer.

What can you do on FortiAnalyzer to accomplish this?

Options:

A.  

Click FortiView and generate a report for that administrator.

B.  

Click Task Monitor and view the tasks performed by that administrator.

C.  

Click Log View and generate a report for that administrator.

D.  

View the tasks performed by the rogue administrator in Fabric View.

Discussion 0
Questions 3

FortiAnalyzer reports are dropping analytical data from 15 days ago, even though the data policy setting for

analytics logs is 60 days.

What is the most likely problem?

Options:

A.  

Quota enforcement is acting on analytical data before a report is complete

B.  

Logs are rolling before the report is run

C.  

CPU resources are too high

D.  

Disk utilization for archive logs is set for 15 days

Discussion 0
Questions 4

What happens when a log file saved on FortiAnalyzer disks reaches the size specified in the device log

settings?

Options:

A.  

The log file is stored as a raw log and is available for analytic support.

B.  

The log file rolls over and is archived.

C.  

The log file is purged from the database.

D.  

The log file is overwritten.

Discussion 0
Questions 5

Which tabs do not appear when FortiAnalyzer is operating in Collector mode?

Options:

A.  

FortiView

B.  

Event Management

C.  

Device Manger

D.  

Reporting

Discussion 0
Questions 6

When working with FortiAnalyzer reports, what is the purpose of a dataset?

Options:

A.  

To provide the layout used for reports

B.  

To define the chart type to be used

C.  

To retrieve data from the database

D.  

To set the data included in templates

Discussion 0
Questions 7

An administrator has moved FortiGate A from the root ADOM to ADOM1.

Which two statements are true regarding logs? (Choose two.)

Options:

A.  

Analytics logs will be moved to ADOM1 from the root ADOM automatically.

B.  

Archived logs will be moved to ADOM1 from the root ADOM automatically.

C.  

Logs will be presented in both ADOMs immediately after the move.

D.  

Analytics logs will be moved to ADOM1 from the root ADOM after you rebuild the ADOM1 SQL database.

Discussion 0
Questions 8

Which SQL query is in the correct order to query the database in the FortiAnslyzer?

Options:

A.  

SELECT devid FROM Slog GROOP BY devid WHERE * user' =* USERl'

B.  

SELECT devid WHERE 'u3er'='USERl' FROM $ log GROUP BY devid

C.  

SELECT devid FROM Slog- WHERE *user' =' USERl' GROUP BY devid

D.  

FROM Slog WHERE 'user* =' USERl' SELECT devid GROUP BY devid

Discussion 0
Questions 9

How does FortiAnalyzer retrieve specific log data from the database?

Options:

A.  

SQL FROM statement

B.  

SQL GET statement

C.  

SQL SELECT statement

D.  

SQL EXTRACT statement

Discussion 0
Questions 10

Logs are being deleted from one of your ADOMs earlier that the configured setting for archiving in your data policy. What is the most likely problem?

Options:

A.  

The total disk space is insufficient and you need to add other disk.

B.  

CPU resources are too high.

C.  

The ADOM disk quota is set too low based on log rates.

D.  

Logs in that ADOM are being forwarded in real-time to another FortiAnalyzer device.

Discussion 0
Questions 11

If the primary FortiAnalyzer in an HA cluster fails, how is the new primary elected?

Options:

A.  

The configured IP address is checked first.

B.  

The active port number is checked first.

C.  

The firmware version is checked first.

D.  

The configured priority is checked first

Discussion 0
Questions 12

What statements are true regarding the "store and upload" log transfer option between FortiAnalyzer and FortiGate? (Choose three.)

Options:

A.  

All FortiGates can send logs to FortiAnalyzer using the store and upload option.

B.  

Only FortiGate models with hard disks can send logs to FortiAnalyzer using the store and upload option.

C.  

Both secure communications methods (SSL and IPsec) allow the store and upload option.

D.  

Disk logging is enabled on the FortiGate through the CLI only.

E.  

Disk logging is enabled by default on the FortiGate.

Discussion 0
Questions 13

What is the purpose of using prefilters when configuring event handlers?

Options:

A.  

They limit which logs are checked for matches by the other filters.

B.  

They can filter the logs before they are processed by FortiAnalyzer

C.  

They download new filters to be used in event handlers.

D.  

They are common filters applied simultaneously to all event handlers.

Discussion 0
Questions 14

Which two methods are the most common methods to control and restrict administrative access on FortiAnalyzer? (Choose two.)

Options:

A.  

Virtual domains

B.  

Administrative access profiles

C.  

Trusted hosts

D.  

Security Fabric

Discussion 0
Questions 15

An administrator has configured the following settings:

config system fortiview settings

set resolve-ip enable

end

What is the significance of executing this command?

Options:

A.  

Use this command only if the source IP addresses are not resolved on FortiGate.

B.  

It resolves the source and destination IP addresses to a hostname in FortiView on FortiAnalyzer.

C.  

You must configure local DNS servers on FortiGate for this command to resolve IP addresses on Forti Analyzer.

D.  

It resolves the destination IP address to a hostname in FortiView on FortiAnalyzer.

Discussion 0
Questions 16

Refer to the exhibit.

Which image corresponds to the packet capture shown in the exhibit?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 17

View the exhibit.

Why is the total quota less than the total system storage?

Options:

A.  

3.6% of the system storage is already being used.

B.  

Some space is reserved for system use, such as storage of compression files, upload files, and temporary report files

C.  

The oftpd process has not archived the logs yet

D.  

The logfiled process is just estimating the total quota

Discussion 0
Questions 18

You crested a playbook on FortiAnalyzer that uses a FortiOS connector

When configuring the FortiGate side, which type of trigger must be used so that the actions in an automation stitch are available in the FortiOS connector?

Options:

A.  

FortiAnalyzer Event Handler

B.  

Incoming webhook

C.  

FortiOS Event Log

D.  

Fabric Connector event

Discussion 0
Questions 19

Which statements are correct regarding FortiAnalyzer reports? (Choose two)

Options:

A.  

FortiAnalyzer provides the ability to create custom reports.

B.  

FortiAnalyzer glows you to schedule reports to run.

C.  

FortiAnalyzer includes pre-defined reports only.

D.  

FortiAnalyzer allows reporting for FortiGate devices only.

Discussion 0
Questions 20

You’ve moved a registered logging device out of one ADOM and into a new ADOM. What happens when you rebuild the new ADOM database?

Options:

A.  

FortiAnalyzer resets the disk quota of the new ADOM to default.

B.  

FortiAnalyzer migrates archive logs to the new ADOM.

C.  

FortiAnalyzer migrates analytics logs to the new ADOM.

D.  

FortiAnalyzer removes logs from the old ADOM.

Discussion 0
Questions 21

Refer to the exhibit.

What is the purpose of using the Chart Builder feature on FortiAnalyzer?

Options:

A.  

In Log View, this feature allows you to build a dataset and chart automatically, based on the filtered search results.

B.  

In Log View, this feature allows you to build a chart and chart automatically, on the top 100 log entries.

C.  

This feature allows you to build a chart under FortiView.

D.  

You can add charts to generated reports using this feature.

Discussion 0
Questions 22

If a hard disk fails on a FortiAnalyzer that supports software RAID, what should you do to bring the

FortiAnalyzer back to functioning normally, without losing data?

Options:

A.  

Hot swap the disk

B.  

Replace the disk and rebuild the RAID manually

C.  

Take no action if the RAID level supports a failed disk

D.  

Shut down FortiAnalyzer and replace the disk

Discussion 0
Questions 23

Which item must you configure on FortiAnalyzer to email generated reports automatically?

Output profile

Report scheduling

SFTP server

SNMP server

Options:

Discussion 0
Questions 24

What statements are true regarding disk log quota? (Choose two)

Options:

A.  

The FortiAnalyzer stops logging once the disk log quota is met.

B.  

The FortiAnalyzer automatically sets the disk log quota based on the device.

C.  

The FortiAnalyzer can overwrite the oldest logs or stop logging once the disk log quota is met.

D.  

The FortiAnalyzer disk log quota is configurable, but has a minimum o 100mb a maximum based on the reserved system space.

Discussion 0
Questions 25

Which statements are true regarding securing communications between FortiAnalyzer and FortiGate with SSL? (Choose two.)

Options:

A.  

SSL is the default setting.

B.  

SSL communications are auto-negotiated between the two devices.

C.  

SSL can send logs in real-time only.

D.  

SSL encryption levels are globally set on FortiAnalyzer.

E.  

FortiAnalyzer encryption level must be equal to, or higher than, FortiGate.

Discussion 0
Questions 26

Refer to the exhibit.

Based on the partial outputs displayed, which devices can be members of a FortiAnalyzer Fabric?

Options:

A.  

FortiAnalyzerl and FortiAnalyzer3

B.  

FortiAnalyzer1 and FortiAnalyzer2

C.  

All devices listed can be members

D.  

FortiAnalyzer2 and FortiAnalyzer3

Discussion 0
Questions 27

Which two statements are true regarding log fetching on FortiAnalyzer? (Choose two.)

Options:

A.  

A FortiAnalyzer device can perform either the fetch server or client role, and it can perform two roles at the same time with the same FortiAnalyzer devices at the other end.

B.  

Log fetching can be done only on two FortiAnalyzer devices that are running the same firmware version.

C.  

Log fetching allows the administrator to fetch analytics logs from another FortiAnalyzer for redundancy.

D.  

Log fetching allows the administrator to run queries and reports against historical data by retrieving archived logs from one FortiAnalyzer device and sending them to another FortiAnalyzer device.

Discussion 0
Questions 28

Which statement about the FortiSIEM management extension is correct?

Options:

A.  

Allows you to manage the entire life cycle of a threat or breach.

B.  

Its use of the available disk space is capped at 50%.

C.  

It requires a licensed FortiSIEM supervisor.

D.  

It can be installed as a dedicated VM.

Discussion 0
Questions 29

If you upgrade the FortiAnalyzer firmware, which report element can be affected?

Options:

A.  

Custom datasets

B.  

Report scheduling

C.  

Report settings

D.  

Output profiles

Discussion 0
Questions 30

Which two statements are true regarding FortiAnalyzer log forwarding? (Choose two.)

Options:

A.  

Both modes, forwarding and aggregation, support encryption of logs between devices.

B.  

In aggregation mode, you can forward logs to syslog and CEF servers as well.

C.  

Aggregation mode stores logs and content files and uploads them to another FortiAnalyzer device at a scheduled time.

D.  

Forwarding mode forwards logs in real time only to other FortiAnalyzer devices.

Discussion 0
Questions 31

Which two statements are true regarding fabric connectors? (Choose two.)

Options:

A.  

Configuring fabric connectors to send notification to ITSM platform upon incident creation Is more efficient than third-party information from the FortiAnalyzer API.

B.  

Fabric connectors allow to save storage costs and improve redundancy.

C.  

Storage connector service does not require a separate license to send logs to cloud platform.

D.  

Cloud-Out connections allow you to send real-time logs to pubic cloud accounts like Amazon S3, Azure Blob , and Google Cloud.

Discussion 0
Questions 32

What are two of the key features of FortiAnalyzer? (Choose two.)

Options:

A.  

Centralized log repository

B.  

Cloud-based management

C.  

Reports

D.  

Virtual domains (VDOMs)

Discussion 0
Questions 33

Which statements are true of Administrative Domains (ADOMs) in FortiAnalyzer? (Choose two.)

Options:

A.  

ADOMs are enabled by default.

B.  

ADOMs constrain other administrator’s access privileges to a subset of devices in the device list.

C.  

Once enabled, the Device Manager, FortiView, Event Management, and Reports tab display per ADOM.

D.  

All administrators can create ADOMs--not just the admin administrator.

Discussion 0
Questions 34

What FortiGate process caches logs when FortiAnalyzer is not reachable?

Options:

A.  

logfiled

B.  

sqlplugind

C.  

oftpd

D.  

miglogd

Discussion 0
Questions 35

What is the best approach to handle a hard disk failure on a FortiAnalyzer that supports hardware RAID?

Options:

A.  

Hot swap the disk.

B.  

There is no need to do anything because the disk will self-recover.

C.  

Run execute format disk to format and restart the FortiAnalyzer device.

D.  

Shut down FortiAnalyzer and replace the disk

Discussion 0
Questions 36

You need to upgrade your FortiAnalyzer firmware.

What happens to the logs being sent to FortiAnalyzer from FortiGate during the time FortiAnalyzer is

temporarily unavailable?

Options:

A.  

FortiAnalyzer uses log fetching to retrieve the logs when back online

B.  

FortiGate uses the miglogd process to cache the logs

C.  

The logfiled process stores logs in offline mode

D.  

Logs are dropped

Discussion 0
Questions 37

Which two statements about log forwarding are true? (Choose two.)

Options:

A.  

Forwarded logs cannot be filtered to match specific criteria.

B.  

Logs are forwarded in real-time only.

C.  

The client retains a local copy of the logs after forwarding.

D.  

You can use aggregation mode only with another FortiAnalyzer.

Discussion 0
Questions 38

Logs are being deleted from one of the ADOMs earlier than the configured setting for archiving in the data

policy.

What is the most likely problem?

Options:

A.  

CPU resources are too high

B.  

Logs in that ADOM are being forwarded, in real-time, to another FortiAnalyzer device

C.  

The total disk space is insufficient and you need to add other disk

D.  

The ADOM disk quota is set too low, based on log rates

Discussion 0
Questions 39

Which daemon is responsible for enforcing the log file size?

Options:

A.  

sqlplugind

B.  

logfiled

C.  

miglogd

D.  

ofrpd

Discussion 0
Questions 40

You are using RAID with a FortiAnalyzer that supports software RAID, and one of the hard disks on

FortiAnalyzer has failed.

What is the recommended method to replace the disk?

Options:

A.  

Shut down FortiAnalyzer and then replace the disk

B.  

Downgrade your RAID level, replace the disk, and then upgrade your RAID level

C.  

Clear all RAID alarms and replace the disk while FortiAnalyzer is still running

D.  

Perform a hot swap

Discussion 0
Questions 41

Which two statements are true regarding ADOM modes? (Choose two.)

Options:

A.  

You can only change ADOM modes through CLI.

B.  

In normal mode, the disk quota of the ADOM is fixed and cannot be modified, but in advance mode, the disk quota of the ADOM is flexible because new devices are added to the ADOM.

C.  

In an advanced mode ADOM. you can assign FortiGate VDOMs from a single FortiGate device to multiple FortiAnalyzer ADOMs.

D.  

Normal mode is the default ADOM mode.

Discussion 0