FCP - FortiAnalyzer 7.4 Administrator Questions and Answers
What is the purpose of a predefined template on the FortiAnalyzer?
What is the purpose of employing RAID with FortiAnalyzer?
NO: 14
View the exhibit.
Why is the total quota less than the total system storage?
What are analytics logs on FortiAnalyzer?
What is the purpose of output variables?
Which two statements are true regarding FortiAnalyzer log forwarding? (Choose two.)
Which SQL query is in the correct order to query the database in the FortiAnslyzer?
Which two statements express the advantages of grouping similar reports? (Choose two.)
What is the purpose of using prefilters when configuring event handlers?
An administrator has moved a registered logging device out of one ADOM and into a new ADOM.
What is the purpose of running the following command: execute sql-local rebuild-adom
What must you consider when using log fetching? (Choose two.)
You are using RAID with a FortiAnalyzer that supports software RAID, and one of the hard disks on
FortiAnalyzer has failed.
What is the recommended method to replace the disk?
View the exhibit.
What does the data point at 14:35 tell you?
Which two methods can you use to send event notifications when an event occurs that matches a configured
event handler? (Choose two.)
The provided image is a multiple-choice question. The question and options are:
Which two statements are true about FortiAnalyzer log forwarding modes? (Choose two.)
Refer to the exhibit.
The image displays the configuration of a FortiAnalyzer the administrator wants to join to an existing HA cluster.
What can you conclude from the configuration displayed?
In a Fortinet Security Fabric, what can make an upstream FortiGate create traffic logs associated with sessions initiated on downstream FortiGate devices?
By default, what happens when a log file reaches its maximum file size?
What is required to authorize a FortiGate on FortiAnalyzer using Fabric authorization?
Which two statements about creating ADOMs are true1? (Choose two.)
Which statement about the FortiSOAR management extension is correct?
FortiAnalyzer reports are dropping analytical data from 15 days ago, even though the data policy setting for
analytics logs is 60 days.
What is the most likely problem?
Which statement regarding the FortiAnalyzer Fabric is true?
Which three RAID configurations provide fault tolerance on FortiAnalyzer? (Choose three.)
Which statement is true about ADOMs?
Which FortiAnalyzer feature allows you to use a proactive approach when managing your network security?
Refer to the exhibits.
How many events will be added to the incident created after running this playbook?
What statements are true regarding the "store and upload" log transfer option between FortiAnalyzer and FortiGate? (Choose three.)
What are two effects of enabling auto-cache in a FortiAnalyzer report? (Choose two.)
Which log type does the FortiAnalyzer indicators of compromise feature use to identify infected hosts?
Which two of the following must you configure on FortiAnalyzer to email a FortiAnalyzer report externally?
(Choose two.)
Which two statements are true regarding high availability (HA) on FortiAnalyzer? (Choose two.)
Which statements are correct regarding FortiAnalyzer reports? (Choose two)
Which statements are true of Administrative Domains (ADOMs) in FortiAnalyzer? (Choose two.)
Which two methods are the most common methods to control and restrict administrative access on FortiAnalyzer? (Choose two.)
Which two constraints can impact the amount of reserved disk space required by FortiAnalyzer? (Choose
two.)
What is the purpose of the following CLI command?
The admin administrator is failing to register a FortiClient EMS on the FortiAnalyzer device.
What can be the reason for this failure?
Refer to the exhibit.
Based on the output, what can you conclude about the FortiAnalyzer logging status?
An administrator has configured the following settings:
What is the purpose of executing these commands?
Which log will generate an event with the status Contained?
An administrator, fortinet, can view logs and perform device management tasks, such as adding and removing registered devices. However, administrator fortinet is not able to create a mail server that can be used to send alert emails.
What can be the problem?
Which two actions should an administrator take to view Compromised Hosts on FortiAnalyzer? (Choose two.)
What are two advantages of setting up fabric ADOM? (Choose two.)
What are two of the key features of FortiAnalyzer? (Choose two.)
How does FortiAnalyzer retrieve specific log data from the database?
View the exhibit:
What does the 1000MB maximum for disk utilization refer to?
FortiAnalyzer uses the Optimized Fabric Transfer Protocok (OFTP) over SSL for what purpose?
Refer to the exhibit.
Laptopt is used by several administrators to manage FortiAnalyzer. You want to configure a generic text filter that matches all login attempts to the web interface generated by any user other than "admin" and coming from Laptop1:
Which filter will achieve the desired result?
If you upgrade the FortiAnalyzer firmware, which report element can be affected?
When working with FortiAnalyzer reports, what is the purpose of a dataset?
An administrator has configured the following settings:
config system global
set log-checksum md5-auth
end
What is the significance of executing this command?
Refer to the exhibit.
The exhibit shows “remoteservergroup” is an authentication server group with LDAP and RADIUS servers.
Which two statements express the significance of enabling “Match all users on remote server” when configuring a new administrator? (Choose two.)
An administrator has configured the following settings:
config system fortiview settings
set resolve-ip enable
end
What is the significance of executing this command?