FCP - FortiAnalyzer 7.4 Analyst Questions and Answers
Exhibit.
A fortiAnalyzer analyst is customizing a SQL query to use in a report.
Which SQL query should the analyst run to get the expected results?
A)
B)
C)
D)
After a generated a repot, you notice the information you were expecting to see in not included in it. However, you confirm that the logs are there:
Which two actions should you perform? (Choose two.)
As part of your analysis, you discover that a Medium severity level incident is fully remediated.
You change the incident status to Closed:Remediated.
Which statement about your update is true?
Which two statements about local logs on FortiAnalyzer are true? (Choose two.)
Which statement about the FortiSOAR management extension is correct?
Which statement about exporting items in Report Definitions is true?
You created a playbook on FortiAnalyzer that uses a FortiOS connector.
When configuring the FortiGate side, which type of trigger must be used so that the actions in an automation stich are available in the FortiOS connector?
Exhibit.
What can you conclude from this output?
Why must you wait for several minutes before you run a playbook that you just created?
Which statement correctly describes one Difference between templates and reports?
Which two statements about playbook execution are true? (Choose two)
Exhibit.
What can you conclude about these search results? (Choose two.)
You are tasked with finding logs corresponding to a suspected attack on your network.
You need to use an interface where all identified threats within timeframe are listed and organized. You also need to be able to quickly export the information to a PDF file.
Where can you go to accomplish this task?
What happens when the indicator of compromise (IOC) engine on FortiAnalyzer finds web logs that match blacklisted IP addresses?
After generating a report, you notice the information you where expecting to see is not included in it. However, you confirm that the logs are there.
Exhibit.
What is the analyst trying to create?