Weekend Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dumps65

Fortinet FCP_FAZ_AN-7.4 Dumps

FCP - FortiAnalyzer 7.4 Analyst Questions and Answers

Question 1

Exhibit.

as

A fortiAnalyzer analyst is customizing a SQL query to use in a report.

Which SQL query should the analyst run to get the expected results?

A)

as

B)

as

C)

as

D)

as

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 2

After a generated a repot, you notice the information you were expecting to see in not included in it. However, you confirm that the logs are there:

Which two actions should you perform? (Choose two.)

Options:

A.

Check the time frame covered by the report.

B.

Disable auto-cache.

C.

Increase the report utilization quota.

D.

Test the dataset.

Question 3

As part of your analysis, you discover that a Medium severity level incident is fully remediated.

You change the incident status to Closed:Remediated.

Which statement about your update is true?

Options:

A.

The incident can no longer be deleted.

B.

The corresponding event will be marked as Mitigated.

C.

The incident dashboard will be updated.

D.

The incident severity will be lowered.

Question 4

Which two statements about local logs on FortiAnalyzer are true? (Choose two.)

Options:

A.

They are not supported in FortiView.

B.

You can view playbook logs for all ADOMs in the root ADOM.

C.

Event logs show system-wide information, whereas application logs are ADOM specific.

D.

Event logs are available only in the root ADOM.

Question 5

Which statement about the FortiSOAR management extension is correct?

Options:

A.

It requires a FortiManager configured to manage FortiGate.

B.

It runs as a docker container on FortiAnalyzer.

C.

It requires a dedicated FortiSOAR device or VM.

D.

It does not include a limited trial by default.

Question 6

Which statement about exporting items in Report Definitions is true?

Options:

A.

Templates can be exported.

B.

Template exports contain associated charts and datasets.

C.

Chart exports contain associated datasets.

D.

Datasets can be exported.

Question 7

You created a playbook on FortiAnalyzer that uses a FortiOS connector.

When configuring the FortiGate side, which type of trigger must be used so that the actions in an automation stich are available in the FortiOS connector?

Options:

A.

FortiAnalyzer Event Handler

B.

Fabric Connector event

C.

FortiOS Event Log

D.

Incoming webhook

Question 8

Exhibit.

as

What can you conclude from this output?

Options:

A.

There is not disk quota allocated to quarantining files.

B.

FGT_B is the Security Fabric root.

C.

The allocated disk quote to ADOM1 is 3 GB.

D.

Archive logs are using more space than analytic logs.

Question 9

Why must you wait for several minutes before you run a playbook that you just created?

Options:

A.

FortiAnalyzer needs that time to parse the new playbook.

B.

FortiAnalyzer needs that time to debug the new playbook.

C.

FortiAnalyzer needs that time to back up the current playbooks.

D.

FortiAnalyzer needs that time to ensure there are no other playbooks running.

Question 10

Which statement correctly describes one Difference between templates and reports?

Options:

A.

Reports provide mora configuration options than templates

B.

Templates can be cloned, but reports cannot be cloned.

C.

Reports support macros, but templates do not.

D.

Template are mapped to device groups. while reports are mapped to ADOMs

Question 11

Which two statements about playbook execution are true? (Choose two)

Options:

A.

FortiAnalyzer will not commit changes made by a Failed playbook

B.

The Playbook Monitor provides troubleshooting logs

C.

You can run the default debugging playbook to investigate playbook errors.

D.

Even I the playbook status is Failed, individual tasks may have succeeded.

Question 12

Exhibit.

as

What can you conclude about these search results? (Choose two.)

Options:

A.

They can be downloaded to a file.

B.

They are sortable by columns and customizable.

C.

They are not available for analysis in FortiView.

D.

They were searched by using text mode.

Question 13

You are tasked with finding logs corresponding to a suspected attack on your network.

You need to use an interface where all identified threats within timeframe are listed and organized. You also need to be able to quickly export the information to a PDF file.

Where can you go to accomplish this task?

Options:

A.

Log Browse

B.

Log View

C.

Fabric View

D.

FortiView

Question 14

What happens when the indicator of compromise (IOC) engine on FortiAnalyzer finds web logs that match blacklisted IP addresses?

Options:

A.

FortiAnalyzer flags the associated host for further analysis.

B.

A new infected entry is added for the corresponding endpoint under Compromised Hosts.

C.

The detection engine classifies those logs as Suspicious.

D.

The endpoint is marked as Compromised and, optionally, can be put in quarantine.

Question 15

After generating a report, you notice the information you where expecting to see is not included in it. However, you confirm that the logs are there.

Options:

A.

Check the time frame covered by the report.

B.

Disable auto-cache.

C.

Increase the report utilization quota.

D.

Test the dataset

Question 16

Exhibit.

as

What is the analyst trying to create?

Options:

A.

The analyst is trying to create a trigger variable to the used in the playbook.

B.

The analyst is trying to create an output variable to be used in the playbook.

C.

The analyst is trying to create a report in the playbook.

D.

The analyst is trying to create a SOC report in the playbook.

Page: 1 / 6
Total 56 questions