Fortinet NSE 5 - FortiAnalyzer 7.6 Analyst Questions and Answers
(Refer to the exhibit.

Which statement about the displayed event is correct? (Choose one answer)
Which statement about sending notifications with incident update is true?
You are tasked with finding logs corresponding to a suspected attack on your network.
You need to use an interface where all identified threats within a timeframe are listed and organized. You also need to be able to quickly export the information to a PDF file.
Where can you go to accomplish this task?
What are the two methods you can use to send notifications when an event is generated by an event handler? (Choose two answers)
Which log will generate an event with the status Contained?
Exhibit.

What can you conclude about the output?
Refer to the exhibit.

What conclusion can you draw from the exhibit?
As part of your analysis, you discover that a Medium severity level incident is fully remediated.
You change the incident status to Closed:Remediated.
Which statement about your update is true?
Exhibit.

Which statement about the event displayed is correct?
When managing incidents on FortiAnalyzer, what must an analyst be aware of?
(When there are no matching parsers for a device log, what does FortiAnalyzer do? (Choose one answer)
You find that as part of your role as an analyst, you frequently search log View using the same parameters.
Instead of defining your search filters repeatedly, what can you do to save time?
Refer to the exhibit.

What can you conclude about the output?
What is the purpose of playbook trigger variables?
Which log will generate an event with the status Unhandled?
A playbook contains five tasks in total. An administrator runs the playbook and four out of five tasks finish successfully, but one task fails.
What will be the status of the playbook after it is run?
You created a playbook on FortiAnalyzer that uses a FortiOS connector.
When configuring the FortiGate side, which type of trigger must be used so that the actions in an automation stitch are available in the FortiOS connector?
Which two statements about playbook execution are true? (Choose two.)
Why must you wait for several minutes before you run a playbook that you just created?
(Refer to the exhibit.

Which statement about the displayed event is correct? (Choose one answer)
Refer to Exhibit:

Client-1 is trying to access the internet for web browsing.
All FortiGate devices in the topology are part of a Security Fabric with logging to FortiAnalyzer configured. All firewall policies have logging enabled. All web filter profiles are configured to log only violations.
Which statement about the logging behavior for this specific traffic flow is true?
Which statement correctly describes one Difference between templates and reports?
Which statement about the FortiSOAR management extension is correct?