Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: myex65

Home > Fortinet > Security Operations > FCP_FAZ_AN-7.4

FCP_FAZ_AN-7.4 FCP - FortiAnalyzer 7.4 Analyst Question and Answers

Question # 4

Which statement about the FortiSOAR management extension is correct?

A.

It requires a FortiManager configured to manage FortiGate.

B.

It runs as a docker container on FortiAnalyzer.

C.

It requires a dedicated FortiSOAR device or VM.

D.

It does not include a limited trial by default.

Full Access
Question # 5

Which two statements regarding FortiAnalyzer operating modes are true? (Choose two.)

A.

When running in collector mode, FortiAnalyzer can forward logs to a syslog server.

B.

FortiAnalyzer runs in collector mode by default unless it is configured for HA.

C.

You can create and edit reports when FortiAnalyzer is running in collector mode.

D.

A topology with FortiAnalyzeer devices running in both modes can improve their performance.

Full Access
Question # 6

Which FortiAnalyzer feature allows you to use a proactive approach when managing your network security?

A.

FortiView Monitor

B.

Outbreak alert services

C.

Incidents dashboard

D.

Threat hunting

Full Access
Question # 7

Which statement about the FortiSIEM management extension is correct?

A.

It allows you to manage the entire life cycle of a threat or breach.

B.

It can be installed as a dedicated VM.

C.

Its use of the available disk space is capped at 50%.

D.

It requires a licensed FortiSIEM supervisor.

Full Access
Question # 8

You discover that a few reports are taking a long tine lo generate. Which two steps can you Like to troubleshoot? (Choose two.)

A.

Remove old reports from the hcache

B.

Enable auto-cache and run the reports again

C.

Increase the ADOM reports quota

D.

Review report diagnostics

Full Access
Question # 9

As part of your analysis, you discover that a Medium severity level incident is fully remediated.

You change the incident status to Closed:Remediated.

Which statement about your update is true?

A.

The incident can no longer be deleted.

B.

The corresponding event will be marked as Mitigated.

C.

The incident dashboard will be updated.

D.

The incident severity will be lowered.

Full Access
Question # 10

Exhibit.

Assume these are all the events that exist on the FortiAnalyzer device.

How many events will be added to the incident created after running this playbook?

A.

Eleven events will be added.

B.

Seven events will be added

C.

No events will be added.

D.

Four events will be added.

Full Access
Question # 11

Which log will generate an event with the status Unhandled?

A.

An AV log with action=quarantine.

B.

An IPS log with action=pass.

C.

A WebFilter log will action=dropped.

D.

An AppControl log with action=blocked.

Full Access
Question # 12

Which two methods can you use to send notifications when an event occurs that matches a configured event handler? (Choose two.)

A.

Send Alert through Fabric Connectors

B.

Send SNMP trap

C.

Send SMS notification

D.

Send Alert through FortiSIEM MEA

Full Access
Question # 13

Refer to Exhibit:

What does the data point at 21:20 indicate?

A.

FortiAnalyzer is indexing logs faster than logs are being received.

B.

The fortilogd daemon is ahead in indexing by one log.

C.

The SQL database requires a rebuild because of high receive lag.

D.

FortiAnalyzer is temporarily buffering received logs so older logs can be indexed first.

Full Access
Question # 14

A playbook contains five tasks in total. An administrator runs the playbook and four out of five tasks finish successfully, but one task fails.

What will be the status of the playbook after it is run?

A.

Attention required

B.

Upstream_failed

C.

Failed

D.

Success

Full Access
Question # 15

Exhibit.

A fortiAnalyzer analyst is customizing a SQL query to use in a report.

Which SQL query should the analyst run to get the expected results?

A)

B)

C)

D)

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 16

Exhibit.

What is the purpose of using the Chart Builder feature On FortiAnalyzer?

A.

To build a chart automatically based on the top 100 log entries

B.

To add charts directly to generate reports in the current ADOM.

C.

To add a new chart under FortiView to be used in new reports

D.

To build a dataset and chart based on the filtered search results

Full Access