Special Summer Sale - 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dm70dm

FCP_FAZ_AD-7.4 FCP - FortiAnalyzer 7.4 Administrator Questions and Answers

Questions 4

Which two statements are true regarding FortiAnalyzer operating modes? (Choose two.)

Options:

A.

When in collector mode, FortiAnalyzer collects logs from multiple devices and forwards these logs in the original binary format.

B.

Collector mode is the default operating mode.

C.

When in collector mode. FortiAnalyzer supports event management and reporting features.

D.

By deploying different FortiAnalyzer devices with collector and analyzer mode in a network, you can improve the overall performance of log receiving, analysis, and reporting

Buy Now
Questions 5

Refer to the exhibit, which shows the HA configuration settings of a FortiAnalyzer device.

FCP_FAZ_AD-7.4 Question 5

The administrator wants to join this FortiAnalyzer to an existing HA cluster. What can you conclude from the configuration displayed?

Options:

A.

After joining the cluster, this FortiAnalyzer will forward received logs to its peers.

B.

This FortiAnalyzer will trigger a failover after losing communication with its peers for 10 seconds.

C.

This FortiAnalyzer is configured to route HA traffic through a gateway.

D.

This FortiAnalyzer will join the existing HA cluster as the secondary.

Buy Now
Questions 6

A playbook contains five tasks in total. An administrator runs the playbook and four out of five tasks finish successfully, but one task fails. What will be the status of the playbook after it is run?

Options:

A.

Running

B.

Failed

C.

Upstream_failed

D.

Success

Buy Now
Questions 7

What statements are true regarding disk log quota? (Choose two)

Options:

A.

The FortiAnalyzer stops logging once the disk log quota is met.

B.

The FortiAnalyzer automatically sets the disk log quota based on the device.

C.

The FortiAnalyzer can overwrite the oldest logs or stop logging once the disk log quota is met.

D.

The FortiAnalyzer disk log quota is configurable, but has a minimum o 100mb a maximum based on the reserved system space.

Buy Now
Questions 8

What are two advantages of setting up fabric ADOM? (Choose two.)

Options:

A.

It can be used for fast data processing and log correlation

B.

It can be used to facilitate communication between devices in same Security Fabric

C.

It can include all Fortinet devices that are part of the same Security Fabric

D.

It can include only FortiGate devices that are part of the same Security Fabric

Buy Now
Questions 9

Which two methods are the most common methods to control and restrict administrative access on FortiAnalyzer? (Choose two.)

Options:

A.

Virtual domains

B.

Administrative access profiles

C.

Trusted hosts

D.

Security Fabric

Buy Now
Questions 10

After you have moved a registered logging device out of one ADOM and into a new ADOM, what is the

purpose of running the following CLI command?

execute sql-local rebuild-adom

Options:

A.

To reset the disk quota enforcement to default

B.

To remove the analytics logs of the device from the old database

C.

To migrate the archive logs to the new ADOM

D.

To populate the new ADOM with analytical logs for the moved device, so you can run reports

Buy Now
Questions 11

On FortiAnalyzer, what is a wildcard administrator account?

Options:

A.

An account that permits access to members of an LDAP group

B.

An account that allows guest access with read-only privileges

C.

An account that requires two-factor authentication

D.

An account that validates against any user account on a FortiAuthenticator

Buy Now
Questions 12

For which two purposes would you use the command set log checksum? (Choose two.)

Options:

A.

To help protect against man-in-the-middle attacks during log upload from FortiAnalyzer to an SFTP server

B.

To prevent log modification or tampering

C.

To encrypt log communications

D.

To send an identical set of logs to a second logging server

Buy Now
Questions 13

Which two constraints can impact the amount of reserved disk space required by FortiAnalyzer? (Choose

two.)

Options:

A.

License type

B.

Disk size

C.

Total quota

D.

RAID level

Buy Now
Questions 14

Which two methods can you use to restrict administrative access on FortiAnalyzer? (Choose two.)

Options:

A.

Configure trusted hosts.

B.

Limit access to specific virtual domains.

C.

Fabric connectors to external LDAP servers.

D.

Use administrator profiles.

Buy Now
Questions 15

Which statement when you are upgrading the firmware on an HA cluster made up of three FortiAnalyzer devices is true?

Options:

A.

You can perform the firmware upgrade using only a console connection.

B.

All FortiAnalyzer devices will be upgraded at the same time.

C.

Enabling uninterruptible-upgrade prevents normal operations from being interrupted during the upgrade.

D.

First, upgrade the secondary devices, and then upgrade the primary device.

Buy Now
Questions 16

How does FortiAnalyzer retrieve specific log data from the database?

Options:

A.

SQL FROM statement

B.

SQL GET statement

C.

SQL SELECT statement

D.

SQL EXTRACT statement

Buy Now
Questions 17

For which two SAML roles can the FortiAnalyzer be configured? (Choose two.)

Options:

A.

Principal

B.

Service provider

C.

Identity collector

D.

Identity provider

Buy Now
Questions 18

If the primary FortiAnalyzer in an HA cluster fails, how is the new primary elected?

Options:

A.

The configured IP address is checked first.

B.

The active port number is checked first.

C.

The firmware version is checked first.

D.

The configured priority is checked first

Buy Now
Questions 19

Refer to the exhibit.

FCP_FAZ_AD-7.4 Question 19

The exhibit shows the creation of a new administrator on FortiAnalyzer. The new account uses the credentials stored on an LDAP server.

Why would an administrator configure a password for this account?

Options:

A.

This password is used if the authentication server becomes unreachable.

B.

This password authenticates FortiAnalyzer aqainst the LDAP server.

C.

This password is set to comply with FortiAnalvzer password policy

D.

This password is required because this is a restricted user.

Buy Now
Questions 20

Which two of the following must you configure on FortiAnalyzer to email a FortiAnalyzer report externally?

(Choose two.)

Options:

A.

Mail server

B.

Output profile

C.

SFTP server

D.

Report scheduling

Buy Now
Questions 21

Which two statement are true regardless initial Logs sync and Log Data Sync for Ha on FortiAnalyzer?

Options:

A.

By default, Log Data Sync is disabled on all backup devise.

B.

Log Data Sync provides real-time log synchronization to all backup devices.

C.

With initial Logs Sync, when you add a unit to an HA cluster, the primary device synchronizes its logs with the backup device.

D.

When Logs Data Sync is turned on, the backup device will reboot and then rebuilt the log database with the synchronized logs.

Buy Now
Questions 22

Which two elements are contained in a system backup created on FortiAnalyzer? (Choose two.)

Options:

A.

System information

B.

Logs from registered devices

C.

Report information

D.

Database snapshot

Buy Now
Questions 23

What is the purpose of employing RAID with FortiAnalyzer?

Options:

A.

To introduce redundancy to your log data

B.

To provide data separation between ADOMs

C.

To separate analytical and archive data

D.

To back up your logs

Buy Now
Questions 24

An administrator, fortinet, can view logs and perform device management tasks, such as adding and removing registered devices. However, administrator fortinet is not able to create a mail server that can be used to send alert emails.

What can be the problem?

Options:

A.

ADOM mode is configured with Advanced mode.

B.

A trusted host is configured.

C.

fortinet is assigned the default Standard_User administrative profile.

D.

fortinet is assigned the default Restricted_User administrative profile.

Buy Now
Questions 25

Which statement is true regarding Macros on FortiAnalyzer?

Options:

A.

Macros are ADOM specific and each ADOM will have unique macros relevant to that ADOM.

B.

Macros are supported only on the FortiGate ADOM.

C.

Macros are useful in generating excel log files automatically based on the reports settings.

D.

Macros are predefined templates for reports and cannot be customized.

Buy Now
Questions 26

When you perform a system backup, what does the backup configuration contain? (Choose two.)

Options:

A.

Generated reports

B.

Device list

C.

Authorized devices logs

D.

System information

Buy Now
Questions 27

You need to upgrade your FortiAnalyzer firmware.

What happens to the logs being sent to FortiAnalyzer from FortiGate during the time FortiAnalyzer is

temporarily unavailable?

Options:

A.

FortiAnalyzer uses log fetching to retrieve the logs when back online

B.

FortiGate uses the miglogd process to cache the logs

C.

The logfiled process stores logs in offline mode

D.

Logs are dropped

Buy Now
Questions 28

Which statement about the communication between FortiGate high availability (HA) clusters and FortiAnalyzer is true?

Options:

A.

If devices were registered to FortiAnalyzer before forming a cluster, you can manually add them together.

B.

FortiAnalyzer distinguishes each cluster member by the IP addresses in log message headers.

C.

If the HA primary device becomes unavailable, you must remove it from the HA cluster list on FortiAnalyzer.

D.

The FortiGate HA cluster must be in active-passive mode in order to avoid conflict.

Buy Now
Questions 29

If a hard disk fails on a FortiAnalyzer that supports software RAID, what should you do to bring the

FortiAnalyzer back to functioning normally, without losing data?

Options:

A.

Hot swap the disk

B.

Replace the disk and rebuild the RAID manually

C.

Take no action if the RAID level supports a failed disk

D.

Shut down FortiAnalyzer and replace the disk

Buy Now
Questions 30

Which statement correctly describes the management extensions available on FortiAnalyzer?

Options:

A.

Management extensions do not require additional licenses.

B.

Management extensions allow FortiAnalyzer to act as a ForbSIEM supervisor.

C.

Management extensions require a dedicated VM for best performance.

D.

Management extensions may require a minimum number of CPU cores to run.

Buy Now
Questions 31

An administrator has moved FortiGate A from the root ADOM to ADOM1.

Which two statements are true regarding logs? (Choose two.)

Options:

A.

Analytics logs will be moved to ADOM1 from the root ADOM automatically.

B.

Archived logs will be moved to ADOM1 from the root ADOM automatically.

C.

Logs will be presented in both ADOMs immediately after the move.

D.

Analytics logs will be moved to ADOM1 from the root ADOM after you rebuild the ADOM1 SQL database.

Buy Now
Questions 32

A rogue administrator was accessing FortiAnalyzer without permission, and you are tasked to see what activity was performed by that rogue administrator on FortiAnalyzer.

What can you do on FortiAnalyzer to accomplish this?

Options:

A.

Click FortiView and generate a report for that administrator.

B.

Click Task Monitor and view the tasks performed by that administrator.

C.

Click Log View and generate a report for that administrator.

D.

View the tasks performed by the rogue administrator in Fabric View.

Buy Now
Questions 33

Logs are being deleted from one of the ADOMs earlier than the configured setting for archiving in the data

policy.

What is the most likely problem?

Options:

A.

CPU resources are too high

B.

Logs in that ADOM are being forwarded, in real-time, to another FortiAnalyzer device

C.

The total disk space is insufficient and you need to add other disk

D.

The ADOM disk quota is set too low, based on log rates

Buy Now
Questions 34

You have recently grouped multiple FortiGate devices into a single ADOM. System Settings > Storage Info

shows the quota used.

What does the disk quota refer to?

Options:

A.

The maximum disk utilization for each device in the ADOM

B.

The maximum disk utilization for the FortiAnalyzer model

C.

The maximum disk utilization for the ADOM type

D.

The maximum disk utilization for all devices in the ADOM

Buy Now
Questions 35

Which two statements express the advantages of grouping similar reports? (Choose two.)

Options:

A.

Improve report completion time.

B.

Conserve disk space on FortiAnalyzer by grouping multiple similar reports.

C.

Reduce the number of hcache tables and improve auto-hcache completion time.

D.

Provides a better summary of reports.

Buy Now
Questions 36

Which two statements about FortiAnalyzer operating modes are true? (Choose two.)

Options:

A.

When in collector mode, FortiAnalyzer offloads the log receiving task to the analyzer.

B.

When in analyzer mode, FortiAnalyzer supports event management and reporting features.

C.

For the collector, you should allocate most of the disk space to analytics logs.

D.

Analyzer mode is the default operating mode.

Buy Now
Questions 37

By default, what happens when a log file reaches its maximum file size?

Options:

A.

FortiAnalyzer overwrites the log files.

B.

FortiAnalyzer stops logging.

C.

FortiAnalyzer rolls the active log by renaming the file.

D.

FortiAnalyzer forwards logs to syslog.

Buy Now
Questions 38

What can you do on FortiAnalyzer to restrict administrative access from specific locations?

Options:

A.

Configure trusted hosts for that administrator.

B.

Enable geo-location services on accessible interface.

C.

Configure two-factor authentication with a remote RADIUS server.

D.

Configure an ADOM for respective location.

Buy Now
Questions 39

How do you restrict an administrator’s access to a subset of your organization’s ADOMs?

Options:

A.

Set the ADOM mode to Advanced

B.

Assign the ADOMs to the administrator’s account

C.

Configure trusted hosts

D.

Assign the default Super_User administrator profile

Buy Now
Questions 40

Consider the CLI command:

FCP_FAZ_AD-7.4 Question 40

What is the purpose of the command?

Options:

A.

To add a unique tag to each log to prove that it came from this FortiAnalyzer

B.

To add the MD5 hash value and authentication code

C.

To add a log file checksum

D.

To encrypt log communications

Buy Now
Questions 41

What is Log Insert Lag Time on FortiAnalyzer?

Options:

A.

The number of times in the logs where end users experienced slowness while accessing resources.

B.

The amount of lag time that occurs when the administrator is rebuilding the ADOM database.

C.

The amount of time that passes between the time a log was received and when it was indexed on FortiAnalyzer.

D.

The amount of time FortiAnalyzer takes to receive logs from a registered device

Buy Now
Questions 42

Refer to the exhibit.

FCP_FAZ_AD-7.4 Question 42

Laptop1 is used by several administrators to manage FortiAnalyzer. You want to configure a generic text filter that matches all login attempts to the web interface generated by any user other than "admin", and coming from Laptop1.

Which filter will achieve the desired result?

Options:

A.

operation-login & dstip==10.1.1.210 & user!-admin

B.

operation-login & srcip==10.1.1.100 & dstip==10.1.1.210 & user==admin

C.

operation-login & performed_on=="GUI(10.1.1.210)" & user!=admin

D.

operation-login & performed_on=="GUI(10.1.1.100)" & user!=admin

Buy Now
Questions 43

Refer to the exhibit.

FCP_FAZ_AD-7.4 Question 43

What does the data point at 14:55 tell you?

Options:

A.

The received rate is almost at its maximum for this device

B.

The sqlplugind daemon is behind in log indexing by two logs

C.

Logs are being dropped

D.

Raw logs are reaching FortiAnalyzer faster than they can be indexed

Buy Now
Questions 44

Which clause is considered mandatory in SELECT statements used by the FortiAnalyzer to generate reports?

Options:

A.

FROM

B.

LIMIT

C.

WHERE

D.

ORDER BY

Buy Now
Questions 45

FortiAnalyzer reports are dropping analytical data from 15 days ago, even though the data policy setting for

analytics logs is 60 days.

What is the most likely problem?

Options:

A.

Quota enforcement is acting on analytical data before a report is complete

B.

Logs are rolling before the report is run

C.

CPU resources are too high

D.

Disk utilization for archive logs is set for 15 days

Buy Now
Questions 46

Logs are being deleted from one of your ADOMs earlier that the configured setting for archiving in your data policy. What is the most likely problem?

Options:

A.

The total disk space is insufficient and you need to add other disk.

B.

CPU resources are too high.

C.

The ADOM disk quota is set too low based on log rates.

D.

Logs in that ADOM are being forwarded in real-time to another FortiAnalyzer device.

Buy Now
Questions 47

Which statements are true regarding securing communications between FortiAnalyzer and FortiGate with SSL? (Choose two.)

Options:

A.

SSL is the default setting.

B.

SSL communications are auto-negotiated between the two devices.

C.

SSL can send logs in real-time only.

D.

SSL encryption levels are globally set on FortiAnalyzer.

E.

FortiAnalyzer encryption level must be equal to, or higher than, FortiGate.

Buy Now
Questions 48

An administrator has moved a FortiGate device from the root ADOM to ADOM1.

Which two statements are true regarding logs? (Choose two.)

Options:

A.

Analytics logs will be moved to ADOM1 from the root ADOM automatically.

B.

Archived logs will be moved to ADOM1 from the root ADOM automatically.

C.

Logs will be present in both ADOMs immediately after the move.

D.

Analytics logs will be moved to ADOM1 from the root ADOM after you rebuild the database.

Buy Now
Questions 49

In a Fortinet Security Fabric, what can make an upstream FortiGate create traffic logs associated with sessions initiated on downstream FortiGate devices?

Options:

A.

The traffic destination is another FortiGate in the fabric.

B.

The upstream FortiGate is configured to do NAT

C.

Log redundancy is configured in the fabric.

D.

The downstream device cannot connect to FortiAnalyzer.

Buy Now
Questions 50

What are two of the key features of FortiAnalyzer? (Choose two.)

Options:

A.

Centralized log repository

B.

Cloud-based management

C.

Reports

D.

Virtual domains (VDOMs)

Buy Now
Questions 51

You crested a playbook on FortiAnalyzer that uses a FortiOS connector

When configuring the FortiGate side, which type of trigger must be used so that the actions in an automation stitch are available in the FortiOS connector?

Options:

A.

FortiAnalyzer Event Handler

B.

Incoming webhook

C.

FortiOS Event Log

D.

Fabric Connector event

Buy Now
Questions 52

Which two statements about creating ADOMs are true1? (Choose two.)

Options:

A.

An administrator with the default standard_User profile can create ADOMs.

B.

Disk quotas can be defined per device inside the ADOM.

C.

FortiAnalyzer creates default ADOMs when ADOMs are enabled.

D.

The ADOM type you create must match the device type you are planning to add.

Buy Now
Questions 53

You are trying to initiate an authorization request from FortiGate to FortiAnalyzer, but the Security Fabric window does not open when you click Authorize.

Which two reasons can cause this to happen? (Choose two.)

Options:

A.

A pre-shared key needs to be established on both sides.

B.

The management computer does not have connectivity to the authorization IP address and port combination.

C.

The Security Fabric root is unauthorized and needs to be added as a trusted host.

D.

The fabric authorization settings on FortiAnalyzer are misconfigured.

Buy Now
Exam Code: FCP_FAZ_AD-7.4
Exam Name: FCP - FortiAnalyzer 7.4 Administrator
Last Update: Mar 28, 2025
Questions: 178

PDF + Testing Engine

$49.5  $164.99

Testing Engine

$37.5  $124.99
buy now FCP_FAZ_AD-7.4 testing engine

PDF (Q&A)

$31.5  $104.99
buy now FCP_FAZ_AD-7.4 pdf
dumpsmate guaranteed to pass
24/7 Customer Support

DumpsMate's team of experts is always available to respond your queries on exam preparation. Get professional answers on any topic of the certification syllabus. Our experts will thoroughly satisfy you.

Site Secure

mcafee secure

TESTED 03 Apr 2025