Labour Day Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 2493360325

Good News !!! NSE5_FAZ-7.2 Fortinet NSE 5 - FortiAnalyzer 7.2 is now Stable and With Pass Result

NSE5_FAZ-7.2 Practice Exam Questions and Answers

Fortinet NSE 5 - FortiAnalyzer 7.2

Last Update 3 days ago
Total Questions : 137

NSE5_FAZ-7.2 is stable now with all latest exam questions are added 3 days ago. Just download our Full package and start your journey with Fortinet NSE 5 - FortiAnalyzer 7.2 certification. All these Fortinet NSE5_FAZ-7.2 practice exam questions are real and verified by our Experts in the related industry fields.

NSE5_FAZ-7.2 PDF

NSE5_FAZ-7.2 PDF (Printable)
$48
$119.99

NSE5_FAZ-7.2 Testing Engine

NSE5_FAZ-7.2 PDF (Printable)
$56
$139.99

NSE5_FAZ-7.2 PDF + Testing Engine

NSE5_FAZ-7.2 PDF (Printable)
$70.8
$176.99
Question # 1

Refer to the exhibit.

Question # 1

What is the purpose of using the Chart Builder feature on FortiAnalyzer?

Options:

A.  

In Log View, this feature allows you to build a dataset and chart automatically, based on the filtered search results.

B.  

In Log View, this feature allows you to build a chart and chart automatically, on the top 100 log entries.

C.  

This feature allows you to build a chart under FortiView.

D.  

You can add charts to generated reports using this feature.

Discussion 0
Question # 2

In the FortiAnalyzer FortiView, source and destination IP addresses from FortiGate devices arenotresolving to a hostname.

How can you resolve the source and destination IP addresses, without introducing any additional performance impact to FortiAnalyzer?

Options:

A.  

Resolve IP addresses on a per-ADOM basis to reduce delay on FortiView while IPs resolve

B.  

Configure# set resolve-ip enablein the system FortiView settings

C.  

Configure local DNS servers on FortiAnalyzer

D.  

Resolve IP addresses on FortiGate

Discussion 0
Question # 3

Which tabs do not appear when FortiAnalyzer is operating in Collector mode?

Options:

A.  

FortiView

B.  

Event Management

C.  

Device Manger

D.  

Reporting

Discussion 0
Question # 4

Which statement about sending notifications with incident updates is true?

Options:

A.  

Notifications can be sent only when an incident is created or deleted.

B.  

You must configure an output profile to send notifications by email.

C.  

Each incident can send notifications to a single external platform.

D.  

Each connector used can have different notification settings.

Discussion 0
Question # 5

What are offline logs on FortiAnalyzer?

Options:

A.  

Compressed logs, which are also known as archive logs, are considered to be offline logs.

B.  

When you restart FortiAnalyzer. all stored logs are considered to be offline logs.

C.  

Logs that are indexed and stored in the SQL database.

D.  

Logs that are collected from offline devices after they boot up.

Discussion 0
Question # 6

Which two of the following must you configure on FortiAnalyzer to email a FortiAnalyzer report externally?

(Choose two.)

Options:

A.  

Mail server

B.  

Output profile

C.  

SFTP server

D.  

Report scheduling

Discussion 0
Question # 7

A playbook contains five tasks in total. An administrator runs the playbook and four out of five tasks finish successfully, but one task fails. What will be the status of the playbook after it is run?

Options:

A.  

Running

B.  

Failed

C.  

Upstream_failed

D.  

Success

Discussion 0
Question # 8

An administrator has configured the following settings:

config system global

set log-checksum md5-auth

end

What is the significance of executing this command?

Options:

A.  

This command records the log file MD5 hash value.

B.  

This command records passwords in log files and encrypts them.

C.  

This command encrypts log transfer between FortiAnalyzer and other devices.

D.  

This command records the log file MD5 hash value and authentication code.

Discussion 0
Question # 9

Refer to the exhibit.

Question # 9

What does the data point at 12:20 indicate?

Options:

A.  

The performance of FortiAnalyzer is below the baseline.

B.  

FortiAnalyzer is using its cache to avoid dropping logs.

C.  

The log insert lag time is increasing.

D.  

The sqlplugind service is caught up with new logs.

Discussion 0
Question # 10

What happens when the IOC breach detection engine on FortiAnalyzer finds web logs that match a blocklisted IP address?

Options:

A.  

The endpoint is marked as Compromised and. optionally, can be put in quarantine.

B.  

FortiAnalyzer flags the associated host for further analysis.

C.  

A new Infected entry is added for the corresponding endpoint.

D.  

The detection engine classifies those logs as Suspicious

Discussion 0
Question # 11

What FortiView tool can you use to automatically build a dataset and chart based on a filtered search result?

Options:

A.  

Chart Builder

B.  

Export to Report Chart

C.  

Dataset Library

D.  

Custom View

Discussion 0
Question # 12

Which two statements are true regarding ADOM modes? (Choose two.)

Options:

A.  

You can only change ADOM modes through CLI.

B.  

In normal mode, the disk quota of the ADOM is fixed and cannot be modified, but in advance mode, the disk quota of the ADOM is flexible because new devices are added to the ADOM.

C.  

In an advanced mode ADOM. you can assign FortiGate VDOMs from a single FortiGate device to multiple FortiAnalyzer ADOMs.

D.  

Normal mode is the default ADOM mode.

Discussion 0
Question # 13

What statements are true regarding the "store and upload" log transfer option between FortiAnalyzer and FortiGate? (Choose three.)

Options:

A.  

All FortiGates can send logs to FortiAnalyzer using the store and upload option.

B.  

Only FortiGate models with hard disks can send logs to FortiAnalyzer using the store and upload option.

C.  

Both secure communications methods (SSL and IPsec) allow the store and upload option.

D.  

Disk logging is enabled on the FortiGate through the CLI only.

E.  

Disk logging is enabled by default on the FortiGate.

Discussion 0
Question # 14

Which statement is true about sending notifications with incident updates?

Options:

A.  

Notifications can be sent only when an incident is updated or deleted.

B.  

If you use multiple fabric connectors, all connectors must have the same notification settings

C.  

Notifications can be sent only by email.

D.  

You can send notifications to multiple external platforms

Discussion 0
Question # 15

How can you attach a report to an incident?

Options:

A.  

By attaching it to an event handler alert

B.  

By editing the settings of the desired report

C.  

From the properties of an existing incident

D.  

Saving it in JSON format, and then importing it

Discussion 0
Question # 16

For which two purposes would you use the commandset log checksum? (Choose two.)

Options:

A.  

To help protect against man-in-the-middle attacks during log upload from FortiAnalyzer to an SFTP server

B.  

To prevent log modification or tampering

C.  

To encrypt log communications

D.  

To send an identical set of logs to a second logging server

Discussion 0
Question # 17

Which two methods can you use to send event notifications when an event occurs that matches a configured

event handler? (Choose two.)

Options:

A.  

SMS

B.  

Email

C.  

SNMP

D.  

IM

Discussion 0
Question # 18

What purposes does the auto-cache setting on reports serve? (Choose two.)

Options:

A.  

To reduce report generation time

B.  

To automatically update the hcache when new logs arrive

C.  

To reduce the log insert lag rate

D.  

To provide diagnostics on report generation time

Discussion 0
Question # 19

If you upgrade the FortiAnalyzer firmware, which report element can be affected?

Options:

A.  

Custom datasets

B.  

Report scheduling

C.  

Report settings

D.  

Output profiles

Discussion 0
Question # 20

Refer to the exhibits.

Question # 20

Question # 20

How many events will be added to the incident created after running this playbook?

Options:

A.  

Ten events will be added.

B.  

No events will be added.

C.  

Five events will be added.

D.  

Thirteen events will be added.

Discussion 0
Question # 21

Which statement about the FortiSIEM management extension is correct?

Options:

A.  

Allows you to manage the entire life cycle of a threat or breach.

B.  

Its use of the available disk space is capped at 50%.

C.  

It requires a licensed FortiSIEM supervisor.

D.  

It can be installed as a dedicated VM.

Discussion 0
Question # 22

Consider the CLI command:

Question # 22

What is the purpose of the command?

Options:

A.  

To add a unique tag to each log to prove that it came from this FortiAnalyzer

B.  

To add the MD5 hash value and authentication code

C.  

To add a log file checksum

D.  

To encrypt log communications

Discussion 0
Question # 23

What is the purpose of a predefined template on the FortiAnalyzer?

Options:

A.  

It can be edited and modified as required

B.  

It specifies the report layout which contains predefined texts, charts, and macros

C.  

It specifies report settings which contains time period, device selection, and schedule

D.  

It contains predefined data to generate mock reports

Discussion 0
Question # 24

How are logs forwarded when FortiAnalyzer is using aggregation mode?

Options:

A.  

Logs are forwarded as they are received and content files are uploaded at a scheduled time.

B.  

Logs and content files are stored and uploaded at a scheduled time.

C.  

Logs are forwarded as they are received.

D.  

Logs and content files are forwarded as they are received.

Discussion 0
Question # 25

Why must you wait for several minutes before you run a playbook that you just created?

Options:

A.  

FortiAnalyzer needs that time to parse the new playbook.

B.  

FortiAnalyzer needs that time to back up the current playbooks.

C.  

FortiAnalyzer needs that time to ensure there are no other playbooks running.

D.  

FortiAnalyzer needs that time to debug the new playbook.

Discussion 0
Question # 26

What are analytics logs on FortiAnalyzer?

Options:

A.  

Log type Traffic logs.

B.  

Logs that roll over when the log file reaches a specific size.

C.  

Logs that are indexed and stored in the SQL.

D.  

Raw logs that are compressed and saved to a log file.

Discussion 0
Question # 27

What are two of the key features of FortiAnalyzer? (Choose two.)

Options:

A.  

Centralized log repository

B.  

Cloud-based management

C.  

Reports

D.  

Virtual domains (VDOMs)

Discussion 0
Question # 28

In order for FortiAnalyzer to collect logs from a FortiGate device, what configuration is required? (Choose two.)

Options:

A.  

Remote logging must be enabled on FortiGate

B.  

Log encryption must be enabled

C.  

ADOMs must be enabled

D.  

FortiGate must be registered with FortiAnalyzer

Discussion 0
Question # 29

Which two statements are true regarding log fetching on FortiAnalyzer? (Choose two.)

Options:

A.  

A FortiAnalyzer device can perform either the fetch server or client role, and it can perform two roles at the same time with the same FortiAnalyzer devices at the other end.

B.  

Log fetching can be done only on two FortiAnalyzer devices that are running the same firmware version.

C.  

Log fetching allows the administrator to fetch analytics logs from another FortiAnalyzer for redundancy.

D.  

Log fetching allows the administrator to run queries and reports against historical data by retrieving archived logs from one FortiAnalyzer device and sending them to another FortiAnalyzer device.

Discussion 0
Question # 30

Which two elements are contained in a system backup created on FortiAnalyzer? (Choose two.)

Options:

A.  

System information

B.  

Logs from registered devices

C.  

Report information

D.  

Database snapshot

Discussion 0
Question # 31

An administrator fortinet, is able to view logs and perform device management tasks, such as adding and removing registered devices. However, administrator fortinet is not able to create a mall server that can be used to send email.

What could be the problem?

Options:

A.  

Fortinet is assigned the Standard_ User administrator profile.

B.  

A trusted host is configured.

C.  

ADOM mode is configured with Advanced mode.

D.  

Fortinet is assigned the Restricted_ User administrator profile.

Discussion 0
Question # 32

After you have moved a registered logging device out of one ADOM and into a new ADOM, what is the

purpose of running the following CLI command?

execute sql-local rebuild-adom

Options:

A.  

To reset the disk quota enforcement to default

B.  

To remove the analytics logs of the device from the old database

C.  

To migrate the archive logs to the new ADOM

D.  

To populate the new ADOM with analytical logs for the moved device, so you can run reports

Discussion 0
Question # 33

Refer to the exhibit.

Question # 33

Based on the partial outputs displayed, which devices can be members of a FortiAnalyzer Fabric?

Options:

A.  

FortiAnalyzerl and FortiAnalyzer3

B.  

FortiAnalyzer1 and FortiAnalyzer2

C.  

All devices listed can be members

D.  

FortiAnalyzer2 and FortiAnalyzer3

Discussion 0
Question # 34

Which two statements are true regarding high availability (HA) on FortiAnalyzer? (Choose two.)

Options:

A.  

FortiAnalyzer HA can function without VRRP. and VRRP is required only if you have more than two FortiAnalyzer devices in a cluster.

B.  

FortiAnalyzer HA supports synchronization of logs as well as some system and configuration settings.

C.  

All devices in a FortiAnalyzer HA cluster must run in the same operation mode: analyzer or collector.

D.  

FortiAnalyzer HA implementation is supported by many public cloud infrastructures such as AWS, Microsoft Azure, and Google Cloud.

Discussion 0
Question # 35

Which two statements about log forwarding are true? (Choose two.)

Options:

A.  

Forwarded logs cannot be filtered to match specific criteria.

B.  

Logs are forwarded in real-time only.

C.  

The client retains a local copy of the logs after forwarding.

D.  

You can use aggregation mode only with another FortiAnalyzer.

Discussion 0
Question # 36

FortiAnalyzer uses the Optimized Fabric Transfer Protocok (OFTP) over SSL for what purpose?

Options:

A.  

To upload logs to an SFTP server

B.  

To prevent log modification during backup

C.  

To send an identical set of logs to a second logging server

D.  

To encrypt log communication between devices

Discussion 0
Question # 37

After generating a report, you notice the information you were expecting to see is not included in it. What are two possible reasons for this scenario? (Choose two.)

Options:

A.  

You enabled auto-cache with extended log filtering.

B.  

The logfiled service has not indexed all the expected logs.

C.  

The logs were overwritten by the data retention policy.

D.  

The time frame selected in the report is wrong.

Discussion 0
Question # 38

What are two advantages of setting up fabric ADOM? (Choose two.)

Options:

A.  

It can be used for fast data processing and log correlation

B.  

It can be used to facilitate communication between devices in same Security Fabric

C.  

It can include all Fortinet devices that are part of the same Security Fabric

D.  

It can include only FortiGate devices that are part of the same Security Fabric

Discussion 0
Question # 39

You’ve moved a registered logging device out of one ADOM and into a new ADOM. What happens when you rebuild the new ADOM database?

Options:

A.  

FortiAnalyzer resets the disk quota of the new ADOM to default.

B.  

FortiAnalyzer migrates archive logs to the new ADOM.

C.  

FortiAnalyzer migrates analytics logs to the new ADOM.

D.  

FortiAnalyzer removes logs from the old ADOM.

Discussion 0
Question # 40

What statements are true regarding disk log quota? (Choose two)

Options:

A.  

The FortiAnalyzer stops logging once the disk log quota is met.

B.  

The FortiAnalyzer automatically sets the disk log quota based on the device.

C.  

The FortiAnalyzer can overwrite the oldest logs or stop logging once the disk log quota is met.

D.  

The FortiAnalyzer disk log quota is configurable, but has a minimum o 100mb a maximum based on the reserved system space.

Discussion 0
Question # 41

Which two statements express the advantages of grouping similar reports? (Choose two.)

Options:

A.  

Improve report completion time.

B.  

Conserve disk space on FortiAnalyzer by grouping multiple similar reports.

C.  

Reduce the number of hcache tables and improve auto-hcache completion time.

D.  

Provides a better summary of reports.

Discussion 0
Get NSE5_FAZ-7.2 dumps and pass your exam in 24 hours!

Free Exams Sample Questions