Pre-Summer Sale - Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70dumps

FCP_FAZ_AN-7.6 Questions and Answers

Question # 6

Which FortiAnalyzer feature allows you to use a proactive approach when managing your network security?

A.

FortiView Monitor

B.

Outbreak alert services

C.

Incidents dashboard

D.

Threat hunting

Full Access
Question # 7

Which two statements about exporting and importing playbooks are true? (Choose two.)

A.

A playbook that was disabled when it was exported will be disabled when it is imported.

B.

Playbooks can be imported to a different FortiAnalyzer device, but only if the connectors already exist

C.

You can import a playbook even if there is another one with the same name in the destination

D.

You can export only one playbook at a time.

Full Access
Question # 8

Exhibit.

Question # 8

Based on the partial outputs displayed, which devices can be members of a FortiAnalyzer Fabric?

A.

FortiAnalyzer1 and FortiAnalyzer3

B.

FortiAnalyzer1 and FortiAnalyzer2

C.

FortiAnalyzer2 and FortiAnalyzer3

D.

All devices listed can be members.

Full Access
Question # 9

Which two modules can be imported and exported between ADOMs on FortiAnalyzer? (Choose two.)

A.

Templates

B.

Reports

C.

Charts

D.

Datasets

Full Access
Question # 10

Which statement regarding macros on FortiAnalyzer is true?

A.

Macros are predefined templates for reports and cannot be customized.

B.

Macros are useful in generating excel log files automatically based on the report settings.

C.

Macros are ADOM-specific and each ADOM type have unique macros relevant to that ADOM.

D.

Macros are supported only on the FortiGate ADOMs.

Full Access
Question # 11

What is the purpose of playbook trigger variables?

A.

To display statistics about the playbook runtime

B.

To use information from the trigger to filter the action in a task

C.

To provide the trigger information to make the playbook start running

D.

To store the start the times of playbooks with On_Schedule triggers

Full Access
Question # 12

An administrator on your team has configured multiple reports to run periodically. Management has an additional request that all new generated reports be sent to a company email inbox for accessibility. The mail server has already been configured on FortiAnalyzer.

Which item must configure on FortiAnalyzer so that emails are sent when the reports are generated?

A.

Enable the option to email all reports under the mail server.

B.

Add a mailto: < email address > option within the report layouts.

C.

Enable email notification under the report calendar.

D.

Enable an output profile on the reports.

Full Access
Question # 13

Exhibit.

Question # 13

Question # 13

Assume these are all the events that exist on the FortiAnalyzer device.

How many events will be added to the incident created after running this playbook?

A.

Eleven events will be added.

B.

Seven events will be added

C.

No events will be added.

D.

Four events will be added.

Full Access
Question # 14

Exhibit.

Question # 14

What is the purpose of using the Chart Builder feature on FortiAnalyzer?

A.

To build a chart automatically based on the top 100 log entries

B.

To add charts directly to generate reports in the current ADOM.

C.

To add a new chart under FortiView to be used in new reports

D.

To build a dataset and chart based on the filtered search results

Full Access
Question # 15

Refer to Exhibit:

Question # 15

What does the data point at 21:20 indicate?

A.

FortiAnalyzer is indexing logs faster than logs are being received.

B.

The fortilogd daemon is ahead in indexing by one log.

C.

The SQL database requires a rebuild because of high receive lag.

D.

FortiAnalyzer is temporarily buffering received logs so older logs can be indexed first.

Full Access
Question # 16

What is the purpose of running the command diagnose sql status sqlreportd?

A.

To view a list of scheduled reports

B.

To list the current SQL processes running

C.

To display the SQL query connections and hcache status

D.

To identify the database log insertion status

Full Access
Question # 17

Exhibit.

Question # 17

What can you conclude from this output?

A.

There is no disk quota allocated to quarantining files.

B.

FGT_B is the Security Fabric root.

C.

The allocated disk quota to ADOM1 is 3 GB.

D.

Archive logs are using more space than analytic logs.

Full Access
Question # 18

Which statement correctly describes one difference between templates and reports?

A.

Reports support macros but templates do not

B.

Templates can be cloned, but reports cannot be cloned.

C.

Templates do not include advanced report settings, but reports do.

D.

Reports can be moved between ADOMs but templates cannot.

Full Access
Question # 19

You discover that a few reports are taking a long time to generate. Which two steps can you take to troubleshoot? (Choose two.)

A.

Remove old reports from the hcache

B.

Enable auto-cache and run the reports again

C.

Increase the ADOM reports quota

D.

Review report diagnostics

Full Access
Question # 20

After generating a report, you notice the information you were expecting to see is not included in it. However, you confirm that the logs are there:

Which two actions should you perform? (Choose two.)

A.

Check the time frame covered by the report.

B.

Disable auto-cache.

C.

Increase the report utilization quota.

D.

Test the dataset.

Full Access
Question # 21

You need to move reports between two ADOMs.

Which two statements are true? (Choose two.)

A.

The ADOMs must be compatible types.

B.

The date and time will be appended to the original report name to avoid conflicts.

C.

All charts and datasets associated with the report will be imported together.

D.

You need to convert the reports into templates first.

Full Access
Question # 22

You created a playbook on FortiAnalyzer that uses a FortiOS connector.

When configuring the FortiGate side, which type of trigger must be used so that the actions in an automation stitch are available in the FortiOS connector?

A.

FortiAnalyzer Event Handler

B.

Fabric Connector event

C.

FortiOS Event Log

D.

Incoming webhook

Full Access
Question # 23

Which statement correctly describes one Difference between templates and reports?

A.

Reports provide more configuration options than templates

B.

Templates can be cloned, but reports cannot be cloned.

C.

Reports support macros, but templates do not.

D.

Template are mapped to device groups. while reports are mapped to ADOMs

Full Access