Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Fortinet FCP_FAZ_AD-7.4 Practice Exam with Questions & Answers | Set: 4

Questions 31

On the RAID management page, the disk status is listed as Initializing.

What does the status Initializing indicate about what the FortiAnalyzer is currently doing?

Options:
A.

FortiAnalyzer is ensuring that the parity data of a redundant drive is valid

B.

FortiAnalyzer is writing data to a newly added hard drive to restore it to an optimal state

C.

FortiAnalyzer is writing to all of its hard drives to make the array fault tolerant

D.

FortiAnalyzer is functioning normally

Fortinet FCP_FAZ_AD-7.4 Premium Access
Questions 32

Which daemon is responsible for enforcing the log file size?

Options:
A.

sqlplugind

B.

logfiled

C.

miglogd

D.

ofrpd

Questions 33

If the primary FortiAnalyzer in an HA cluster fails, how is the new primary elected?

Options:
A.

The configured IP address is checked first.

B.

The active port number is checked first.

C.

The firmware version is checked first.

D.

The configured priority is checked first

Questions 34

What is the purpose of a predefined template on the FortiAnalyzer?

Options:
A.

It can be edited and modified as required

B.

It specifies the report layout which contains predefined texts, charts, and macros

C.

It specifies report settings which contains time period, device selection, and schedule

D.

It contains predefined data to generate mock reports

Questions 35

In FortiAnalyzer’s FormView, source and destination IP addresses from FortiGate devices are not resolving to

a hostname. How can you resolve the source and destination IPs, without introducing any additional

performance impact to FortiAnalyzer?

Options:
A.

Configure local DNS servers on FortiAnalyzer

B.

Resolve IPs on FortiGate

C.

Configure # set resolve-ip enable in the system FortiView settings

D.

Resolve IPs on a per-ADOM basis to reduce delay on FortiView while IPs resolve

Questions 36

Which statement about the FortiSIEM management extension is correct?

Options:
A.

Allows you to manage the entire life cycle of a threat or breach.

B.

Its use of the available disk space is capped at 50%.

C.

It requires a licensed FortiSIEM supervisor.

D.

It can be installed as a dedicated VM.

Questions 37

Which two actions should an administrator take to view Compromised Hosts on FortiAnalyzer? (Choose two.)

Options:
A.

Enable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent to FortiAnalyzer.

B.

Make sure all endpoints are reachable by FortiAnalyzer.

C.

Enable device detection on an interface on the FortiGate devices that are connected to the FortiAnalyzer device.

D.

Subscribe FortiAnalyzer to FortiGuard to keep its local threat database up to date.

Questions 38

Which two statements about FortiAnalyzer operating modes are true? (Choose two.)

Options:
A.

When in collector mode, FortiAnalyzer offloads the log receiving task to the analyzer.

B.

When in analyzer mode, FortiAnalyzer supports event management and reporting features.

C.

For the collector, you should allocate most of the disk space to analytics logs.

D.

Analyzer mode is the default operating mode.

Questions 39

What FortiView tool can you use to automatically build a dataset and chart based on a filtered search result?

Options:
A.

Chart Builder

B.

Export to Report Chart

C.

Dataset Library

D.

Custom View

Questions 40

Refer to the exhibit.

FCP_FAZ_AD-7.4 Question 40

Laptopt is used by several administrators to manage FortiAnalyzer. You want to configure a generic text filter that matches all login attempts to the web interface generated by any user other than "admin" and coming from Laptop1:

Which filter will achieve the desired result?

Options:
A.

operation-login & performed_on=="GUI(10.1.1.100)" & user!=admin

B.

operation-login & srcip==10.1.1.100 & dstip==10.1.1.210 & user==admin

C.

operation-login & dstip==10.1.1.210 & userl-admin

D.

operation-login & performed_on=="GUI(10.1.1.210)' & user!=admin

Exam Code: FCP_FAZ_AD-7.4
Certification Provider: Fortinet
Exam Name: FCP - FortiAnalyzer 7.4 Administrator
Last Update: Jul 17, 2025
Questions: 178