New Year Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free Fortinet FCP_FAZ_AN-7.6 Practice Exam with Questions & Answers

Questions 1

Which statement about exporting items in Report Definitions is true?

Options:
A.

Templates can be exported.

B.

Template exports contain associated charts and datasets.

C.

Chart exports contain associated datasets.

D.

Datasets can be exported.

Questions 2

Exhibit.

FCP_FAZ_AN-7.6 Question 2

A fortiAnalyzer analyst is customizing a SQL query to use in a report.

Which SQL query should the analyst run to get the expected results?

A)

FCP_FAZ_AN-7.6 Question 2

B)

FCP_FAZ_AN-7.6 Question 2

C)

D)

Options:
A.

Option A

B.

Option B

C.

Option C

D.

Option D

Questions 3

Which statement describes archive logs on FortiAnalyzer?

Options:
A.

Logs that are indexed and stored in the SQL database

B.

Logs a FortiAnalyzer administrator can access in FortiView

C.

Logs compressed and saved in files with the .gz extension

D.

Logs previously collected from devices that are offline

Questions 4

Exhibit.

What can you conclude from this output?

Options:
A.

There is not disk quota allocated to quarantining files.

B.

FGT_B is the Security Fabric root.

C.

The allocated disk quote to ADOM1 is 3 GB.

D.

Archive logs are using more space than analytic logs.

Questions 5

(When there are no matching parsers for a device log, what does FortiAnalyzer do? (Choose one answer))

Options:
A.

Drops the log

B.

Applies the generic SYSLOG parser

C.

Stores the log but doesn’t normalize it

D.

Archives the log for future analysis

Questions 6

Exhibit.

Laptop1 is used by several administrators to manage FotiAnalyzer. You want to configure a generic text filter that matches all login attempts to the web interface generated by any user other than admin’’, and coming from Laptop1.

Which filter will achieve the desired result?

Options:
A.

Operation-login and performed_on==’’GUI(10.1.1.100)’ and user!=admin

B.

Operation-login and performed_on==’’GU (10.1.1.120)’ and user!=admin

C.

Operation-login and srcip== 10.1.1.100 anddstip==10.1.1.1.210 and user==admin

D.

Operation-login and dstip==10.1.1.210 and user!-admin

Questions 7

Which statement about automation connectors in FortiAnalyzer is true?

Options:
A.

An ADOM with the Fabric type comes with multiple connectors configured.

B.

The local connector becomes available after you configured any external connector.

C.

The local connector becomes available after you connectors are displayed.

D.

The actions available with FortiOS connectors are determined by automation rules configured on FortiGate.

Questions 8

After generating a report, you notice the information you where expecting to see is not included in it. However, you confirm that the logs are there.

Options:
A.

Check the time frame covered by thereport.

B.

Disable auto-cache.

C.

Increase the report utilization quota.

D.

Test the dataset

Questions 9

Exhibit.

FCP_FAZ_AN-7.6 Question 9

What can you conclude about the output?

Options:
A.

The message ratebeing lower that the log rate is normal.

B.

Both messages and logs are almost finished indexing.

C.

There are more traffic logs than event logs.

D.

The output is ADOM specific

Questions 10

(Refer to the exhibit.

FCP_FAZ_AN-7.6 Question 10

Which two observations can you make after reviewing this log entry? (Choose two answers))

Options:
A.

This is a normalized log.

B.

This is a formatted view of the log.

C.

This is the original log that FortiAnalyzer received from FortiGate.

D.

This log is in a raw log format.