Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: ecus65

Fortinet FCP_FAZ_AN-7.4 - FCP - FortiAnalyzer 7.4 Analyst

Page: 1 / 2
Total 56 questions

You created a playbook on FortiAnalyzer that uses a FortiOS connector.

When configuring the FortiGate side, which type of trigger must be used so that the actions in an automation stich are available in the FortiOS connector?

A.

FortiAnalyzer Event Handler

B.

Fabric Connector event

C.

FortiOS Event Log

D.

Incoming webhook

A playbook contains five tasks in total. An administrator runs the playbook and four out of five tasks finish successfully, but one task fails.

What will be the status of the playbook after it is run?

A.

Attention required

B.

Upstream_failed

C.

Failed

D.

Success

What is the purpose of playbook trigger variables?

A.

To display statistics about the playbook runtime

B.

To use information from the trigger to filter the action in a task

C.

To provide the trigger information to make the playbook start running

D.

To store the start the times of playbooks with On_Schedule triggers

Exhibit.

What can you conclude about the output?

A.

The message rate being lower that the log rate is normal.

B.

Both messages and logs are almost finished indexing.

C.

There are more traffic logs than event logs.

D.

The output is ADOM specific

Which two statements about local logs on FortiAnalyzer are true? (Choose two.)

A.

They are not supported in FortiView.

B.

You can view playbook logs for all ADOMs in the root ADOM.

C.

Event logs show system-wide information, whereas application logs are ADOM specific.

D.

Event logs are available only in the root ADOM.

As part of your analysis, you discover that a Medium severity level incident is fully remediated.

You change the incident status to Closed:Remediated.

Which statement about your update is true?

A.

The incident can no longer be deleted.

B.

The corresponding event will be marked as Mitigated.

C.

The incident dashboard will be updated.

D.

The incident severity will be lowered.

Which two methods can you use to send notifications when an event occurs that matches a configured event handler? (Choose two.)

A.

Send Alert through Fabric Connectors

B.

Send SNMP trap

C.

Send SMS notification

D.

Send Alert through FortiSIEM MEA

What are two effects of enabling auto-cache in a FortiAnalyzer report? (Choose two.)

A.

The generation time for reports is decreased.

B.

When new logs are received, the hard-cache data is updated automatically.

C.

FortiAnalyzer local cache is used to store generated reports.

D.

The size of newly generated reports is optimized to conserve disk space.

Which statement describes archive logs on FortiAnalyzer?

A.

Logs that are indexed and stored in the SQL database

B.

Logs a FortiAnalyzer administrator can access in FortiView

C.

Logs compressed and saved in files with the .gz extension

D.

Logs previously collected from devices that are offline

Which SQL query is in the correct order to query to database in the FortiAnalyzer?

A.

SELECT devid FROM $log GROUP BY devid WHERE ‘user’,,’ users1’

B.

SELECT FROM $log WHERE devid ‘user’,, USER1’ GROUP BY devid

C.

SELCT devid WHERE ’user’-‘ USER1’ FROM $log GROUP By devid

D.

SELECT devid FROM $log WHERE ‘user’=’ GROUP BY devid