Month End Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Fortinet FCP_FAZ_AN-7.6 - Fortinet NSE 5 - FortiAnalyzer 7.6 Analyst

Page: 1 / 2
Total 67 questions

As part of your analysis, you discover that an incident is a false positive.

You change the incident status to Closed: False Positive.

Which statement about your update is true?

A.

The audit history log will be updated.

B.

The corresponding event will be marked as mitigated.

C.

The incident will bedeleted.

D.

The incident number will be changed

Which two actions should an administrator take to vide Compromised Hosts on FortiAnalyzer? (Choose two.)

A.

Enable device detection on the FotiGate device that are sending logs to FortiAnalyzer.

B.

Enable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent to fortiAnalyzer.

C.

Make sure all endpoints are reachable by FortiAnalyzer.

D.

Subscribe FortiAnalyzer to FortiGuard to keep its local threat database up to date.

Which statement about sending notifications with incident update is true?

A.

You can send notifications to multiple external platforms.

B.

Notifications can be sent only by email.

C.

If you use multiple fabric connectors, all connectors must have the same settings.

D.

Notifications can be sent only when an incident is updated or deleted.

What is the purpose of using data selectors when configuring event handlers?

A.

They filter the types of logs that FortiAnalyzer can accept from registered devices.

B.

They download new filters can be used in event handlers.

C.

They apply their filter criteria to the entire event handler so that you don’t have to configure the same criteria in the individual rules.

D.

They are common filters that can be appliedsimultaneously to all event handlers.

As part of your analysis, you discover that a Medium severity level incident is fully remediated.

You change the incident status to Closed:Remediated.

Which statement about your update is true?

A.

The incident can no longer be deleted.

B.

The corresponding event will be marked as Mitigated.

C.

The incident dashboard will be updated.

D.

The incident severity will be lowered.

What are the two methods you can use to send notifications when an event is generated by an event handler? (Choose two answers)

A.

Send SNMP trap.

B.

Send an alert through the FortiGuard server.

C.

Send an alert through Fabric connectors.

D.

Send SMS notification

Exhibit.

What does the data point at 12:20 indicate?

A.

The loginsert log time is increasing.

B.

FortiAnalyzer is using its cache to avoid dropping logs.

C.

The performance of FortiAnalyzer is below the baseline.

D.

The sqiplugind service is caught up with the logs

Which FortiAnalyzer feature allows you to use a proactive approach when managing your network security?

A.

FortiView Monitor

B.

Outbreak alert services

C.

Incidentsdashboard

D.

Threat hunting

When managing incidents on FortiAnlyzer, what must an analyst be aware of?

A.

You can manually attach generated reports to incidents.

B.

The status of the incident is always linked to the status of the attach event.

C.

Severity incidents rated with the level High have an initial service-level agreement (SLA) response time of 1 hour.

D.

Incidents must be acknowledged before they can be analyzed.

Which statement about exporting items in Report Definitions is true?

A.

Templates can be exported.

B.

Template exports contain associated charts and datasets.

C.

Chart exports contain associated datasets.

D.

Datasets can be exported.