Fortinet FCP_FAZ_AD-7.4 Practice Test - Questions Answers, Page 6

List of questions
Question 51

An administrator has configured the following settings:
config system global
set log-checksum md5-auth
end
What is the significance of executing this command?
This command records the log file MD5 hash value.
This command records passwords in log files and encrypts them.
This command encrypts log transfer between FortiAnalyzer and other devices.
This command records the log file MD5 hash value and authentication code.
Question 52

Which two of the following must you configure on FortiAnalyzer to email a FortiAnalyzer report externally?
(Choose two.)
Mail server
Output profile
SFTP server
Report scheduling
Question 53

For which two purposes would you use the command set log checksum? (Choose two.)
To help protect against man-in-the-middle attacks during log upload from FortiAnalyzer to an SFTP server
To prevent log modification or tampering
To encrypt log communications
To send an identical set of logs to a second logging server
To prevent logs from being tampered with while in storage, you can add a log checksum using the config system global command. You can configure FortiAnalyzer to record a log file hash value, timestamp, and authentication code when the log is rolled and archived and when the log is uploaded (if that feature is enabled). This can also help against man-in-the-middle only for the transmission from FortiAnalyzer to an
SSH File Transfer Protocol (SFTP) server during log upload.
FortiAnalyzer_7.0_Study_Guide-Online page 149
Question 54

Refer to the exhibit.
What does the data point at 14:55 tell you?
The received rate is almost at its maximum for this device
The sqlplugind daemon is behind in log indexing by two logs
Logs are being dropped
Raw logs are reaching FortiAnalyzer faster than they can be indexed
Question 55

You are using RAID with a FortiAnalyzer that supports software RAID, and one of the hard disks on
FortiAnalyzer has failed.
What is the recommended method to replace the disk?
Shut down FortiAnalyzer and then replace the disk
Downgrade your RAID level, replace the disk, and then upgrade your RAID level
Clear all RAID alarms and replace the disk while FortiAnalyzer is still running
Perform a hot swap
https://community.fortinet.com/t5/FortiAnalyzer/Technical-Note-How-to-swap-Hard-Disk-on-FortiAnalyzer/ta-p/194997?externalID=FD41397#:~:text=If%20a%20hard%20disk%20on,process%20known%20as%20hot%20swapping
Question 56

On the RAID management page, the disk status is listed as Initializing.
What does the status Initializing indicate about what the FortiAnalyzer is currently doing?
FortiAnalyzer is ensuring that the parity data of a redundant drive is valid
FortiAnalyzer is writing data to a newly added hard drive to restore it to an optimal state
FortiAnalyzer is writing to all of its hard drives to make the array fault tolerant
FortiAnalyzer is functioning normally
8977-00505692583a/FortiAnalyzer-5.6.10-Administration-Guide.pdf (40)
Question 57

In the FortiAnalyzer FortiView, source and destination IP addresses from FortiGate devices are not resolving to a hostname.
How can you resolve the source and destination IP addresses, without introducing any additional performance impact to FortiAnalyzer?
Resolve IP addresses on a per-ADOM basis to reduce delay on FortiView while IPs resolve
Configure # set resolve-ip enable in the system FortiView settings
Configure local DNS servers on FortiAnalyzer
Resolve IP addresses on FortiGate
https://packetplant.com/fortigate-and-fortianalyzer-resolve-source-and-destination-ip/
''As a best practice, it is recommended to resolve IPs on the FortiGate end. This is because you get both source and destination, and it offloads the work from FortiAnalyzer. On FortiAnalyzer, this IP resolution does destination IPs only''
Question 58

You have recently grouped multiple FortiGate devices into a single ADOM. System Settings > Storage Info shows the quota used.
What does the disk quota refer to?
The maximum disk utilization for each device in the ADOM
The maximum disk utilization for the FortiAnalyzer model
The maximum disk utilization for the ADOM type
The maximum disk utilization for all devices in the ADOM
Question 59

Why should you use an NTP server on FortiAnalyzer and all registered devices that log into FortiAnalyzer?
To properly correlate logs
To use real-time forwarding
To resolve host names
To improve DNS response times
Question 60

You need to upgrade your FortiAnalyzer firmware.
What happens to the logs being sent to FortiAnalyzer from FortiGate during the time FortiAnalyzer is temporarily unavailable?
FortiAnalyzer uses log fetching to retrieve the logs when back online
FortiGate uses the miglogd process to cache the logs
The logfiled process stores logs in offline mode
Logs are dropped
Question