Fortinet FCP_FAZ_AD-7.4 Practice Test - Questions Answers, Page 7

List of questions
Question 61

After you have moved a registered logging device out of one ADOM and into a new ADOM, what is the purpose of running the following CLI command?
execute sql-local rebuild-adom <new-ADOM-name>
To reset the disk quota enforcement to default
To remove the analytics logs of the device from the old database
To migrate the archive logs to the new ADOM
To populate the new ADOM with analytical logs for the moved device, so you can run reports
FortiAnalyzer_7.0_Study_Guide-Online.pdf page 128: Are the device analytics logs required for reports in the new ADOM? If so, rebuild the new ADOM database
Question 62

If a hard disk fails on a FortiAnalyzer that supports software RAID, what should you do to bring the FortiAnalyzer back to functioning normally, without losing data?
Hot swap the disk
Replace the disk and rebuild the RAID manually
Take no action if the RAID level supports a failed disk
Shut down FortiAnalyzer and replace the disk
https://kb.fortinet.com/kb/documentLink.do?externalID=FD46446#:~:text=On%20FortiAnalyzer%2FFortiManager%20devices%20that,to%20exchanging%20the%20hard%20disk.
If a hard disk on a FortiAnalyzer unit fails, it must be replaced. On FortiAnalyzer devices that support hardware RAID, the hard disk can be replaced while the unit is still running -- known as hot swapping. On FortiAnalyzer units with software RAID, the device must be shutdown prior to exchanging the hard disk.
Question 63

If you upgrade the FortiAnalyzer firmware, which report element can be affected?
Custom datasets
Report scheduling
Report settings
Output profiles
https://docs.fortinet.com/document/fortianalyzer/6.2.5/upgrade-guide/669300/checking-reports
Question 64

FortiAnalyzer reports are dropping analytical data from 15 days ago, even though the data policy setting for analytics logs is 60 days.
What is the most likely problem?
Quota enforcement is acting on analytical data before a report is complete
Logs are rolling before the report is run
CPU resources are too high
Disk utilization for archive logs is set for 15 days
Question 65

Which log type does the FortiAnalyzer indicators of compromise feature use to identify infected hosts?
Antivirus logs
Web filter logs
IPS logs
Application control logs
FortiAnalyzer_Admin_Guide/3600_FortiView/0200_Using_FortiView/1200_Compromised_hosts_page.htm?
TocPath=FortiView%7CUsing%20FortiView%7C_____6
Question 66

Which two settings must you configure on FortiAnalyzer to allow non-local administrators to authenticate to FortiAnalyzer with any user account in a single LDAP group? (Choose two.)
A local wildcard administrator account
A remote LDAP server
A trusted host profile that restricts access to the LDAP group
An administrator group
Question 67

When you perform a system backup, what does the backup configuration contain? (Choose two.)
Generated reports
Device list
Authorized devices logs
System information
https://help.fortinet.com/fa/cli-olh/5-6-5/Content/Document/1400_execute/backup.htm
Question 68

Which clause is considered mandatory in SELECT statements used by the FortiAnalyzer to generate reports?
FROM
LIMIT
WHERE
ORDER BY
Question 69

What is the purpose of a dataset query in FortiAnalyzer?
It sorts log data into tables
It extracts the database schema
It retrieves log data from the database
It injects log data into the database
Question 70

Logs are being deleted from one of the ADOMs earlier than the configured setting for archiving in the data policy.
What is the most likely problem?
CPU resources are too high
Logs in that ADOM are being forwarded, in real-time, to another FortiAnalyzer device
The total disk space is insufficient and you need to add other disk
The ADOM disk quota is set too low, based on log rates
20logs.htm
Question