Fortinet FCP_FAZ_AN-7.4 Practice Test - Questions Answers, Page 2
List of questions
Related questions
When managing incidents on FortiAnlyzer, what must an analyst be aware of?
You can manually attach generated reports to incidents.
The status of the incident is always linked to the status of the attach event.
Severity incidents rated with the level High have an initial service-level agreement (SLA) response time of 1 hour.
Incidents must be acknowledged before they can be analyzed.
Why must you wait for several minutes before you run a playbook that you just created?
FortiAnalyzer needs that time to parse the new playbook.
FortiAnalyzer needs that time to debug the new playbook.
FortiAnalyzer needs that time to back up the current playbooks.
FortiAnalyzer needs that time to ensure there are no other playbooks running.
Exhibit.
What can you conclude about the output?
The message rate being lower that the log rate is normal.
Both messages and logs are almost finished indexing.
There are more traffic logs than event logs.
The output is ADOM specific
Exhibit.
A fortiAnalyzer analyst is customizing a SQL query to use in a report.
Which SQL query should the analyst run to get the expected results?
A)
B)
C)
D)
Option A
Option B
Option C
Option D
Exhibit.
What can you conclude about these search results? (Choose two.)
They can be downloaded to a file.
They are sortable by columns and customizable.
They are not available for analysis in FortiView.
They were searched by using text mode.
Which two methods can you use to send notifications when an event occurs that matches a configured event handler? (Choose two.)
Send Alert through Fabric Connectors
Send SNMP trap
Send SMS notification
Send Alert through FortiSIEM MEA
Exhibit.
What can you conclude from this output?
There is not disk quota allocated to quarantining files.
FGT_B is the Security Fabric root.
The allocated disk quote to ADOM1 is 3 GB.
Archive logs are using more space than analytic logs.
Exhibit.
Assume these are all the events that exist on the FortiAnalyzer device.
How many events will be added to the incident created after running this playbook?
Eleven events will be added.
Seven events will be added
No events will be added.
Four events will be added.
Which statement about SQL SELECT queries is true?
They can be used to purge log entries from the database.
They must be followed immediately by a WHERE clause.
They can be used to display the database schema.
They are not used in macros.
Exhibit.
What is the analyst trying to create?
The analyst is trying to create a trigger variable to the used in the playbook.
The analyst is trying to create an output variable to be used in the playbook.
The analyst is trying to create a report in the playbook.
The analyst is trying to create a SOC report in the playbook.
Question