Fortinet FCP_FAZ_AN-7.4 Practice Test - Questions Answers, Page 3
Related questions
Which FortiAnalyzer feature allows you to use a proactive approach when managing your network security?
FortiView Monitor
Outbreak alert services
Incidents dashboard
Threat hunting
Refer to the exhibit with partial output:
Your colleague exported a playbook and has sent it to you for review. You open the file in a text editor and observer the output as shown in the exhibit.
Which statement about the export is true?
The export data type is zipped.
The playbook is misconfigured.
The option to include the connector was not selected.
Your colleague put a password on the export.
You find that as part of your role as an analyst, you frequently search log View using the same parameters.
Instead of defining your search filters repeatedly, what can you do to save time?
Configure a custom dashboard.
Configure a custom view.
Configure a data selector.
Configure a marco and apply it to device groups.
An administrator on your team has configured multiple reports to run periodically. Management has an additional request that all new generated reports be sent to a company email inbox for accessibility. The mail server has already been configured on FortiAnalyzer.
Which item must configure on FortiAnalyzer so that emails are sent when the reports are generated?
Enable the option to email all repots under the mail server.
Add a mailto:<email address> option within the report layouts.
Enable email notification under the report calendar.
Enable an output profile on the reports.
Which statement regarding macros on FortiAnalyzer is true?
Macros are predefined templates for reports and cannot be customized.
Macros are useful in generating excel log files automatically based on the report settings.
Macros are ADOM-specific and each ADOM type have unique macros relevant to that ADOM.
Macros are supported only on the FortiGate ADOMs.
After a generated a repot, you notice the information you were expecting to see in not included in it. However, you confirm that the logs are there:
Which two actions should you perform? (Choose two.)
Check the time frame covered by the report.
Disable auto-cache.
Increase the report utilization quota.
Test the dataset.
After generating a report, you notice the information you where expecting to see is not included in it. However, you confirm that the logs are there.
Check the time frame covered by the report.
Disable auto-cache.
Increase the report utilization quota.
Test the dataset
Which two statements regarding FortiAnalyzer operating modes are true? (Choose two.)
When running in collector mode, FortiAnalyzer can forward logs to a syslog server.
FortiAnalyzer runs in collector mode by default unless it is configured for HA.
You can create and edit reports when FortiAnalyzer is running in collector mode.
A topology with FortiAnalyzeer devices running in both modes can improve their performance.
As part of your analysis, you discover that an incident is a false positive.
You change the incident status to Closed: False Positive.
Which statement about your update is true?
The audit history log will be updated.
The corresponding event will be marked as mitigated.
The incident will be deleted.
The incident number will be changed
Exhibit.
Laptop1 is used by several administrators to manage FotiAnalyzer. You want to configure a generic text filter that matches all login attempts to the web interface generated by any user other than admin'', and coming from Laptop1.
Which filter will achieve the desired result?
Operation-login and performed_on==''GUI(10.1.1.100)' and user!=admin
Operation-login and performed_on==''GU (10.1.1.120)' and user!=admin
Operation-login and srcip== 10.1.1.100 and dstip==10.1.1.1.210 and user==admin
Operation-login and dstip==10.1.1.210 and user!-admin
Question