Fortinet FCP_FAZ_AN-7.4 Practice Test - Questions Answers, Page 4
Related questions
Which two statements about local logs on FortiAnalyzer are true? (Choose two.)
They are not supported in FortiView.
You can view playbook logs for all ADOMs in the root ADOM.
Event logs show system-wide information, whereas application logs are ADOM specific.
Event logs are available only in the root ADOM.
Refer to Exhibit:
What does the data point at 21:20 indicate?
FortiAnalyzer is indexing logs faster than logs are being received.
The fortilogd daemon is ahead in indexing by one log.
The SQL database requires a rebuild because of high receive lag.
FortiAnalyzer is temporarily buffering received logs so older logs can be indexed first.
A playbook contains five tasks in total. An administrator runs the playbook and four out of five tasks finish successfully, but one task fails.
What will be the status of the playbook after it is run?
Attention required
Upstream_failed
Failed
Success
Refer to Exhibit:
Client-1 is trying to access the internet for web browsing.
All FortiGate devices in the topology are part of a Security Fabric with logging to FortiAnalyzer configured. All firewall policies have logging enabled. All web filter profiles are configured to log only violations.
Which statement about the logging behavior for this specific traffic flow is true?
Only FGT-B will create traffic logs.
FGT-B will see the MAC address of FGT-A as the destination and notifies FGT-A to log this flow.
FGT B will create traffic logs and will create web filter logs if it detects a violation.
Only FGT-A will create web filter logs if it detects a violation.
What are two effects of enabling auto-cache in a FortiAnalyzer report? (Choose two.)
The generation time for reports is decreased.
When new logs are received, the hard-cache data is updated automatically.
FortiAnalyzer local cache is used to store generated reports.
The size of newly generated reports is optimized to conserve disk space.
What is the purpose of running the command diagnose sql status sqlreportd?
To view a list of scheduled reports
To list the current SQL processes running
To display the SQL query connections and hcache status
To identify the database log insertion status
Refer to the exhibit.
What can you conclude about the output?
The low indexing values require investigation.
The output is not ADOM specific.
There are more event logs than traffic logs.
The log rate higher than the message rate is not normal.
As part of your analysis, you discover that a Medium severity level incident is fully remediated.
You change the incident status to Closed:Remediated.
Which statement about your update is true?
The incident can no longer be deleted.
The corresponding event will be marked as Mitigated.
The incident dashboard will be updated.
The incident severity will be lowered.
Which two statement regarding the outbreak detection service are true? (Choose two.)
An additional license is required.
It automatically downloads new event handlers and reports.
Outbreak alerts are available on the root ADOM only.
New alerts are received by email.
You must find a specific security event log in the FortiAnalyzer logs displayed in FortiView, but, so far, you have been uncuccessful.
Which two tasks should you perform to investigate why you are having this issue? (Choose two.)
Open .gz log files in FortiView.
Rebuild the SQL database and check FortiView.
Review the ADOM data policy
Check logs in the Log Browse
Question