ExamGecko
Home Home / Fortinet / NSE5_FAZ-7.2

Fortinet NSE5_FAZ-7.2 Practice Test - Questions Answers, Page 14

Question list
Search
Search

Which daemon is responsible for enforcing the log file size?

A.
sqlplugind
A.
sqlplugind
Answers
B.
logfiled
B.
logfiled
Answers
C.
miglogd
C.
miglogd
Answers
D.
ofrpd
D.
ofrpd
Answers
Suggested answer: B

Explanation:

FortiAnalyzer_7.0_Study_Guide-Online.pdf page 121: The logfiled process enforces the log file size and is also responsible for disk quota enforcement by monitoring the other processes.

Refer to the exhibit.

Which statement is correct regarding the event displayed?

A.
The security risk was blocked or dropped.
A.
The security risk was blocked or dropped.
Answers
B.
The security event risk is considered open.
B.
The security event risk is considered open.
Answers
C.
An incident was created from this event.
C.
An incident was created from this event.
Answers
D.
The risk source is isolated.
D.
The risk source is isolated.
Answers
Suggested answer: A

Explanation:

Events in FortiAnalyzer will be in one of four statuses. The current status will determine if more actions need to be taken by the security team or not.

The possible statuses are:

Unhandled: The security event risk is not mitigated or contained, so it is considered open.

Contained: The risk source is isolated.

Mitigated: The security risk is mitigated by being blocked or dropped.

(Blank): Other scenarios.

FortiAnalyzer_7.0_Study_Guide-Online pag. 206

What is required to authorize a FortiGate on FortiAnalyzer using Fabric authorization?

A.
A FortiGate ADOM
A.
A FortiGate ADOM
Answers
B.
The FortiGate serial number
B.
The FortiGate serial number
Answers
C.
A pre-shared key
C.
A pre-shared key
Answers
D.
Valid FortiAnalyzer credentials
D.
Valid FortiAnalyzer credentials
Answers
Suggested answer: D

Explanation:

FortiAnalyzer_7.0_Study_Guide-Online.pdf page 93: The fourth method uses the Fortinet Security

Fabric authorization process. This method requires that both FortiGate and FortiAnalyzer are running version 7.0.1 or higher. It is also required that the FortiGate administrator has valid credentials to log in on FortiAnalyzer and complete the registration.

https://docs.fortinet.com/document/fortianalyzer/7.2.1/administration-guide/13897/adding-afortigate-using-security-fabric-authorization

Refer to the exhibit.

Which image corresponds to the packet capture shown in the exhibit?

A)

B)

C)

D)

A.
Option A
A.
Option A
Answers
B.
Option B
B.
Option B
Answers
C.
Option C
C.
Option C
Answers
D.
Option D
D.
Option D
Answers
Suggested answer: C

What are two benefits of using fabric connectors? (Choose two.)

A.
They allow FortiAnalyzer to send logs in real-time to public cloud accounts.
A.
They allow FortiAnalyzer to send logs in real-time to public cloud accounts.
Answers
B.
You do not need an additional license to send logs to the cloud platform.
B.
You do not need an additional license to send logs to the cloud platform.
Answers
C.
Fabric connectors allow you to improve redundancy.
C.
Fabric connectors allow you to improve redundancy.
Answers
D.
Using fabric connectors is more efficient than using third-party polling with API.
D.
Using fabric connectors is more efficient than using third-party polling with API.
Answers
Suggested answer: A, C

Which log will generate an event with the status Contained?

A.
An IPS log with action=pass.
A.
An IPS log with action=pass.
Answers
B.
A WebFilter log with action=dropped.
B.
A WebFilter log with action=dropped.
Answers
C.
An AV log with action=quarantine.
C.
An AV log with action=quarantine.
Answers
D.
An AppControl log with action=blocked.
D.
An AppControl log with action=blocked.
Answers
Suggested answer: C

Refer to the exhibit.

Laptop1 is used by several administrators to manage FortiAnalyzer. You want to configure a generic text filter that matches all login attempts to the web interface generated by any user other than "admin", and coming from Laptop1.

Which filter will achieve the desired result?

A.
operation-login & dstip==10.1.1.210 & user!-admin
A.
operation-login & dstip==10.1.1.210 & user!-admin
Answers
B.
operation-login & srcip==10.1.1.100 & dstip==10.1.1.210 & user==admin
B.
operation-login & srcip==10.1.1.100 & dstip==10.1.1.210 & user==admin
Answers
C.
operation-login & performed_on=="GUI(10.1.1.210)" & user!=admin
C.
operation-login & performed_on=="GUI(10.1.1.210)" & user!=admin
Answers
D.
operation-login & performed_on=="GUI(10.1.1.100)" & user!=admin
D.
operation-login & performed_on=="GUI(10.1.1.100)" & user!=admin
Answers
Suggested answer: D
Total 137 questions
Go to page: of 14