ExamGecko
Home Home / Fortinet / NSE6_FAZ-7.2

Fortinet NSE6_FAZ-7.2 Practice Test - Questions Answers, Page 2

Question list
Search
Search

Which two parameters impact the amount of reserved disk space required by FortiAnalyzer? (Choose two.)

A.
Disk size
A.
Disk size
Answers
B.
Total quota
B.
Total quota
Answers
C.
RAID level
C.
RAID level
Answers
D.
License type
D.
License type
Answers
Suggested answer: A, C

Explanation:

The amount of reserved disk space required by FortiAnalyzer is influenced by the disk size and the RAID level. The system reserves a portion of the disk space for system use and unexpected quota overflow, with the rest available for device allocation. The RAID level determines the disk size and the reserved disk quota level, with different RAID configurations leading to variations in the reserved space.

Reference: FortiAnalyzer 7.2 Administrator Guide, 'Disk Space Allocation' and 'RAID Level Impact' sections.

Which two settings must you configure on FortiAnalyzer to allow non-local administrators to authenticate on FortiAnalyzer with any user account in a single LDAP group? (Choose two.)

A.
LDAP servers IP addresses added as trusted hosts
A.
LDAP servers IP addresses added as trusted hosts
Answers
B.
One or more remote LDAP servers
B.
One or more remote LDAP servers
Answers
C.
A local wildcard administrator account
C.
A local wildcard administrator account
Answers
D.
An administrator group
D.
An administrator group
Answers
Suggested answer: B, D

Explanation:

To allow non-local administrators to authenticate on FortiAnalyzer with any user account in a single LDAP group, you must configure one or more remote LDAP servers and an administrator group. First, you configure the LDAP server(s) by specifying the server name, IP, and other details such as the Common Name Identifier and Distinguished Name. Then, you add the LDAP server to a user group. Finally, you create an administrator account that uses this user group for authentication, allowing any user from the specified LDAP group to authenticate.

Reference: FortiAnalyzer 7.2 Administrator Guide, 'Configuring remote authentication for administrators using LDAP' section.

Which two statements are true regarding the log synchronization states for HA on FortiAnalyzer? (Choose two.)

A.
Log Data Sync provides real-time log synchronization to all backup devices.
A.
Log Data Sync provides real-time log synchronization to all backup devices.
Answers
B.
When Log Data Sync is turned on, the backup device reboots and then rebuilds the log database with the synchronized logs.
B.
When Log Data Sync is turned on, the backup device reboots and then rebuilds the log database with the synchronized logs.
Answers
C.
With Initial Logs Sync, when you add a unit to an HA cluster, the primary device synchronizes its logs with the backup device.
C.
With Initial Logs Sync, when you add a unit to an HA cluster, the primary device synchronizes its logs with the backup device.
Answers
D.
By default. Log Data Sync is disabled on all backup devices.
D.
By default. Log Data Sync is disabled on all backup devices.
Answers
Suggested answer: A, C

Explanation:

For HA on FortiAnalyzer, Log Data Sync ensures real-time log synchronization among all cluster members, including backup devices. This feature is enabled by default. The Initial Logs Sync state is triggered when a new unit is added to an HA cluster, where the primary unit synchronizes its logs with the newly added unit. After the initial synchronization, the secondary unit reboots and rebuilds its log database with the synchronized logs.

Reference: FortiAnalyzer 7.2 Administrator Guide, 'Log synchronization' section.

An administrator, fortinet, can view logs and perform device management tasks, such as adding and removing registered devices. However, administrator fortinet is not able to create a mail server that can be used to send alert emails.

What can be the problem?

A.
ADOM mode is configured with Advanced mode.
A.
ADOM mode is configured with Advanced mode.
Answers
B.
fortinet is assigned the Standard_User administrative profile.
B.
fortinet is assigned the Standard_User administrative profile.
Answers
C.
A trusted host is configured.
C.
A trusted host is configured.
Answers
D.
fortinet is assigned Restricted_User administrative profile.
D.
fortinet is assigned Restricted_User administrative profile.
Answers
Suggested answer: B

Explanation:

If the administrator 'fortinet' can view logs and perform device management tasks but cannot create a mail server for alert emails, it is likely due to the administrative profile assigned to them. The Standard_User administrative profile may restrict certain administrative functions, such as creating mail servers. To perform all administrative tasks, including creating mail servers, a higher privilege profile, such as Super_Admin, might be required.

Reference: FortiAnalyzer 7.2 Administrator Guide, 'Mail Server' section.

Which two statements are true regarding fabric connectors? (Choose two.)

A.
Using fabric connectors is more efficient than third-party polling information from the FortiAnalyzer API
A.
Using fabric connectors is more efficient than third-party polling information from the FortiAnalyzer API
Answers
B.
Cloud-out connectors allow you to send real-time logs to public cloud accounts like Amazon S3.
B.
Cloud-out connectors allow you to send real-time logs to public cloud accounts like Amazon S3.
Answers
C.
Fabric connectors allow you to save storage costs and improve redundancy.
C.
Fabric connectors allow you to save storage costs and improve redundancy.
Answers
D.
The storage connector service does not require a separate license to send logs to the cloud platform.
D.
The storage connector service does not require a separate license to send logs to the cloud platform.
Answers
Suggested answer: A, D

Explanation:

Fabric connectors in FortiAnalyzer, such as security fabric connectors (e.g., FortiClient EMS, FortiMail, FortiCASB) and storage connectors (e.g., Amazon S3, Azure Blob Container, Google Cloud Storage), provide efficient integration and data sharing capabilities. Using fabric connectors for direct integration with FortiAnalyzer is more efficient and reliable than relying on third-party applications to poll information through the FortiAnalyzer API. Additionally, the ability to send logs to cloud storage platforms like Amazon S3, Azure Blob, and Google Cloud directly through storage connectors is a built-in feature that does not require an additional license, thus saving on storage costs and improving redundancy without incurring extra licensing fees.

Reference: FortiAnalyzer 7.4.1 Administration Guide, 'Fabric Connectors' and 'Storage connectors' sections.

An administrator has configured the following settings:

What is the purpose of executing these commands?

A.
To record the hash value and authentication code of log files.
A.
To record the hash value and authentication code of log files.
Answers
B.
To encrypt log transfer between FortiAnalyzer and other devices.
B.
To encrypt log transfer between FortiAnalyzer and other devices.
Answers
C.
To verify the integrity of the log files received.
C.
To verify the integrity of the log files received.
Answers
D.
To create the secure channel used by the OFTP process.
D.
To create the secure channel used by the OFTP process.
Answers
Suggested answer: C

Explanation:

The purpose of executing the provided CLI commands, which include setting the log-checksum to md5-auth, is to ensure the integrity of the log files. This setting is used to record the MD5 hash value of log files, which is a widely used cryptographic hash function that produces a 128-bit (16-byte) hash value. By using MD5 authentication, FortiAnalyzer ensures that the log files have not been altered or tampered with during transit, thereby verifying their integrity upon receipt. This is not related to encrypting log transfers, scheduling reports, or creating secure channels for OFTP (Over-the-FortiGate Protocol) processes.

Which statement is true about the communication between FortiGate high availability (HA) clusters and FortiAnalyzer?

A.
Each cluster member sends its logs directly to FortiAnalyzer.
A.
Each cluster member sends its logs directly to FortiAnalyzer.
Answers
B.
You must add the device lo the cluster first, and then registers the cluster with FortiAnalyzer.
B.
You must add the device lo the cluster first, and then registers the cluster with FortiAnalyzer.
Answers
C.
FortiAnalyzer distinguishes each cluster member by its MAC address.
C.
FortiAnalyzer distinguishes each cluster member by its MAC address.
Answers
D.
Only the primary device in the cluster communicates with FortiAnalyzer.
D.
Only the primary device in the cluster communicates with FortiAnalyzer.
Answers
Suggested answer: D

Explanation:

In a FortiGate high availability (HA) cluster, only the primary device sends its logs to the FortiAnalyzer. This is to ensure that logs are not duplicated between the primary and secondary devices in the cluster. The configuration of the FortiAnalyzer server on the FortiGate is such that the HA primary device is set as the server that forwards the logs.

Reference: FortiAnalyzer 7.4.1 Administration Guide, sections mentioning HA cluster configuration and log forwarding.

Which two statements are true regarding FortiAnalyzer system backups? (Choose two.)

A.
Existing reports can be included in the backup files.
A.
Existing reports can be included in the backup files.
Answers
B.
The system reserves at least 5% to 20% disk space for backup files.
B.
The system reserves at least 5% to 20% disk space for backup files.
Answers
C.
Scheduled system backups can be configured only from the CLI.
C.
Scheduled system backups can be configured only from the CLI.
Answers
D.
Backup files can be uploaded to SCP and SFTP servers.
D.
Backup files can be uploaded to SCP and SFTP servers.
Answers
Suggested answer: A, D

Explanation:

FortiAnalyzer allows for the inclusion of existing reports in the backup files, providing a comprehensive backup of configurations and data. Additionally, the backup files can be configured to be uploaded to SCP and SFTP servers, ensuring secure transfer and offsite storage of backup data. This can be configured both in the GUI and the CLI, providing flexibility in how backups are scheduled and managed.

Reference: FortiAnalyzer 7.4.1 Administration Guide, 'Scheduling automatic backups' section.

Which statement is true about ADOMs?

A.
When a FortiAnalyzer Fabric is implemented, the default ADOM mode is set to advanced.
A.
When a FortiAnalyzer Fabric is implemented, the default ADOM mode is set to advanced.
Answers
B.
A fabric ADOM can include all the device types supported by FortiAnalyzer.
B.
A fabric ADOM can include all the device types supported by FortiAnalyzer.
Answers
C.
You can change the ADOM mode only through the GUI.
C.
You can change the ADOM mode only through the GUI.
Answers
D.
In normal mode, you cannot change the disk quota of the ADOM after its creation.
D.
In normal mode, you cannot change the disk quota of the ADOM after its creation.
Answers
Suggested answer: B

Explanation:

Regarding ADOMs (Administrative Domains) in FortiAnalyzer, a fabric ADOM is capable of including all device types that FortiAnalyzer supports. This is part of the flexibility offered by ADOMs to manage and report on logs from various devices within a Fortinet security fabric. ADOMs can be enabled to support non-FortiGate devices as well, and the root ADOM in Fabric ADOMs provides visibility into all Security Fabric devices. Additionally, it should be noted that in normal mode, you cannot assign different FortiGate VDOMs to different ADOMs, while in advanced mode, you can, which provides a more granular control over the log data from individual VDOMs.

Reference: FortiAnalyzer 7.4.1 Administration Guide, 'ADOMs' and 'ADOM device modes' sections.

Which FortiAnalyzer command erases all device settings, images, databases, and logs on disk, but preserves The network configuration?

A.
execute factory-reset
A.
execute factory-reset
Answers
B.
execute format disk
B.
execute format disk
Answers
C.
execute formatlogdisk
C.
execute formatlogdisk
Answers
D.
execute reset all-except---ip
D.
execute reset all-except---ip
Answers
Suggested answer: A

Explanation:

The FortiAnalyzer command execute factory-reset is used to erase all device settings, images, databases, and logs on disk but preserves the current IP address and route information. This command effectively resets the FortiAnalyzer to its factory settings while maintaining its network configuration, allowing it to be quickly reconfigured with the same network settings.

Reference: FortiAnalyzer 7.4.1 Administration Guide, 'Reset Commands' section.

Total 30 questions
Go to page: of 3