ExamGecko
Home / Fortinet / NSE6_FAZ-7.2 / List of questions
Ask Question

Fortinet NSE6_FAZ-7.2 Practice Test - Questions Answers, Page 2

List of questions

Question 11

Report Export Collapse

Which two parameters impact the amount of reserved disk space required by FortiAnalyzer? (Choose two.)

Disk size
Disk size
Total quota
Total quota
RAID level
RAID level
License type
License type
Suggested answer: A, C
Explanation:

The amount of reserved disk space required by FortiAnalyzer is influenced by the disk size and the RAID level. The system reserves a portion of the disk space for system use and unexpected quota overflow, with the rest available for device allocation. The RAID level determines the disk size and the reserved disk quota level, with different RAID configurations leading to variations in the reserved space.

Reference: FortiAnalyzer 7.2 Administrator Guide, 'Disk Space Allocation' and 'RAID Level Impact' sections.

asked 18/09/2024
Soma Ismael Bola
41 questions

Question 12

Report Export Collapse

Which two settings must you configure on FortiAnalyzer to allow non-local administrators to authenticate on FortiAnalyzer with any user account in a single LDAP group? (Choose two.)

LDAP servers IP addresses added as trusted hosts
LDAP servers IP addresses added as trusted hosts
One or more remote LDAP servers
One or more remote LDAP servers
A local wildcard administrator account
A local wildcard administrator account
An administrator group
An administrator group
Suggested answer: B, D
Explanation:

To allow non-local administrators to authenticate on FortiAnalyzer with any user account in a single LDAP group, you must configure one or more remote LDAP servers and an administrator group. First, you configure the LDAP server(s) by specifying the server name, IP, and other details such as the Common Name Identifier and Distinguished Name. Then, you add the LDAP server to a user group. Finally, you create an administrator account that uses this user group for authentication, allowing any user from the specified LDAP group to authenticate.

Reference: FortiAnalyzer 7.2 Administrator Guide, 'Configuring remote authentication for administrators using LDAP' section.

asked 18/09/2024
hamza reza
54 questions

Question 13

Report Export Collapse

Which two statements are true regarding the log synchronization states for HA on FortiAnalyzer? (Choose two.)

Log Data Sync provides real-time log synchronization to all backup devices.
Log Data Sync provides real-time log synchronization to all backup devices.
When Log Data Sync is turned on, the backup device reboots and then rebuilds the log database with the synchronized logs.
When Log Data Sync is turned on, the backup device reboots and then rebuilds the log database with the synchronized logs.
With Initial Logs Sync, when you add a unit to an HA cluster, the primary device synchronizes its logs with the backup device.
With Initial Logs Sync, when you add a unit to an HA cluster, the primary device synchronizes its logs with the backup device.
By default. Log Data Sync is disabled on all backup devices.
By default. Log Data Sync is disabled on all backup devices.
Suggested answer: A, C
Explanation:

For HA on FortiAnalyzer, Log Data Sync ensures real-time log synchronization among all cluster members, including backup devices. This feature is enabled by default. The Initial Logs Sync state is triggered when a new unit is added to an HA cluster, where the primary unit synchronizes its logs with the newly added unit. After the initial synchronization, the secondary unit reboots and rebuilds its log database with the synchronized logs.

Reference: FortiAnalyzer 7.2 Administrator Guide, 'Log synchronization' section.

asked 18/09/2024
henri victor BOGMIS
45 questions

Question 14

Report Export Collapse

An administrator, fortinet, can view logs and perform device management tasks, such as adding and removing registered devices. However, administrator fortinet is not able to create a mail server that can be used to send alert emails.

What can be the problem?

ADOM mode is configured with Advanced mode.
ADOM mode is configured with Advanced mode.
fortinet is assigned the Standard_User administrative profile.
fortinet is assigned the Standard_User administrative profile.
A trusted host is configured.
A trusted host is configured.
fortinet is assigned Restricted_User administrative profile.
fortinet is assigned Restricted_User administrative profile.
Suggested answer: B
Explanation:

If the administrator 'fortinet' can view logs and perform device management tasks but cannot create a mail server for alert emails, it is likely due to the administrative profile assigned to them. The Standard_User administrative profile may restrict certain administrative functions, such as creating mail servers. To perform all administrative tasks, including creating mail servers, a higher privilege profile, such as Super_Admin, might be required.

Reference: FortiAnalyzer 7.2 Administrator Guide, 'Mail Server' section.

asked 18/09/2024
George Sanchez
44 questions

Question 15

Report Export Collapse

Which two statements are true regarding fabric connectors? (Choose two.)

Using fabric connectors is more efficient than third-party polling information from the FortiAnalyzer API
Using fabric connectors is more efficient than third-party polling information from the FortiAnalyzer API
Cloud-out connectors allow you to send real-time logs to public cloud accounts like Amazon S3.
Cloud-out connectors allow you to send real-time logs to public cloud accounts like Amazon S3.
Fabric connectors allow you to save storage costs and improve redundancy.
Fabric connectors allow you to save storage costs and improve redundancy.
The storage connector service does not require a separate license to send logs to the cloud platform.
The storage connector service does not require a separate license to send logs to the cloud platform.
Suggested answer: A, D
Explanation:

Fabric connectors in FortiAnalyzer, such as security fabric connectors (e.g., FortiClient EMS, FortiMail, FortiCASB) and storage connectors (e.g., Amazon S3, Azure Blob Container, Google Cloud Storage), provide efficient integration and data sharing capabilities. Using fabric connectors for direct integration with FortiAnalyzer is more efficient and reliable than relying on third-party applications to poll information through the FortiAnalyzer API. Additionally, the ability to send logs to cloud storage platforms like Amazon S3, Azure Blob, and Google Cloud directly through storage connectors is a built-in feature that does not require an additional license, thus saving on storage costs and improving redundancy without incurring extra licensing fees.

Reference: FortiAnalyzer 7.4.1 Administration Guide, 'Fabric Connectors' and 'Storage connectors' sections.

asked 18/09/2024
pradeep singh dhesi
38 questions

Question 16

Report Export Collapse

An administrator has configured the following settings:

Fortinet NSE6_FAZ-7.2 image Question 16 26684 09182024190514000000

What is the purpose of executing these commands?

To record the hash value and authentication code of log files.
To record the hash value and authentication code of log files.
To encrypt log transfer between FortiAnalyzer and other devices.
To encrypt log transfer between FortiAnalyzer and other devices.
To verify the integrity of the log files received.
To verify the integrity of the log files received.
To create the secure channel used by the OFTP process.
To create the secure channel used by the OFTP process.
Suggested answer: C
Explanation:

The purpose of executing the provided CLI commands, which include setting the log-checksum to md5-auth, is to ensure the integrity of the log files. This setting is used to record the MD5 hash value of log files, which is a widely used cryptographic hash function that produces a 128-bit (16-byte) hash value. By using MD5 authentication, FortiAnalyzer ensures that the log files have not been altered or tampered with during transit, thereby verifying their integrity upon receipt. This is not related to encrypting log transfers, scheduling reports, or creating secure channels for OFTP (Over-the-FortiGate Protocol) processes.

asked 18/09/2024
ONWUDIWE NYENKE
38 questions

Question 17

Report Export Collapse

Which statement is true about the communication between FortiGate high availability (HA) clusters and FortiAnalyzer?

Each cluster member sends its logs directly to FortiAnalyzer.
Each cluster member sends its logs directly to FortiAnalyzer.
You must add the device lo the cluster first, and then registers the cluster with FortiAnalyzer.
You must add the device lo the cluster first, and then registers the cluster with FortiAnalyzer.
FortiAnalyzer distinguishes each cluster member by its MAC address.
FortiAnalyzer distinguishes each cluster member by its MAC address.
Only the primary device in the cluster communicates with FortiAnalyzer.
Only the primary device in the cluster communicates with FortiAnalyzer.
Suggested answer: D
Explanation:

In a FortiGate high availability (HA) cluster, only the primary device sends its logs to the FortiAnalyzer. This is to ensure that logs are not duplicated between the primary and secondary devices in the cluster. The configuration of the FortiAnalyzer server on the FortiGate is such that the HA primary device is set as the server that forwards the logs.

Reference: FortiAnalyzer 7.4.1 Administration Guide, sections mentioning HA cluster configuration and log forwarding.

asked 18/09/2024
Ramon Pasay
43 questions

Question 18

Report Export Collapse

Which two statements are true regarding FortiAnalyzer system backups? (Choose two.)

Become a Premium Member for full access
  Unlock Premium Member

Question 19

Report Export Collapse

Which statement is true about ADOMs?

Become a Premium Member for full access
  Unlock Premium Member

Question 20

Report Export Collapse

Which FortiAnalyzer command erases all device settings, images, databases, and logs on disk, but preserves The network configuration?

Become a Premium Member for full access
  Unlock Premium Member
Total 30 questions
Go to page: of 3