[Aug 30, 2023] NSE5_FAZ-7.0 PDF Recently Updated Questions Dumps to Improve Exam Score
NSE5_FAZ-7.0 Dumps Full Questions with Free PDF Questions to Pass
NEW QUESTION # 24
What does the disk status Degraded mean for RAID management?
- A. The FortiAnalyzer device is writing to all the hard drives on the device in order to make the array fault tolerant.
- B. The FortiAnalyzer device is writing data to a newly added hard drive in order to restore the hard drive to an optimal state.
- C. The hard driveiIs no longer being used by the RAID controller
- D. One or more drives are missing from the FortiAnalyzer unit. The drive is no longer available to the operating system.
Answer: C
NEW QUESTION # 25
Which two statements are true regarding log fetching on FortiAnalyzer? (Choose two.)
- A. Log fetching allows the administrator to run queries and reports against historical data by retrieving archived logs from one FortiAnalyzer device and sending them to another FortiAnalyzer device.
- B. Log fetching allows the administrator to fetch analytics logs from another FortiAnalyzer for redundancy.
- C. Log fetching can be done only on two FortiAnalyzer devices that are running the same firmware version.
- D. A FortiAnalyzer device can perform either the fetch server or client role, and it can perform two roles at the same time with the same FortiAnalyzer devices at the other end.
Answer: A,C
Explanation:
Reference:
Using FortiAnalyzer, you can enable log fetching. This allows FortiAnalyzer to fetch the archived logs of specified devices from another FortiAnalyzer, which you can then run queries or reports on for forensic analysis.
The FortiAnalyzer device that fetches logs operates as the fetch client, and the other FortiAnalyzer device that sends logs operates as the fetch server. Log fetching can happen only between two FortiAnalyzer devices, and both of them must be running the same firmware version. A FortiAnalyzer device can perform either the fetch server or client role, and it can perform two roles at the same time with different FortiAnalyzer devices at the other end.
FortiAnalyzer_7.0_Study_Guide-Online pag. 168
NEW QUESTION # 26
What is the purpose of output variables?
- A. To store playbook execution statistics
- B. To save all the task settings when a playbook is exported
- C. To use the output of the previous task as the input of the current task
- D. To display details of the connectors used by a playbook
Answer: C
Explanation:
FortiAnalyzer_7.0_Study_Guide-Online.pdf page 242: Output variables allow you to use the output from a preceding task as an input to the current task.
"Output variables allow you to use the output from a preceding task as an input to the current task." FortiAnalyzer_7.0_Study_Guide-Online page 242
NEW QUESTION # 27
After you have moved a registered logging device out of one ADOM and into a new ADOM, what is the purpose of running the following CLI command?
execute sql-local rebuild-adom <new-ADOM-name>
- A. To remove the analytics logs of the device from the old database
- B. To populate the new ADOM with analytical logs for the moved device, so you can run reports
- C. To migrate the archive logs to the new ADOM
- D. To reset the disk quota enforcement to default
Answer: B
Explanation:
NEW QUESTION # 28
Logs are being deleted from one of your ADOMs earlier that the configured setting for archiving in your data policy. What is the most likely problem?
- A. The total disk space is insufficient and you need to add other disk.
- B. CPU resources are too high.
- C. Logs in that ADOM are being forwarded in real-time to another FortiAnalyzer device.
- D. The ADOM disk quota is set too low based on log rates.
Answer: D
Explanation:
https://help.fortinet.com/fmgr/50hlp/56/5-6-1/FMG FAZ/1100_Storage/0017_Deleted%20device%20logs.htm
https://docs.fortinet.com/document/fortianalyzer/6.2.5/administration-guide/87802/automatic-deletion
NEW QUESTION # 29
What is the purpose of the following CLI command?
- A. To add the MD's hash value and authentication code
- B. To add a unique tag to each log to prove that it came from this FortiAnalyzer
- C. To encrypt log communications
- D. To add a log file checksum
Answer: D
Explanation:
https://docs2.fortinet.com/document/fortianalyzer/6.0.3/cli-reference/849211/global
NEW QUESTION # 30
What FortiView tool can you use to automatically build a dataset and chart based on a filtered search result?
- A. Chart Builder
- B. Export to Report Chart
- C. Dataset Library
- D. Custom View
Answer: B
NEW QUESTION # 31
Which two settings must you configure on FortiAnalyzer to allow non-local administrators to authenticate to FortiAnalyzer with any user account in a single LDAP group? (Choose two.)
- A. A remote LDAP server
- B. An administrator group
- C. A trusted host profile that restricts access to the LDAP group
- D. A local wildcard administrator account
Answer: A,D
NEW QUESTION # 32
What is required to authorize a FortiGate on FortiAnalyzer using Fabric authorization?
- A. A pre-shared key
- B. The FortiGate serial number
- C. Valid FortiAnalyzer credentials
- D. A FortiGate ADOM
Answer: C
Explanation:
FortiAnalyzer_7.0_Study_Guide-Online.pdf page 93: The fourth method uses the Fortinet Security Fabric authorization process. This method requires that both FortiGate and FortiAnalyzer are running version 7.0.1 or higher. It is also required that the FortiGate administrator has valid credentials to log in on FortiAnalyzer and complete the registration.
https://docs.fortinet.com/document/fortianalyzer/7.2.1/administration-guide/13897/adding-a-fortigate-using-security-fabric-authorization
NEW QUESTION # 33
For which two SAML roles can the FortiAnalyzer be configured? (Choose two.)
- A. Principal
- B. Identity provider
- C. Service provider
- D. Identity collector
Answer: B,C
Explanation:
Reference:
20the%20identity%20provider%20(IdP,external%20identity%20provider%20is%20available.
https://docs.fortinet.com/document/fortianalyzer/6.2.0/administration-guide/981386/saml-admin-authentication In FortiAnalyzer, SAML can be enabled across all Security Fabric devices, enabling smooth movement between devices for the administrator by means of single sign-on (SSO).
FortiAnalyzer can play the role of the identity provider (IdP), the service provider (SP), or Fabric SP, when an external identity provider is available.
FortiAnalyzer_7.0_Study_Guide-Online pag. 48
NEW QUESTION # 34
Refer to the exhibits.

How many events will be added to the incident created after running this playbook?
- A. Thirteen events will be added.
- B. Five events will be added.
- C. Ten events will be added.
- D. No events will be added.
Answer: B
NEW QUESTION # 35
After you have moved a registered logging device out of one ADOM and into a new ADOM, what is the purpose of running the following CLI command?
execute sql-local rebuild-adom <new-ADOM-name>
- A. To remove the analytics logs of the device from the old database
- B. To populate the new ADOM with analytical logs for the moved device, so you can run reports
- C. To migrate the archive logs to the new ADOM
- D. To reset the disk quota enforcement to default
Answer: B
Explanation:
FortiAnalyzer_7.0_Study_Guide-Online.pdf page 128: Are the device analytics logs required for reports in the new ADOM? If so, rebuild the new ADOM database
NEW QUESTION # 36
What is the purpose of a predefined template on the FortiAnalyzer?
- A. It contains predefined data to generate mock reports
- B. It can be edited and modified as required
- C. It specifies report settings which contains time period, device selection, and schedule
- D. It specifies the report layout which contains predefined texts, charts, and macros
Answer: D
Explanation:
Reference:
2300_Reports/0010_Predefined_reports.htm#:~:text=FortiAnalyzer%20includes%20a%20number%
20of,create%20and%2For%20build%20reports.&text=A%20template%20populates%20the%20Layout,that%
20is%20to%20be%20created.
https://help.fortinet.com/fa/faz50hlp/56/5-6-2/FMG-FAZ/2300_Reports/0010_Predefined_reports.htm
NEW QUESTION # 37
Which statements are true of Administrative Domains (ADOMs) in FortiAnalyzer? (Choose two.)
- A. Once enabled, the Device Manager, FortiView, Event Management, and Reports tab display per ADOM.
- B. All administrators can create ADOMs--not just the admin administrator.
- C. ADOMs are enabled by default.
- D. ADOMs constrain other administrator's access privileges to a subset of devices in the device list.
Answer: A,D
NEW QUESTION # 38
Which log type does the FortiAnalyzer indicators of compromise feature use to identify infected hosts?
- A. Application control logs
- B. Web filter logs
- C. Antivirus logs
- D. IPS logs
Answer: B
Explanation:
Reference:
FortiAnalyzer_Admin_Guide/3600_FortiView/0200_Using_FortiView/1200_Compromised_hosts_page.htm?
TocPath=FortiView%7CUsing%20FortiView%7C_____6
NEW QUESTION # 39
What happens when a log file saved on FortiAnalyzer disks reaches the size specified in the device log settings?
- A. The log file is purged from the database.
- B. The log file is overwritten.
- C. The log file is stored as a raw log and is available for analytic support.
- D. The log file rolls over and is archived.
Answer: D
Explanation:
Reference:
81a4-00505692583a/FortiAnalyzer-6.0.5-Administration-Guide.pdf
https://docs.fortinet.com/document/fortianalyzer/6.2.5/administration-guide/355632/log-browse
NEW QUESTION # 40
Which FortiAnalyzer feature allows you to use a proactive approach when managing your network security?
- A. FortiView Monitor
- B. Incidents dashboards
- C. Threat hunting
- D. Outbreak alert services
Answer: C
Explanation:
FortiAnalyzer_7.0_Study_Guide-Online.pdf page 217: Threat hunting consists in proactively searching for suspicious or potentially risky network activity in your environment. The proactive approach will help administrator find any threats that might have eluded detection by the current security solutions or configurations.
NEW QUESTION # 41
......
100% Updated Fortinet NSE5_FAZ-7.0 Enterprise PDF Dumps: https://pass4sure.examtorrent.com/NSE5_FAZ-7.0-prep4sure-dumps.html
