[Mar 05, 2024] NSE5_FAZ-7.0 Exam Dumps - Fortinet Practice Test Questions [Q43-Q67]

Share

[Mar 05, 2024] NSE5_FAZ-7.0 Exam Dumps - Fortinet Practice Test Questions

New Real NSE5_FAZ-7.0 Exam Dumps Questions


Fortinet NSE5_FAZ-7.0 (Fortinet NSE 5 - FortiAnalyzer 7.0) Certification Exam is a certification program designed for IT professionals who want to prove their skills and expertise in using FortiAnalyzer to collect, analyze, and report on log data generated from Fortinet devices. Fortinet NSE 5 - FortiAnalyzer 7.0 certification is aimed at professionals who have experience in network security and have a good understanding of Fortinet products and solutions. Fortinet NSE 5 - FortiAnalyzer 7.0 certification exam covers topics such as FortiAnalyzer administration, log management, event management, and reporting.

 

NEW QUESTION # 43
Consider the CLI command:

What is the purpose of the command?

  • A. To add a unique tag to each log to prove that it came from this FortiAnalyzer
  • B. To add a log file checksum
  • C. To encrypt log communications
  • D. To add the MD5 hash value and authentication code

Answer: B

Explanation:
https://docs.fortinet.com/document/fortianalyzer/6.2.5/cli-reference/849211/global


NEW QUESTION # 44
Which clause is considered mandatory in SELECT statements used by the FortiAnalyzer to generate reports?

  • A. FROM
  • B. WHERE
  • C. LIMIT
  • D. ORDER BY

Answer: A


NEW QUESTION # 45
Which statement is true regarding Macros on FortiAnalyzer?

  • A. Macros are predefined templates for reports and cannot be customized.
  • B. Macros are supported only on the FortiGate ADOM.
  • C. Macros are useful in generating excel log files automatically based on the reports settings.
  • D. Macros are ADOM specific and each ADOM will have unique macros relevant to that ADOM.

Answer: D


NEW QUESTION # 46
What are offline logs on FortiAnalyzer?

  • A. Compressed logs, which are also known as archive logs, are considered to be offline logs.
  • B. When you restart FortiAnalyzer. all stored logs are considered to be offline logs.
  • C. Logs that are indexed and stored in the SQL database.
  • D. Logs that are collected from offline devices after they boot up.

Answer: A


NEW QUESTION # 47
Which daemon is responsible for enforcing the log file size?

  • A. sqlplugind
  • B. ofrpd
  • C. logfiled
  • D. miglogd

Answer: C

Explanation:
FortiAnalyzer_7.0_Study_Guide-Online.pdf page 121: The logfiled process enforces the log file size and is also responsible for disk quota enforcement by monitoring the other processes.


NEW QUESTION # 48
In Log View, you can use the Chart Builder feature to build a dataset and chart based on the filtered search results.
Similarly, which feature you can use for FortiView?

  • A. Export to PDF
  • B. Export to Chart Builder
  • C. Export to Custom Chart
  • D. Export to Report Chart

Answer: D

Explanation:
Reference:
Similar to the Chart Builder feature in Log View, you can export a chart from a FortiView. The chart export includes any filters you set on the FortiView. FortiAnalyzer_7.0_Study_Guide-Online pag. 292.


NEW QUESTION # 49
What statements are true regarding the "store and upload" log transfer option between FortiAnalyzer and FortiGate? (Choose three.)

  • A. Only FortiGate models with hard disks can send logs to FortiAnalyzer using the store and upload option.
  • B. Both secure communications methods (SSL and IPsec) allow the store and upload option.
  • C. Disk logging is enabled by default on the FortiGate.
  • D. All FortiGates can send logs to FortiAnalyzer using the store and upload option.
  • E. Disk logging is enabled on the FortiGate through the CLI only.

Answer: A,B,E


NEW QUESTION # 50
What is the purpose of a dataset query in FortiAnalyzer?

  • A. It injects log data into the database
  • B. It sorts log data into tables
  • C. It retrieves log data from the database
  • D. It extracts the database schema

Answer: C


NEW QUESTION # 51
Refer to the exhibit.

The exhibit shows "remoteservergroup" is an authentication server group with LDAP and RADIUS servers.
Which two statements express the significance of enabling "Match all users on remote server" when configuring a new administrator? (Choose two.)

  • A. Administrator can log in to FortiAnalyzer using their credentials on remote servers LDAP and RADIUS.
  • B. It creates a wildcard administrator using LDAP and RADIUS servers.
  • C. Use remoteadmin from LDAP and RADIUS servers will be able to log in to FortiAnalyzer at anytime.
  • D. It allows administrators to use two-factor authentication.

Answer: A,B


NEW QUESTION # 52
Which two statement are true regardless initial Logs sync and Log Data Sync for Ha on FortiAnalyzer?

  • A. With initial Logs Sync, when you add a unit to an HA cluster, the primary device synchronizes its logs with the backup device.
  • B. By default, Log Data Sync is disabled on all backup devise.
  • C. Log Data Sync provides real-time log synchronization to all backup devices.
  • D. When Logs Data Sync is turned on, the backup device will reboot and then rebuilt the log database with the synchronized logs.

Answer: A,D


NEW QUESTION # 53
On FortiAnalyzer, what is a wildcard administrator account?

  • A. An account that validates against any user account on a FortiAuthenticator
  • B. An account that permits access to members of an LDAP group
  • C. An account that allows guest access with read-only privileges
  • D. An account that requires two-factor authentication

Answer: B

Explanation:
https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/747268/configuring-wildcard-admin-accounts


NEW QUESTION # 54
An administrator fortinet, is able to view logs and perform device management tasks, such as adding and removing registered devices. However, administrator fortinet is not able to create a mall server that can be used to send email.
What could be the problem?

  • A. ADOM mode is configured with Advanced mode.
  • B. A trusted host is configured.
  • C. Fortinet is assigned the Restricted_ User administrator profile.
  • D. Fortinet is assigned the Standard_ User administrator profile.

Answer: D

Explanation:
* Super_User, which, like in FortiGate, provides access to all device and system privileges.
* Standard_User, which provides read and write access to device privileges, but not system privileges.
* Restricted_User, which provides read access only to device privileges, but not system privileges. Access to the Management extensions is also removed.
* No_Permissions_User, which provides no system or device privileges. Can be used, for example, to temporarily remove access granted to existing admins.
FortiAnalyzer_7.0_Study_Guide-Online page 42


NEW QUESTION # 55
Refer to the exhibit.

The image displays the configuration of a FortiAnalyzer the administrator wants to join to an existing HA cluster.
What can you conclude from the configuration displayed?

  • A. This FortiAnalyzer is configured to receive logs in its port1.
  • B. This FortiAnalyzer will trigger a failover after losing communication with its peers for 10 seconds.
  • C. This FortiAnalyzer will join to the existing HA cluster as the primary.
  • D. After joining to the cluster, this FortiAnalyzer will keep an updated log database.

Answer: A

Explanation:
"If the preferred role is Primary, then this unit becomes the primary unit if it is configured first in a new HA cluster. If there is an existing primary unit, then this unit becomes a secondary unit." (https://docs.fortinet.com/document/fortianalyzer/7.0.5/administration-guide/275104)


NEW QUESTION # 56
What is the purpose of the following CLI command?

  • A. To add a unique tag to each log to prove that it came from this FortiAnalyzer
  • B. To add the MD's hash value and authentication code
  • C. To add a log file checksum
  • D. To encrypt log communications

Answer: C

Explanation:
https://docs2.fortinet.com/document/fortianalyzer/6.0.3/cli-reference/849211/global


NEW QUESTION # 57
Which statement is true when you are upgrading the firmware on an HA cluster made up of two FortiAnalyzer devices?

  • A. First, upgrade the secondary device, and then upgrade the primary device.
  • B. You can perform the firmware upgrade using only a console connection.
  • C. Both FortiAnalyzer devices will be upgraded at the same time.
  • D. You can enable uninterruptible-upgrade so that the normal FortiAnalyzer operations are not interrupted while the cluster firmware upgrades.

Answer: A

Explanation:
FortiAnalyzer_7.0_Study_Guide-Online.pdf page 64: To upgrade FortiAnalyzer HA cluster firmware:
1. Log in to each secondary device.
2. Upgrade the firmware of all secondary devices.
3. Wait for the upgrades to complete and verify that all secondary devices joined the cluster.
4. Verify that logs on all secondary devices are synchronized with the primary device.
5. Upgrade the primary device.
https://docs.fortinet.com/document/fortianalyzer/7.2.0/upgrade-guide/262607/upgrading-fortianalyzer-firmware


NEW QUESTION # 58
Refer to the exhibit.

Which statement is correct regarding the event displayed?

  • A. The risk source is isolated.
  • B. The security risk was blocked or dropped.
  • C. The security event risk is considered open.
  • D. An incident was created from this event.

Answer: B

Explanation:
Events in FortiAnalyzer will be in one of four statuses. The current status will determine if more actions need to be taken by the security team or not.
The possible statuses are:
Unhandled: The security event risk is not mitigated or contained, so it is considered open.
Contained: The risk source is isolated.
Mitigated: The security risk is mitigated by being blocked or dropped.
(Blank): Other scenarios.
FortiAnalyzer_7.0_Study_Guide-Online pag. 206


NEW QUESTION # 59
Which two statements are true regarding high availability (HA) on FortiAnalyzer? (Choose two.)

  • A. FortiAnalyzer HA can function without VRRP. and VRRP is required only if you have more than two FortiAnalyzer devices in a cluster.
  • B. All devices in a FortiAnalyzer HA cluster must run in the same operation mode: analyzer or collector.
  • C. FortiAnalyzer HA implementation is supported by many public cloud infrastructures such as AWS, Microsoft Azure, and Google Cloud.
  • D. FortiAnalyzer HA supports synchronization of logs as well as some system and configuration settings.

Answer: B,D

Explanation:
Reference:
FortiAnalyzer HA implementation works only in networks where Virtual Router Redundancy Protocol (VRRP) is permitted. Therefore it may not be supported by some public cloud infrastructures.


NEW QUESTION # 60
What can you do on FortiAnalyzer to restrict administrative access from specific locations?

  • A. Configure two-factor authentication with a remote RADIUS server.
  • B. Enable geo-location services on accessible interface.
  • C. Configure trusted hosts for that administrator.
  • D. Configure an ADOM for respective location.

Answer: C


NEW QUESTION # 61
If the primary FortiAnalyzer in an HA cluster fails, how is the new primary elected?

  • A. The active port number is checked first.
  • B. The configured priority is checked first
  • C. The firmware version is checked first.
  • D. The configured IP address is checked first.

Answer: B

Explanation:
In the case of a primary device failure, FortiAnalyzer HA uses the following rules to select a new primary:
* All cluster devices are assigned a priority from 80 to 120. The default priority is 100. If the primary device becomes unavailable, the device with the highest priority is selected as the new primary device. For example, a device with a priority of 110 is selected over a device with a priority of 100.
* If multiple devices have the same priority, the device whose primary IP address has the greatest value is selected as the new primary device. For example, 123.45.67.124 is selected over 123.45.67.123.
* If a new device with a higher priority or a greater value IP address joins the cluster, the new device does not replace (or pre-empt) the current primary device automatically.
FortiAnalyzer_7.0_Study_Guide-Online page 62


NEW QUESTION # 62
What are offline logs on FortiAnalyzer?

  • A. Compressed logs, which are also known as archive logs, are considered to be offline logs.
  • B. When you restart FortiAnalyzer. all stored logs are considered to be offline logs.
  • C. Logs that are indexed and stored in the SQL database.
  • D. Logs that are collected from offline devices after they boot up.

Answer: A

Explanation:
Reference:
Logs are received and saved in a log file on the FortiAnalyzer disks. Eventually, when the log file reaches a configured size, or at a set schedule, it is rolled over by being renamed. These files (rolled or otherwise) are known as archive logs and are considered offline so they don't offer immediate analytic support. Combined, they count toward the archive quota and retention limits, and they are deleted based on the ADOM data policy. FortiAnalyzer_7.0_Study_Guide-Online page 140


NEW QUESTION # 63
Which statement is true regarding Macros on FortiAnalyzer?

  • A. Macros are predefined templates for reports and cannot be customized.
  • B. Macros are supported only on the FortiGate ADOM.
  • C. Macros are useful in generating excel log files automatically based on the reports settings.
  • D. Macros are ADOM specific and each ADOM will have unique macros relevant to that ADOM.

Answer: D

Explanation:
FortiAnalyzer_7.0_Study_Guide-Online.pdf page 283: Note that macros are ADOM-specific and supported in FortiGate and FortiCarrier ADOMs only.


NEW QUESTION # 64
Which two constraints can impact the amount of reserved disk space required by FortiAnalyzer? (Choose two.)

  • A. RAID level
  • B. Total quota
  • C. License type
  • D. Disk size

Answer: A,D

Explanation:
https://docs.fortinet.com/document/fortianalyzer/6.2.5/administration-guide/368682/disk-space-allocation


NEW QUESTION # 65
What can the CLI command # diagnose test application oftpd 3 help you to determine?

  • A. What logs, if any, are reaching FortiAnalyzer
  • B. What devices and IP addresses are connecting to FortiAnalyzer
  • C. What ADOMs are enabled and configured
  • D. What devices are registered and unregistered

Answer: B

Explanation:
https://docs.fortinet.com/document/fortianalyzer/6.2.5/cli-reference/395556/test#test_application


NEW QUESTION # 66
Which two statements are true regarding FortiAnalyzer log forwarding? (Choose two.)

  • A. In aggregation mode, you can forward logs to syslog and CEF servers as well.
  • B. Forwarding mode forwards logs in real time only to other FortiAnalyzer devices.
  • C. Both modes, forwarding and aggregation, support encryption of logs between devices.
  • D. Aggregation mode stores logs and content files and uploads them to another FortiAnalyzer device at a scheduled time.

Answer: B,D


NEW QUESTION # 67
......

NSE5_FAZ-7.0 Certification Exam Dumps Questions in here: https://drive.google.com/open?id=1ksOSKov3snuUEqmivfFWVSJl21owWKU6

Pass Your NSE5_FAZ-7.0 Exam Easily with Accurate PDF Questions: https://www.test4sure.com/NSE5_FAZ-7.0-pass4sure-vce.html