Search Header Logo

NSE5_FAZ-7.2

Authored by David Peña

Instructional Technology

Professional Development

Used 5+ times

NSE5_FAZ-7.2
AI

AI Actions

Add similar questions

Adjust reading levels

Convert to real-world scenario

Translate activity

More...

    Content View

    Student View

37 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which statement about sending notifications with incident updates is true?

 Notifications can be sent only when an incident is created or deleted.

You must configure an output profile to send notifications by email.

Each incident can send notifications to a single external platform.

Each connector used can have different notification settings.

2.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Why must you wait for several minutes before you run a playbook that you just created?

 FortiAnalyzer needs that time to back up the current playbooks.

FortiAnalyzer needs that time to parse the new playbook

FortiAnalyzer needs that time to ensure there are no other playbooks running.

FortiAnalyzer needs that time to debug the new playbook.

3.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

How can you attach a report to an incident?

By attaching it to an event handler alert

By editing the settings of the desired report

From the properties of an existing incident

Saving it in JSON format, and then importing it

4.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Media Image

Which statement is correct regarding the event displayed?

 The security event risk is considered open.

The security risk was blocked or dropped

The risk source is isolated.

An incident was created from this event.

5.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

What happens when the IOC breach detection engine on FortiAnalyzer finds web logs that match a blocklisted IP address?

FortiAnalyzer flags the associated host for further analysis.

The endpoint is marked as Compromised and, optionally, can be put in quarantine.

A new Infected entry is added for the corresponding endpoint.

The detection engine classifies those logs as Suspicious.

6.

MULTIPLE SELECT QUESTION

45 sec • 1 pt

Which two methods can you use to send notifications when an event occurs that matches a configured event handler? (Choose two.)

Send Alert through Fabric Connectors

Send Alert through FortiSIEM MEA

Send SNMP trap

Send SMS notification

7.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Why run the command diagnose sql status sqlplugind?

To list the current SQL processes running

 To check what is the database log insertion status 

To display the SQL query connections and hcache status

To view the current hcache size

Access all questions and much more by creating a free account

Create resources

Host any resource

Get auto-graded reports

Google

Continue with Google

Email

Continue with Email

Classlink

Continue with Classlink

Clever

Continue with Clever

or continue with

Microsoft

Microsoft

Apple

Apple

Others

Others

Already have an account?