Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

NSE5_FAZ-7.2

Total questions: 37

Worksheet time: 21mins

Name
Class
Date
1.

Which statement about sending notifications with incident updates is true?

a)

 Notifications can be sent only when an incident is created or deleted.

b)

You must configure an output profile to send notifications by email.

c)

Each incident can send notifications to a single external platform.

d)

Each connector used can have different notification settings.

2.

Why must you wait for several minutes before you run a playbook that you just created?

a)

 FortiAnalyzer needs that time to back up the current playbooks.

b)

FortiAnalyzer needs that time to parse the new playbook

c)

FortiAnalyzer needs that time to ensure there are no other playbooks running.

d)

FortiAnalyzer needs that time to debug the new playbook.

3.

How can you attach a report to an incident?

a)

By attaching it to an event handler alert

b)

By editing the settings of the desired report

c)

From the properties of an existing incident

d)

Saving it in JSON format, and then importing it

4.

Which statement is correct regarding the event displayed?

a)

 The security event risk is considered open.

b)

The security risk was blocked or dropped

c)

The risk source is isolated.

d)

An incident was created from this event.

5.

What happens when the IOC breach detection engine on FortiAnalyzer finds web logs that match a blocklisted IP address?

a)

FortiAnalyzer flags the associated host for further analysis.

b)

The endpoint is marked as Compromised and, optionally, can be put in quarantine.

c)

A new Infected entry is added for the corresponding endpoint.

d)

The detection engine classifies those logs as Suspicious.

6.

Which two methods can you use to send notifications when an event occurs that matches a configured event handler? (Choose two.)

a)

Send Alert through Fabric Connectors

b)

Send Alert through FortiSIEM MEA

c)

Send SNMP trap

d)

Send SMS notification

7.

Why run the command diagnose sql status sqlplugind?

a)

To list the current SQL processes running

b)

 To check what is the database log insertion status 

c)

To display the SQL query connections and hcache status

d)

To view the current hcache size

8.

What are two benefits of using fabric connectors? (Choose two.)

a)

They allow FortiAnalyzer to send logs in real-time to public cloud accounts.

b)

You do not need an additional license to send logs to the cloud platform.

c)

Fabric connectors allow you to improve redundancy.

d)

Using fabric connectors is more efficient than using third-party polling with API.

9.

Which statement correctly describes the management extensions available on FortiAnalyzer?

a)

Management extensions do not require additional licenses.

b)

Management extensions may require a minimum number of CPU cores to run

c)

Management extensions allow FortiAnalyzer to act as a FortiSIEM supervisor.

d)

Management extensions require a dedicated VM for best performance.

10.

Which statement describes a dataset in FortiAnalyzer?

a)

They determine what data is retrieved from the database.

b)

They provide the layout used for reports.

c)

They are used to set the data included in templates.

d)

They define the chart types to be used in reports.

11.

Which statement is correct regarding the event displayed?

a)

The security risk was blocked or dropped.

b)

The security event risk is considered open

c)

The risk source is isolated.

d)

An incident was created from this event.

12.

Which statement describes archive logs on FortiAnalyzer?

a)

Logs compressed and saved in files with the .gz extension

b)

Logs a FortiAnalyzer administrator can access in FortiView

c)

Logs previously collected from devices that are offline

d)

Logs that are indexed and stored in the SQL database

13.

Which two actions should an administrator take to view Compromised Hosts on FortiAnalyzer? (Choose two.)

a)

Enable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent to FortiAnalyzer.

b)

Subscribe FortiAnalyzer to FortiGuard to keep its local threat database up to date.

c)

Make sure all endpoints are reachable by FortiAnalyzer.

d)

Enable device detection on the FortiGate devices that are sending logs to FortiAnalyzer.

14.

Which item must you configure on FortiAnalyzer to email generated reports automatically?

a)

Report scheduling

b)

Output profile

c)

SFTP server

d)

SNMP server

15.

You created a playbook on FortiAnalyzer that uses a FortiOS connector.
When configuring the FortiGate side, which type of trigger must be used so that the actions in an automation stitch are available in the FortiOS connector?

a)

FortiAnalyzer Event Handler

b)

Fabric Connector event

c)

Incoming webhook

d)

 FortiOS Event Log

16.

In Log View, you can use the Chart Builder feature to build a dataset and chart based on the filtered search results.

Similarly, which feature can you use for FortiView?

a)

Export to Chart Library

b)

Export to Custom Chart

c)

Export to Chart Builder

d)

Export to Report Chart

17.

An administrator has configured the following settings:
config system fortiview setting
set resolve-ip enable
end
What is the significance of running this command?

a)

 Use this command only if the source IP addresses are not resolved on FortiGate.

b)

 It resolves the source and destination IP addresses to a hostname in FortiView on FortiAnalyzer.

c)

It resolves the destination IP address to a hostname in FortiView on FortiAnalyzer.

d)

You must configure local DNS servers on FortiGate for this command to resolve IP addresses on FortiAnalyzer.

18.

What is the purpose of output variables?

a)

To store playbook execution statistics

b)

To save all the task settings when a playbook is exported

c)

To display details of the connectors used by a playbook

d)

To use the output of the previous task as the input of the current task

19.

Which two statements are true regarding the outbreak detection service? (Choose two.)

a)

Outbreak alerts are available on the root ADOM only.

b)

New alerts are received by email.

c)

 It automatically downloads new event handlers and reports.

d)

An additional license is required

20.

A playbook contains five tasks in total. An administrator runs the playbook and four out of five tasks finish successfully, but one task fails.
What will be the status of the playbook after it is run?

a)

Running

b)

Failed

c)

Upstream_failed

d)

Success

21.

Which log will generate an event with the status Contained?

a)

An IPS log with action=pass.

b)

AWebFilter log with action=dropped.

c)

An AV log with action=quarantine.

d)

An AppControl log with action=blocked.

22.

Laptop1 is used by several administrators to manage FortiAnalyzer. You want to configure a generic text filter that matches all login attempts to the web interface generated by any user other than “admin?, and coming from Laptop1.

Which filter will achieve the desired result?

a)

operation-login & dstip==10.1.1.210 & user!-admin

b)

operation-login & sreip==10.1.1.100 & dstip==10.1.1.210 & user==admin

c)

operation-login & performed_on=="GUI(10.1.1.210)" & user!=admin

d)

operation-login & performed_on=="GUI(10.1.1.100)" & user!=admin

23.

What are two advantages of grouping similar reports? (Choose two.)

a)

Reduces the number of hcache tables and improves auto-hcache completion time

b)

Conserves disk space on FortiAnalyzer by grouping multiple similar reports

c)

Improves report completion time

d)

Provides a better summary of reports

24.

Which statement describes online logs on FortiAnalyzer?

a)

Logs that reached a specific size and were rolled over

b)

Logs that can be used to create reports

c)

Logs that can be viewed using Log Browse

d)

Logs that are saved to disk, compressed, and available in FortiView

25.

After generating a report, you notice the information you were expecting to see is not included in it.

What are two possible reasons for this scenario? (Choose two.)

a)

You enabled auto-cache with extended log filtering.

b)

The logfiled service has not indexed all the expected logs.

c)

The logs were overwritten by the data retention policy.

d)

The time frame selected in the report is wrong.

26.

What is the purpose of predefined report templates on FortiAnalyzer?

a)

they can be customized to meet the needs of the intended audience.

b)

They can be created by saving reports as templates.

c)

They specify the layout used in reports.

d)

They include the data used in reports charts.

27.

Which statement is true about sending notifications with incident updates?

a)

Notifications can be sent only by email.

b)

If you use multiple fabric connectors, all connectors must have the same notification settings.

c)

Notifications can be sent only when an incident is updated or deleted.

d)

You can send notifications to multiple external platforms.

28.

Which FortiAnalyzer feature allows you to use a proactive approach when managing your network security?

a)

Outbreak alert services

b)

FortiView Monitor

c)

Threat hunting

d)

Incidents dashboard

29.

What is the purpose of using the Chart Builder feature on FortiAnalyzer?

a)

 To add a new chart under FortiView to be used in new reports

b)

 To build a dataset and chart automatically, based on the filtered search results

c)

To add charts directly to generate reports in the current ADOM

d)

To build a chart automatically based on the top 100 log entries

30.

You are looking for a playbook that was exported by a junior administrator. You perform a search and find the files listed below.

Which file will perform an import operation?

a)

Exported_playbook.json

b)

Exported_playbook.csv

c)

Exported_playbook.txt

d)

Exported_playbook.sql

31.

Which two statements are true regarding log fetching on FortiAnalyzer? (Choose two.)

a)

 Log fetching can be done only on two FortiAnalyzer devices that are running the same firmware version

b)

Log fetching allows the administrator to run queries and reports against historical data by retrieving archived logs from one FortiAnalyzer device and sending them to another FortiAnalyzer device

c)

A FortiAnalyzer device can perform either the fetch server or client role, and it can perform two roles at the same time with the same FortiAnalyzer devices at the other end.

d)

 Log fetching allows the administrator to fetch analytics logs from another FortiAnalyzer for redundancy.

32.

Which two statements are correct regarding the export and import of playbooks? (Choose two.)

a)

 You can import a playbook even if there is another one with the same name in the destination

b)

You can export only one playbook at a time.

c)

A playbook that was disabled when it was exported will be disabled when it is imported

d)

Playbooks can be exported and imported only within the same FortiAnalyzer device.

33.

What are two effects of enabling auto-cache in a FortiAnalyzer report? (Choose two.)

a)

The size of newly generated reports is optimized to conserve disk space.

b)

FortiAnalyzer local cache is used to store generated reports.

c)

The generation time for reports is decreased

d)

When new logs are received, the hard-cache data is updated automatically.

34.

Which two statements about a FortiAnalyzer Fabric are true? (Choose two.)

a)

Fabric members must be in the same time zone as the supervisor.

b)

Fabric members and the supervisor support HA.

c)

All fabric members must run in collector mode except the supervisor.

d)

The supervisor can access the logs in the fabric members using an API.

35.

Which statement about the FortiSOAR management extension is correct?

a)

It requires a FortiManager configured to manage FortiGate.

b)

It requires a dedicated FortiSOAR device or VM.

c)

It does not include a limited trial by default.

d)

 It runs as a docker container on FortiAnalyzer.

36.

What must you consider when using log fetching? (Choose two.)

a)

The fetch client can retrieve logs from devices that are not added to its local Device Manager.

b)

You can use filters to include only logs from a single device

c)

The fetching profile must include a user with the Super_User profile.

d)

The archive logs retrieved from the server become archive logs in the client

37.

What is the purpose of using prefilters when configuring event handlers?

a)

 They limit which logs are checked for matches by the other filters.

b)

They can filter the logs before they are processed by FortiAnalyzer.

c)

They download new filters to be used in event handlers.

d)

They are common filters applied simultaneously to all event handlers.