Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Prueba 2

Total questions: 60

Worksheet time: 30mins

Name
Class
Date
1.
By default, what happens when a log file reaches its maximum file size?
a)
FortiAnalyzer forwards logs to syslog.
b)
FortiAnalyzer overwrites the log files.
c)
FortiAnalyzer rolls the active log by renaming the file.
d)
FortiAnalyzer stops logging.
2.
Why should you use an NTP server on FortiAnalyzer and all registered devices that log into FortiAnalyzer?
a)
To properly correlate logs.
b)
To use real-time forwarding.
c)
To resolve host names.
d)
To improve DNS response times.
3.
Which two statements are true regarding FortiAnalyzer log forwarding?
a)
Both modes, forwarding and aggregation, support encryption of logs between devices.
b)
In aggregation mode, you can forward logs to syslog and CEF servers as well.
c)
Aggregation mode stores logs and content files and uploads them to another FortiAnalyzer device at a schedule time.
d)
Forwarding mode forwards logs in real time only to other FortiAnalyzer devices.
4.

What are two advantages of setting up fabric ADOM? (Choose two.)

a)
It can be used for fast data processing and log correlation.
b)
It can be used to facilitate communicating between devices in same Security Fabric.
c)
It can include all Fortinet devices that are part of the same Security Fabric.
d)
It can include only FortiGate devices that are part of the same Security Fabric.
5.
What remote authentication servers can you configure to validate your FortiAnalyzer administrator logons? (Choose three.)
a)
Local.
b)
TACACS+.
c)
PKI.
d)
LDAP.
e)
RADIUS.
6.
You are using RAID with a FortiAnalyzer that supports software RAID, and one of the hard disk on FortiAnalyzer has failed. What is the recommended method to replace the disk?
a)
Shut down FortiAnalyzer and then replace the disk.
b)
Downgrade your RAID level, replace the disk, and then upgrade your RAID level.
c)
Clear all RAID alarms and replace the disk while ForitAnalyzer is still running.
d)
Perform a hot swap.
7.
Which clause is considered mandatory in SELECT statements used by the FortiAnalyzer to generate reports?
a)
WHERE
b)
ORDER BY
c)
LIMIT
d)
FROM
8.
Refer to the exhibit. Which image corresponds to the packet captured show in the exhibit?
a)
A
b)
B
c)
C
d)
D (Real time in red)
9.
What is the purpose of output variables?
a)
To store playbook execution statistics.
b)
To use the output of the previous task as the input of the current task.
c)
To display details of the connectors used by a playbook.
d)
To save all the task settings when a playbook is exported.
10.
Which log type does the FortiAnalyzer indicators of compromise feature use to identify infected host?
a)
IPS logs.
b)
Antivirus logs.
c)
Web filter logs.
d)
Application control logs.
11.
How can you configure FortiAnalyzer to permit administrator logins from only specific locations?
a)
Use static routes.
b)
Use administratives profiles.
c)
Use trusted hosts.
d)
Use secure protocols.
12.
Which two elemets are contained in a system backup created on FortiAnalyzer? (Choose two.)
a)
System information.
b)
Logs from registered devices.
c)
Report information.
d)
Database snapshot.
13.
In FortiAnalyzer's FormView, source and destination IP addresses from FortiGate devices are not resolving to a hostname. How can you resolve the source and destinations IPs, without introducing any additional perfomance?
a)
Resolve IPs on a per-ADOM basis to reduce delay on FortiView while IPs resolve.
b)
Configure # set resolve-ip enable in the system FortiView settings.
c)
Configure local DNS servers on FortiAnalyzer.
d)
Resolve IPs on Fortigate.
14.
When working with FortiAnalyzer reports, what is the purpose of a dataset?
a)
To set the data included in templates.
b)
To retrieve data from the database.
c)
To provide the layout used for reports.
d)
To define the chart type to be used.
15.
What are offline logs on FortiAnalyzer?
a)
Logs that are collected from offline devices after they boot up.
b)
Logs that are indexed and stored in the SQL database.
c)
When you restart FortiAnalyzer, all stored logs are considered to be offline logs.
d)
Compressed logs, which are also known as archive logs, are considered to be offline logs.
16.
What statements are true regarding the "store and upload" log transfer option between FortiAnalyzer and FortiGate? (Choose three.)
a)
Disk logging is enable by default on the FortiGate.
b)
Both secure communications methods (SSL and IPsec) allow the store and upload option.
c)
Disk logging is enabled on the FortiGate through the CLI only.
d)
All FortiGates can send logs to FortiAnalyzer using the store and upload option.
e)
Only FortiGate models with hard disks can send logs to FortiAnalyzer using the store and upload option.
17.
Refer to the exhibit. Which statement is correct regarding the event displayed?
a)
The security risk was blocked or dropped.
b)
The security event risk is considered open.
c)
An incident was created from this event.
d)
The risk source is isolated.
18.
In order for FotriAnalyzer to collect logs from a FortiGate device, what configuration is required? (Choose two.)
a)
Remote logging must be enable on FortiGate.
b)
Log encryption must be enabled.
c)
ADOMs must be enabled.
d)
FortiGate must be registered with FortiAnalyzer.
19.
An administrator has moved FortiGate A from the root ADOM to ADOM1. Which two statements are true regarding logs? (Choose two.)
a)
Logs will be presented in both ADOMs immediately after the move.
b)
Analytics logs will be moved to ADOM1 from the root ADOM after you rebuild the ADOM1 SQL databse.
c)
Archived logs will be moved to ADOM1 from the root ADOM automatically.
d)
Analytics logs will be move to ADOM1 from the root ADOM automatically.
20.
FortiAnalyzer reports are dropping analytical data from 15 days ago, even though the data policy setting for analytics logs is 60 days. What is the most likely problem?
a)
Quota enforcement is acting on analytical data before a report is complete.
b)
CPU resources are too high.
c)
Disk utilization for archive logs is set for 15 days.
d)
Logs are rolling before the report is run.
21.
View the exhibit. Why is the total quota less than the total system storage?
a)
3.6% of the system storage is already being used.
b)
Some space is reserved for system use, such as storage of compression files, upload files, and temporary report files.
c)
The oftpd process has not archived the logs yet.
d)
The logfiled process is just estimating the total quota.
22.
What does the disk status Degraded mean for RAID management?
a)
One or more drives are missing from the FortiAnalyzer unit. The drive is no longer available to the operating system.
b)
The FortiAnalyzer device is writing data to newly added hard drive in order to restore the hard drive to an optimal state.
c)
The hard driveils no longer being used by the RAID controller.
d)
The FortiAnalyzer device is writing to all the hard drives on the device in order to make the array fault tolerant.
23.
Refer to the exhibit. What is the purpose of using the Chart Builder feature on FortiAnalyzer?
a)
In Log View, this feature allows you to build a chart automatically, on the top 100 log entries.
b)
In Log View, this feature allows you to build a dataset and chart automatically, based on the filtered search results.
c)
This feature allows you to build a a chart under FortiView.
d)
You can add charts to generated reports using this feature.
24.
What are two benefits of using fabric connectors? (Choose two.)
a)
Using fabric connectors is more efficient than using third-party polling with API.
b)

They allow FortiAnalyzer to send logs in real-time to public cloud accounts.

c)
You do not need an additional license to send logs to the cloud platform.
d)
Fabric connectors allow you to improve redundancy.
25.
If the primary FortiAnalyzer in an HA cluster fails, how is the new primary elected?
a)
The configured IP address is checked first.
b)
The active port number is checked first.
c)
The firmware version is checked first.
d)
The configured priority is checked first.
26.
Refer to the exhibit. What is the purpose of using Chart Builder feature on FortiAnalyzer?
a)
To build a dataset and chart automatically, based on the filtered search results.
b)
To build a chart automatically based on the top 100 log entries.
c)
To add a new chart under FortiView to be used in new reports.
d)
To add charts directly to generate reports in the current ADOM.
27.
An administrator has moved FortiGate A from the root ADOM to ADOM1. However the administrator is not able to generate reports for FortiGate A in ADOM1. What should the administrator do to solve this issue?
a)
Use the execute sql-report run ADOM1 command to run a report.
b)
Use the execute sql-local rebuild-db command to rebuild all ADOM databases.
c)
Use the execute sql-local rebuild-adom root command to rebuild the ADOM database.
d)
Use the execute sql-local rebuild-adom ADOM1 command to rebuild the ADOM database.
28.
You crested a playbook on FortiAnalyzer that uses a FortiOS connector. When configuring the FortiGate side, which type of trigger must be used so that the actions in an automation stitch are available in the FortiOS connector?
a)
FortiAnalyzer Event Handler.
b)
Incoming webhook.
c)
FortiOS Event Log.
d)
Fabric Connector event.
29.

You have recently grouped multiple FortiGate devices into a single ADOM.System Settings > Storage Info show the quota used. What does the disk quota refer to?

a)
The maximum disk utilization for all devices in the ADOM.
b)
The maximun disk utilization for the FortiAnalyzer model.
c)
The maximum disk utilization for the ADOM type.
d)
The maximum disk utilization for each device in the ADOM.
30.
An administrator fortinet, is able to view logs and perform device management tasks, such as adding and removing registered devices. However, administrator fortinet is not able to create a mail server that can used to send emails. What could be the problem?
a)
Fortinet is assigned the Standard_User administrator profile.
b)
A trusted host is configured.
c)
ADOM mode is configured with Advanced mode.
d)
Fortinet is assigned the Restricted_User administrator profile.
31.
What must you consider when using log fetching? (Choose two.)
a)
The fetching profile must include a user with the Super_User profile.
b)
You can use filters to include only logs from a single device.
c)
The fetch client can retrieve logs from devices that are not added to its local Device Manager.
d)
The archive logs retrieved from the server become archive logs in the client.
32.
For proper log correlation between the logging devices and FortiAnalyzer and all registered devices should:
a)
Use real-time forwarding.
b)
Use an NTP server.
c)
Use DNS.
d)
Use host name resolution.
33.
Refer to the exhibit. Based on the partial outputs displayed, which devices can be members of a FortiAnalyzer Fabric?
a)
All devices listed can be members.
b)

FortiAnalyzer1 and FortiAnalyzer3.

c)
FortiAnalyzer2 and FortiAnalyzer3.
d)
FortiAnalyzer1 and FortiAnalyzer2.
34.
Refer to the exhibit. Which two statements are true regarding enabling auto-cache on FortiAnalyzer? (Choose two.)
a)
Report size will be optimized to conserve disk space on FortiAnalyzer.
b)
Reports will be cached in the memory.
c)
This feature is automatically enabled for scheduled reports.
d)
Enabling auto-cache reduces report generation time for reports that require a long time to assemble datasets.
35.
Which FortiAnalyzer feature allows you to use a proactive approach when managing your network security?
a)
Incidents dashboards.
b)
Threat hunting.
c)
FortiView Monitor.
d)
Outbreak alert services.
36.
Which daemon is responsible for enforcing raw log file size?
a)
miglogd
b)
oftpd
c)
logfiled
d)
sqlplugind
37.
What is the purpose of the following CLI command?
a)
To add a log file checksum.
b)
To add the MD's hash value and authentication code.
c)
To add a unique tag to each log to prove that it came from this FortiAnalyzer.
d)
To encrypt log communications.
38.
Which two statement are true regardless initial Logs sync and Log Data Sync for Ha on FortiAnalyzer?
a)
With initial Logs Sync, when you add a unit to an HA cluster, the primary device synchronizes its logs with the backup device.
b)
By default, Log Data Sync is disabled on all backup devise.
c)
When Logs Data Sync is turned one, the backup device will reboot and then rebuilt the log database with the synchronized logs.
d)
Log Data Sync provides real-time log synchronization to all backup devices.
39.
Which statements are true regarding securing communications between FortiAnalyzer and FortGate with SSL? (Choose two.)
a)
SSL is the default setting.
b)
FortiAnalyzer encryption level must be equal to, or higher than, FortiGate.
c)
SSL can send logs in real-time only.
d)
SSL communications are auto-negotiated between the two devices.
e)
SSL encryption levels are globally set FortiAnalyzer.
40.
On FortiAnalyzer, what is a wildcard administrator account?
a)
An account that permits access to members of an LDAP group.
b)
An account that allows guest access with read-only privileges.
c)
An account that requires two-factor authentication.
d)
An account that validates against any user account on a FortiAuthenticator.
41.
What is required to authorize a FortiGate on FotiAnalyzer using Fabric authorization?
a)
A FortiGate ADOM.
b)
The FortiGate serial number.
c)
A pre-shared key.
d)
Valid FortiAnalyzer credentials.
42.
What FortiGate process caches logs when FortiAnalyzer is not reachable?
a)
miglogd
b)
oftpd
c)
logfiled
d)
sqlplugind
43.
In the FortiAnalyzer FortiView, source and destination IP addresses from FortiGate devices are not resolving to a hostname. How can you resolve the source and destination IP addresses, without introducing any additional performance impact to FortiAnalyzer?
a)
Resolve IP addresses on a per-ADOM basis to reduce delay on FortiView while IPs resolve.
b)
Configure #set resolve-ip enablein the system FortiView settings.
c)
Configure local DNS servers on FortiAnalyzer.
d)
Resolve IP addresses on FortiGate.
44.
How can you attach a report to an incident?
a)
By editing the settings of the desired report.
b)
From the properties of an existing incident.
c)
By attaching it to an event handler alert.
d)
Saving it in JSON format, and then importing it.
45.
What happens when a log file saved on FortiAnalyzer disk reaches the size specified in the device log settings?
a)
The log file rolls over and is archived.
b)
The log file is purged from the database.
c)
The log file is overwritten.
d)
The log file is stored as a raw log and is available for analytic support.
46.
View the exhibit. What does 1000MB maximum for disk utilization refer to?
a)
The disk quote for the FortiAnalyzer model.
b)
The disk quota for all device in the ADOM.
c)
The disk quota for each device in the ADOM.
d)
The disk quota for the ADOM type.
47.
For which two SAML roles can the FortiAnalyzer be configured? (Choose two.)
a)
Service provider.
b)
Identity collector.
c)
Principal.
d)
Identity provider.
48.
Which tabs do not appear when FortiAnalyzer is operating in Collector mode?
a)
FortiView.
b)
Device Manger.
c)
Event Management.
d)
Reporting.
49.
Why must you wait for several minutes before you run a playbook that you just created?
a)
FortiAnalyzer needs that time to parse the new playbook.
b)
FortyAnalyzer needs that time to ensure there are no other playbooks running.
c)
FortiAnalyzer needs that time to back up the current playbooks.
d)
FortiAnalyzer needs that time to debug the new playbook.
50.
Refer the exhibit. The exhibit shows "remoteservergroup" is an authentication server group with LDAP and RADIUS servers. Which two statements express the significance of enabling "Match all users on remote server" when configuring a new administrator? (Choose two.)
a)
Administrator can log in to FortiAnalyzer using their credentials on remote servers LDAP and RADIUS.
b)
It allows administrators to use two-factor authentication.
c)
Use remote admin from LDAP and RADIUS servers will be able to log in to FortiAnalyzer at anytime.
d)
It creates a wildcard administrator using LDAP and RADIUS servers.
51.
Refer the exhibits. How many events will be added to the incident created after running this playbook?
a)
Five events will be added.
b)
Thirteen events will be added.
c)
No events will be added.
d)
Ten events will be added.
52.
What must you configure on FortyAnalyzer to upload a FortiAnalyzer report to a supported external server? (Choose two.)
a)
SFTP, FTP, or SCP server.
b)
Mail server.
c)
Output profile.
d)
Report scheduling.
53.
What statements are true regarding FortiAnalyzer's treatment of high availability (HA) dusters? (Choose two.)
a)
FortiAnalyzer only needs to know (he serial number of the primary device in the cluster-it automatically discovers the other devices.
b)
FortiAnalyzer receives logs from d devices in duster.
c)
FortiAnalyzer distinguishes different devices by their serial number.
d)
FortiAnalyzer receives bgs only from the primary device in the cluster.
54.
What statements are true regarding the "store and upload" log transfer option between FortiAnalyzer and FortiGate? (Choose three.)
a)
Disk logging is enabled by default on the FortiGate.
b)
Both secure communications methods (SSL and IPsec) allow the store and upload option.
c)
Disk logging is enabled on the FortiGate through the CLI only.
d)
All FortiGates can send logs to FortiAnalyzer using the store and upload option.
e)
Only FortiGate models with hard disk can send logs to FortiAnalyzer using the store and upload option.
55.
Which two statements are true regarding ADOM modes? (Choose two.)
a)
In an advanced mode ADOM. you can assign FortiGate VDOMs from a single FortiGate device to multiple FortiAnalyzer ADOMs.
b)
Normal mode is the default ADOM mode.
c)
You can only change ADOM modes through CLI.
d)
In normal mode, the disk quota of the ADOM is fixed and cannot be modified, but in advance mode, the disk quota of the ADOM is flexible because new devices are added to the ADOM.
56.
On the RAID management page, the disk status is listed as Initializing. What does the status Initializing indicate about what the FortiAnalyzer is currently doing?
a)
FortiAnalyzer is ensuring that the parity data of a redundant drive is valid.
b)
FortiAnalyzer is writing data to newly added hard drive to restore it to an optimal state.
c)
FortiAnalyzer is writing to all of its hard drives to make the array fault tolerant.
d)
FortiAnalyzer is functioning normally.
57.
Which two settings must you configure on FortiAnalyzer to allow non-local administrators to authenticate to FortiAnalyzer with any user account in a single LDAP group? (Choose two.)
a)
A remote LDAP server.
b)
A trusted host profile that restrics access to the LDAP group.
c)
A local wildcard administrator account.
d)
An administrator group.
58.
What are two effects of enabling auto-cache in a FortiaAnalyzer report? (Choose two.)
a)
FortiAnalyzer local cache is used to store generated reports.
b)
The generation time for reports is decreased.
c)
When new logs are received, the hard-cache data is updated automatically.
d)
The size of newly generated reports is optimized to conserve disk space.
59.
When you perform a system backup, what does the backup configuration contain? (Choose two.)
a)
Generated reports.
b)
Device list.
c)
Authorized devices logs.
d)
System information.
60.
What is the main purpose of using an NTP server on FortiAnalyzer and all of its registered devices?
a)
Real-time forwarding.
b)
Log collection.
c)
Host name resolution.
d)
Log correlation.