Weekend Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: netbudy65

NSE5_FAZ-7.2 Fortinet NSE 5 - FortiAnalyzer 7.2 Questions and Answers

Questions 4

How do you restrict an administrator’s access to a subset of your organization’s ADOMs?

Options:

A.

Set the ADOM mode toAdvanced

B.

Assign the ADOMs to the administrator’s account

C.

Configure trusted hosts

D.

Assign the defaultSuper_Useradministrator profile

Buy Now
Questions 5

What FortiGate process caches logs when FortiAnalyzer is not reachable?

Options:

A.

logfiled

B.

sqlplugind

C.

oftpd

D.

miglogd

Buy Now
Questions 6

What must you configure on FortiAnalyzer to upload a FortiAnalyzer report to a supported external server?

(Choose two.)

Options:

A.

SFTP, FTP, or SCP server

B.

Mail server

C.

Output profile

D.

Report scheduling

Buy Now
Questions 7

An administrator has moved FortiGate A from the root ADOM to ADOM1.

Which two statements are true regarding logs? (Choose two.)

Options:

A.

Analytics logs will be moved to ADOM1 from the root ADOM automatically.

B.

Archived logs will be moved to ADOM1 from the root ADOM automatically.

C.

Logs will be presented in both ADOMs immediately after the move.

D.

Analytics logs will be moved to ADOM1 from the root ADOM after you rebuild the ADOM1 SQL database.

Buy Now
Questions 8

Which item must you configure on FortiAnalyzer to email generated reports automatically?

Options:

A.

Output profile

B.

Report scheduling

C.

SFTP server

D.

SNMP server

Buy Now
Questions 9

In FortiAnalyzer’s FormView, source and destination IP addresses from FortiGate devices are not resolving to

a hostname. How can you resolve the source and destination IPs, without introducing any additional

performance impact to FortiAnalyzer?

Options:

A.

Configure local DNS servers on FortiAnalyzer

B.

Resolve IPs on FortiGate

C.

Configure # set resolve-ip enable in the system FortiView settings

D.

Resolve IPs on a per-ADOM basis to reduce delay on FortiView while IPs resolve

Buy Now
Questions 10

Which statement about the FortiSOAR management extension is correct?

Options:

A.

It requires a FortiManager configured to manage FortiGate

B.

It requires a dedicated FortiSOAR device or VM.

C.

It does not include a limited trial by default.

D.

It runs as a docker container on FortiAnalyzer

Buy Now
Questions 11

What are two effects of enabling auto-cache in a FortiAnalyzer report? (Choose two.)

Options:

A.

The size of newly generated reports is optimized to conserve disk space.

B.

FortiAnalyzer local cache is used to store generated reports.

C.

When new logs are received, the hard-cache data is updated automatically.

D.

The generation time for reports is decreased.

Buy Now
Questions 12

Which two methods are the most common methods to control and restrict administrative access on FortiAnalyzer? (Choose two.)

Options:

A.

Virtual domains

B.

Administrative access profiles

C.

Trusted hosts

D.

Security Fabric

Buy Now
Questions 13

An administrator has configured the following settings:

config system fortiview settings

set resolve-ip enable

end

What is the significance of executing this command?

Options:

A.

Use this command only if the source IP addresses are not resolved on FortiGate.

B.

It resolves the source and destination IP addresses to a hostname in FortiView on FortiAnalyzer.

C.

You must configure local DNS servers on FortiGate for this command to resolve IP addresses on Forti Analyzer.

D.

It resolves the destination IP address to a hostname in FortiView on FortiAnalyzer.

Buy Now
Questions 14

What is the purpose of output variables?

Options:

A.

To store playbook execution statistics

B.

To use the output of the previous task as the input of the current task

C.

To display details of the connectors used by a playbook

D.

To save all the task settings when a playbook is exported

Buy Now
Questions 15

Refer to the exhibit.

NSE5_FAZ-7.2 Question 15

What does the data point at 14:55 tell you?

Options:

A.

The received rate is almost at its maximum for this device

B.

The sqlplugind daemon is behind in log indexing by two logs

C.

Logs are being dropped

D.

Raw logs are reaching FortiAnalyzer faster than they can be indexed

Buy Now
Questions 16

If you upgrade your FortiAnalyzer firmware, what report elements can be affected?

Options:

A.

Output profiles

B.

Report settings

C.

Report scheduling

D.

Custom datasets

Buy Now
Questions 17

In order for FortiAnalyzer to collect logs from a FortiGate device, what configuration is required? (Choose two.)

Options:

A.

Remote logging must be enabled on FortiGate

B.

Log encryption must be enabled

C.

ADOMs must be enabled

D.

FortiGate must be registered with FortiAnalyzer

Buy Now
Questions 18

Refer to the exhibit.

NSE5_FAZ-7.2 Question 18

Which two statements are true regarding enabling auto-cache on FortiAnalyzer? (Choose two.)

Options:

A.

Report size will be optimized to conserve disk space on FortiAnalyzer.

B.

Reports will be cached in the memory.

C.

This feature is automatically enabled for scheduled reports.

D.

Enabling auto-cache reduces report generation time for reports that require a long time to assemble datasets.

Buy Now
Questions 19

Which two statements are true regarding the outbreak detection service? (Choose two.)

Options:

A.

New alerts are received by email.

B.

Outbreak alerts are available on the root ADOM only.

C.

An additional license is required.

D.

It automatically downloads new event handlers and reports.

Buy Now
Questions 20

You have recently grouped multiple FortiGate devices into a single ADOM.System Settings>Storage Info

shows the quota used.

What does the disk quota refer to?

Options:

A.

The maximum disk utilization for each device in the ADOM

B.

The maximum disk utilization for the FortiAnalyzer model

C.

The maximum disk utilization for the ADOM type

D.

The maximum disk utilization for all devices in the ADOM

Buy Now
Questions 21

Which statement describes a dataset in FortiAnalyzer?

Options:

A.

They determine what data is retrieved from the database.

B.

They provide the layout used for reports.

C.

They are used to set the data included in templates.

D.

They define the chart types to be used in reports.

Buy Now
Questions 22

Which statement is true about sending notifications with incident updates?

Options:

A.

Notifications can be sent only when an incident is updated or deleted.

B.

If you use multiple fabric connectors, all connectors must have the same notification settings

C.

Notifications can be sent only by email.

D.

You can send notifications to multiple external platforms

Buy Now
Questions 23

Which two elements are contained in a system backup created on FortiAnalyzer? (Choose two.)

Options:

A.

System information

B.

Logs from registered devices

C.

Report information

D.

Database snapshot

Buy Now
Questions 24

Which statement about the FortiSIEM management extension is correct?

Options:

A.

Allows you to manage the entire life cycle of a threat or breach.

B.

Its use of the available disk space is capped at 50%.

C.

It requires a licensed FortiSIEM supervisor.

D.

It can be installed as a dedicated VM.

Buy Now
Questions 25

Refer to the exhibit.

NSE5_FAZ-7.2 Question 25

Based on the partial outputs displayed, which devices can be members of a FortiAnalyzer Fabric?

Options:

A.

FortiAnalyzerl and FortiAnalyzer3

B.

FortiAnalyzer1 and FortiAnalyzer2

C.

All devices listed can be members

D.

FortiAnalyzer2 and FortiAnalyzer3

Buy Now
Questions 26

In Log View, you can use the Chart Builder feature to build a dataset and chart based on the filtered search results.

Similarly, which feature you can use for FortiView?

Options:

A.

Export to Report Chart

B.

Export to PDF

C.

Export to Chart Builder

D.

Export to Custom Chart

Buy Now
Questions 27

Which two statements are true regarding FortiAnalyzer log forwarding? (Choose two.)

Options:

A.

Both modes, forwarding and aggregation, support encryption of logs between devices.

B.

In aggregation mode, you can forward logs to syslog and CEF servers as well.

C.

Aggregation mode stores logs and content files and uploads them to another FortiAnalyzer device at a scheduled time.

D.

Forwarding mode forwards logs in real time only to other FortiAnalyzer devices.

Buy Now
Questions 28

Which two statements are true regarding fabric connectors? (Choose two.)

Options:

A.

Configuring fabric connectors to send notification to ITSM platform upon incident creation Is more efficient than third-party information from the FortiAnalyzer API.

B.

Fabric connectors allow to save storage costs and improve redundancy.

C.

Storage connector service does not require a separate license to send logs to cloud platform.

D.

Cloud-Out connections allow you to send real-time logs to pubic cloud accounts like Amazon S3, Azure Blob , and Google Cloud.

Buy Now
Questions 29

Which FortiAnalyzer feature allows you to use a proactive approach when managing your network security?

Options:

A.

Incidents dashboards

B.

Threat hunting

C.

FortiView Monitor

D.

Outbreak alert services

Buy Now
Questions 30

On FortiAnalyzer, what is a wildcard administrator account?

Options:

A.

An account that permits access to members of an LDAP group

B.

An account that allows guest access with read-only privileges

C.

An account that requires two-factor authentication

D.

An account that validates against any user account on a FortiAuthenticator

Buy Now
Questions 31

If a hard disk fails on a FortiAnalyzer that supports software RAID, what should you do to bring the

FortiAnalyzer back to functioning normally, without losing data?

Options:

A.

Hot swap the disk

B.

Replace the disk and rebuild the RAID manually

C.

Take no action if the RAID level supports a failed disk

D.

Shut down FortiAnalyzer and replace the disk

Buy Now
Questions 32

Which two actions should an administrator take to view Compromised Hosts on FortiAnalyzer? (Choose two.)

Options:

A.

Enable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent to FortiAnalyzer.

B.

Make sure all endpoints are reachable by FortiAnalyzer.

C.

Enable device detection on an interface on the FortiGate devices that are connected to the FortiAnalyzer device.

D.

Subscribe FortiAnalyzer to FortiGuard to keep its local threat database up to date.

Buy Now
Questions 33

Refer to the exhibit.

NSE5_FAZ-7.2 Question 33

What is the purpose of using the Chart Builder feature on FortiAnalyzer?

Options:

A.

In Log View, this feature allows you to build a dataset and chart automatically, based on the filtered search results.

B.

In Log View, this feature allows you to build a chart and chart automatically, on the top 100 log entries.

C.

This feature allows you to build a chart under FortiView.

D.

You can add charts to generated reports using this feature.

Buy Now
Questions 34

Why run the command diagnose sql status sqlplugind?

Options:

A.

To list the current SQL processes running

B.

To check what is the database log insertion status

C.

To display the SOL query connections and hcache status

D.

To view the current hcache size

Buy Now
Questions 35

What purposes does the auto-cache setting on reports serve? (Choose two.)

Options:

A.

To reduce report generation time

B.

To automatically update the hcache when new logs arrive

C.

To reduce the log insert lag rate

D.

To provide diagnostics on report generation time

Buy Now
Questions 36

For which two purposes would you use the commandset log checksum? (Choose two.)

Options:

A.

To help protect against man-in-the-middle attacks during log upload from FortiAnalyzer to an SFTP server

B.

To prevent log modification or tampering

C.

To encrypt log communications

D.

To send an identical set of logs to a second logging server

Buy Now
Questions 37

Logs are being deleted from one of your ADOMs earlier that the configured setting for archiving in your data policy. What is the most likely problem?

Options:

A.

The total disk space is insufficient and you need to add other disk.

B.

CPU resources are too high.

C.

The ADOM disk quota is set too low based on log rates.

D.

Logs in that ADOM are being forwarded in real-time to another FortiAnalyzer device.

Buy Now
Questions 38

What are the operating modes of FortiAnalyzer? (Choose two)

Options:

A.

Standalone

B.

Manager

C.

Analyzer

D.

Collector

Buy Now
Questions 39

An administrator has moved FortiGate A from the root ADOM to ADOM1. However, the administrator is not able to generate reports for FortiGate A in ADOM1.

What should the administrator do to solve this issue?

Options:

A.

Use the execute sql-local rebuild-db command to rebuild all ADOM databases.

B.

Use the execute sql-local rebuild-adom ADOM1 command to rebuild the ADOM database.

C.

Use the execute sql-report run ADOM1 command to run a report.

D.

Use the execute sql-local rebuild-adom root command to rebuild the ADOM database.

Buy Now
Questions 40

Refer to the exhibit.

NSE5_FAZ-7.2 Question 40

What does the data point at 12:20 indicate?

Options:

A.

The performance of FortiAnalyzer is below the baseline.

B.

FortiAnalyzer is using its cache to avoid dropping logs.

C.

The log insert lag time is increasing.

D.

The sqlplugind service is caught up with new logs.

Buy Now
Questions 41

Which two statements are true regarding FortiAnalyzer operating modes? (Choose two.)

Options:

A.

When in collector mode, FortiAnalyzer collects logs from multiple devices and forwards these logs in the original binary format.

B.

Collector mode is the default operating mode.

C.

When in collector mode. FortiAnalyzer supports event management and reporting features.

D.

By deploying different FortiAnalyzer devices with collector and analyzer mode in a network, you can improve the overall performance of log receiving, analysis, and reporting

Buy Now
Exam Code: NSE5_FAZ-7.2
Exam Name: Fortinet NSE 5 - FortiAnalyzer 7.2
Last Update: Oct 16, 2025
Questions: 137

PDF + Testing Engine

$134.99

Testing Engine

$99.99

PDF (Q&A)

$84.99