Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: best70

FCP_FAZ_AN-7.6 Fortinet NSE 5 - FortiAnalyzer 7.6 Analyst Questions and Answers

Questions 4

Exhibit.

FCP_FAZ_AN-7.6 Question 4

What can you conclude from this output?

Options:

A.

There is no disk quota allocated to quarantining files.

B.

FGT_B is the Security Fabric root.

C.

The allocated disk quota to ADOM1 is 3 GB.

D.

Archive logs are using more space than analytic logs.

Buy Now
Questions 5

After generating a report, you notice the information you were expecting to see is not included in it. However, you confirm that the logs are there.

Options:

A.

Check the time frame covered by the report.

B.

Disable auto-cache.

C.

Increase the report utilization quota.

D.

Test the dataset

Buy Now
Questions 6

Which three types of logs does FortiAnalyzer collect from FortiGate devices for normalization? (Choose three.)

Options:

A.

Security

B.

Event

C.

Traffic

D.

Firewall

E.

System

Buy Now
Questions 7

When managing incidents on FortiAnalyzer, what must an analyst be aware of?

Options:

A.

You can manually attach generated reports to incidents.

B.

The status of the incident is always linked to the status of the attached event.

C.

Severity incidents rated with the level High have an initial service-level agreement (SLA) response time of 1 hour.

D.

Incidents must be acknowledged before they can be analyzed.

Buy Now
Questions 8

Which two modules can be imported and exported between ADOMs on FortiAnalyzer? (Choose two.)

Options:

A.

Templates

B.

Reports

C.

Charts

D.

Datasets

Buy Now
Questions 9

Refer to the exhibit.

FCP_FAZ_AN-7.6 Question 9

What conclusion can you draw from the exhibit?

Options:

A.

These are application control logs from FortiGate

B.

Social networking websites are being allowed

C.

Unrated websites are being blocked.

D.

This is a custom view that was set by the analyst

Buy Now
Questions 10

Which two statements about exporting and importing playbooks are true? (Choose two.)

Options:

A.

A playbook that was disabled when it was exported will be disabled when it is imported.

B.

Playbooks can be imported to a different FortiAnalyzer device, but only if the connectors already exist

C.

You can import a playbook even if there is another one with the same name in the destination

D.

You can export only one playbook at a time.

Buy Now
Questions 11

(Refer to the exhibit.

FCP_FAZ_AN-7.6 Question 11

Which two observations can you make after reviewing this log entry? (Choose two answers)

Options:

A.

This is a normalized log.

B.

This is a formatted view of the log.

C.

This is the original log that FortiAnalyzer received from FortiGate.

D.

This log is in a raw log format.

Buy Now
Questions 12

An administrator on your team has configured multiple reports to run periodically. Management has an additional request that all new generated reports be sent to a company email inbox for accessibility. The mail server has already been configured on FortiAnalyzer.

Which item must configure on FortiAnalyzer so that emails are sent when the reports are generated?

Options:

A.

Enable the option to email all reports under the mail server.

B.

Add a mailto: < email address > option within the report layouts.

C.

Enable email notification under the report calendar.

D.

Enable an output profile on the reports.

Buy Now
Questions 13

Exhibit.

FCP_FAZ_AN-7.6 Question 13

What is the purpose of using the Chart Builder feature on FortiAnalyzer?

Options:

A.

To build a chart automatically based on the top 100 log entries

B.

To add charts directly to generate reports in the current ADOM.

C.

To add a new chart under FortiView to be used in new reports

D.

To build a dataset and chart based on the filtered search results

Buy Now
Questions 14

Which statement describes archive logs on FortiAnalyzer?

Options:

A.

Logs that are indexed and stored in the SQL database

B.

Logs a FortiAnalyzer administrator can access in FortiView

C.

Logs compressed and saved in files with the .gz extension

D.

Logs previously collected from devices that are offline

Buy Now
Questions 15

Which two statements about playbook execution are true? (Choose two.)

Options:

A.

FortiAnalyzer will not commit changes made by a Failed playbook

B.

The Playbook Monitor provides troubleshooting logs

C.

You can run the default debugging playbook to investigate playbook errors.

D.

Even if the playbook status is Failed, individual tasks may have succeeded.

Buy Now
Questions 16

Refer to Exhibit:

FCP_FAZ_AN-7.6 Question 16

Client-1 is trying to access the internet for web browsing.

All FortiGate devices in the topology are part of a Security Fabric with logging to FortiAnalyzer configured. All firewall policies have logging enabled. All web filter profiles are configured to log only violations.

Which statement about the logging behavior for this specific traffic flow is true?

Options:

A.

Only FGT-B will create traffic logs.

B.

FGT-B will see the MAC address of FGT-A as the destination and notifies FGT-A to log this flow.

C.

FGT B will create traffic logs and will create web filter logs if it detects a violation.

D.

Only FGT-A will create web filter logs if it detects a violation.

Buy Now
Questions 17

Which log will generate an event with the status Contained?

Options:

A.

An AV log with action=quarantine.

B.

An IPS log with action=pass.

C.

A WebFilter log with action=dropped.

D.

An AppControl log with action=blocked.

Buy Now
Questions 18

Exhibit.

FCP_FAZ_AN-7.6 Question 18

What does the data point at 12:20 indicate?

Options:

A.

The log insert log time is increasing.

B.

FortiAnalyzer is using its cache to avoid dropping logs.

C.

The performance of FortiAnalyzer is below the baseline.

D.

The sqiplugind service is caught up with the logs

Buy Now
Questions 19

(Refer to the exhibit.

FCP_FAZ_AN-7.6 Question 19

Which statement about the displayed event is correct? (Choose one answer)

Options:

A.

The security risk was dropped.

B.

The risk source is isolated.

C.

The security risk was blocked.

D.

The security event risk is from an application control log.

Buy Now
Questions 20

Which log will generate an event with the status Unhandled?

Options:

A.

An AV log with action=quarantine.

B.

An IPS log with action=pass.

C.

A WebFilter log with action=dropped.

D.

An AppControl log with action=blocked.

Buy Now
Questions 21

What is the purpose of running the command diagnose sql status sqlreportd?

Options:

A.

To view a list of scheduled reports

B.

To list the current SQL processes running

C.

To display the SQL query connections and hcache status

D.

To identify the database log insertion status

Buy Now
Questions 22

(Which two parameters does FortiAnalyzer use to identify an indicator of compromise (IOC)? (Choose two answers)

Options:

A.

IP address

B.

URL

C.

Policy ID

D.

Application category

Buy Now
Questions 23

Which two statements about local logs on FortiAnalyzer are true? (Choose two.)

Options:

A.

They are not supported in FortiView.

B.

You can view playbook logs for all ADOMs in the root ADOM.

C.

Event logs show system-wide information, whereas application logs are ADOM-specific.

D.

Event logs are available only in the root ADOM.

Buy Now
Exam Code: FCP_FAZ_AN-7.6
Exam Name: Fortinet NSE 5 - FortiAnalyzer 7.6 Analyst
Last Update: Jun 19, 2026
Questions: 79

PDF + Testing Engine

$134.99

Testing Engine

$99.99

PDF (Q&A)

$84.99