FCP_FAZ_AN-7.6 Fortinet NSE 5 - FortiAnalyzer 7.6 Analyst Questions and Answers
Which two actions should an administrator take to vide Compromised Hosts on FortiAnalyzer? (Choose two.)
(Refer to the exhibit.

Which statement about the displayed event is correct? (Choose one answer))
You find that as part of your role as an analyst, you frequently search log View using the same parameters.
Instead of defining your search filters repeatedly, what can you do to save time?
(In a FortiAnalyzer Fabric deployment, which three modules from Fabric members are available for analysis on the supervisor? (Choose three answers))
Exhibit.

A fortiAnalyzer analyst is customizing a SQL query to use in a report.
Which SQL query should the analyst run to get the expected results?
A)

B)

C)
D)
Exhibit.

Based on the partial outputs displayed, which devices can be members of a FotiAnalyzer Fabric?
(Which two parameters does FortiAnalyzer use to identify an indicator of compromise (IOC)? (Choose two answers))
In firmware version 7.6, how does on-premises FortiAnalyzer store logs? (Choose one answer)
What are two effects of enabling auto-cache in a FortiAnalyzer report? (Choose two.)
(You created a playbook on FortiAnalyzer that uses a FortiOS connector. When you configure FortiGate, which type of trigger must you use so that the actions in an automation stitch are available in the FortiOS connector? (Choose one answer))
(Refer to the exhibit.

Which statement about the displayed event is correct? (Choose one answer))
