NSE5_FAZ-7.2 Exam Questions
155 real NSE5_FAZ-7.2 exam questions with expert-verified answers and explanations. Page 3 of 4.
- Question #101
Which two statement are true regardless initial Logs sync and Log Data Sync for Ha on FortiAnalyzer?
- Question #102
Which two statements are true regarding fabric connectors? (Choose two.)
- Question #103
What does the disk status Degraded mean for RAID management?
- Question #104
An administrator, fortinet, is able to view logs and perform device management tasks, such as adding and removing registered devices. However, administrator fortinet is not able to...
- Question #105
Which statement is true when you are upgrading the firmware on an HA cluster made up of two FortiAnalyzer devices?
- Question #106
What is the purpose of output variables?
- Question #107
Which two elements are contained in a system backup created on FortiAnalyzer? (Choose two.)
- Question #108
Which two statements are correct regarding the export and import of playbooks? (Choose two.)
- Question #109
Which SQL query is in the correct order to query the database in the FortiAnslyzer?
- Question #110
Refer to the exhibits. How many events will be added to the incident created after running this playbook?
- Question #111
Which daemon is responsible for enforcing the log file size?
- Question #112
Refer to the exhibit. Which statement is correct regarding the event displayed?
- Question #113
What is required to authorize a FortiGate on FortiAnalyzer using Fabric authorization?
- Question #115
Refer to the exhibit. Laptopt is used by several administrators to manage FortiAnalyzer. You want to configure a generic text filter that matches all login attempts to the web inte...
- Question #116
If the primary FortiAnalyzer in an HA cluster fails, how is the new primary elected?
- Question #117
What is the best approach to handle a hard disk failure on a FortiAnalyzer that supports hardware RAID?
- Question #118
Which statement is true about sending notifications with incident updates?
- Question #119
Which statement correctly describes the management extensions available on FortiAnalyzer?
- Question #120
A play book contains five tasks in total. An administrator executed the playbook and four out of five tasks finished successfully, but one task failed. What will be the status of t...
- Question #121
When working with FortiAnalyzer reports, what is the purpose of a dataset?
- Question #122
Refer to the exhibit. The image displays the configuration of a FortiAnalyzer the administrator wants to join to an existing HA cluster. What can you conclude from the configuratio...
- Question #123
You crested a playbook on FortiAnalyzer that uses a FortiOS connector. When configuring the FortiGate side, which type of trigger must be used so that the actions in an automation...
- Question #124
What must you consider when using log fetching? (Choose two.)
- Question #125
Which two statements are true regarding the outbreak detection service? (Choose two.)
- Question #126
What are two effects of enabling auto-cache in a FortiAnalyzer report? (Choose two.)
- Question #127
Why must you wait for several minutes before you run a playbook that you just created?
- Question #128
Which statement describes online logs on FortiAnalyzer?
- Question #129
How can you attach a report to an incident?
- Question #130
Which item must you configure on FortiAnalyzer to email generated reports automatically?
- Question #131
Which statement about the FortiSOAR management extension is correct?
- Question #132
Why run the command diagnose sql status sqlplugind?
- Question #133
What are two benefits of using fabric connectors? (Choose two.)
- Question #134
Which log will generate an event with the status Contained?
- Question #135
Refer to the exhibit. Laptop1 is used by several administrators to manage FortiAnalyzer. You want to configure a generic text filter that matches all login attempts to the web inte...
- Question #136
After generating a report, you notice the information you were expecting to see is not included in it. What are two possible reasons for this scenario? (Choose two.)
- Question #137
What is the purpose of using prefilters when configuring event handlers?
- Question #138
Which statement describes a dataset in FortiAnalyzer?
- Question #139
A playbook contains five tasks in total. An administrator runs the playbook and four out of five tasks finish successfully, but one task fails. What will be the status of the playb...
- Question #140
What is the purpose of trigger variables?
- Question #141
Which statement about sending notifications with incident updates is true?
- Question #142
Refer to the exhibit. What is the purpose of using the Chart Builder feature on FortiAnalyzer?
- Question #143
What happens when the IOC breach detection engine on FortiAnalyzer finds web logs that match a blocklisted IP address?
- Question #144
Refer to the exhibit. Based on the partial outputs displayed, which devices can be members of a FortiAnalyzer Fabric?
- Question #145
Refer to the exhibit. What does the data point at 12:20 indicate?
- Question #146
Which statement about the FortiSIEM management extension is correct?
- Question #147
Refer to the exhibit. Which statement is correct regarding the event displayed?
- Question #148
What is the purpose of predefined report templates on FortiAnalyzer?
- Question #149
Refer to the exhibit. What does the data point at 21:20 indicate?
- Question #150
Which two methods can you use to send notifications when an event occurs that matches a configured event handier? (Choose two.)
- Question #151
Refer to the exhibit. Which FortiAnalyzer tool can refer to the Cyber Kill Chain stages and allows you to identify which Fortinet products can protect you against new vulnerabiliti...