0% found this document useful (0 votes)
236 views10 pages

Exam NSE5 - FAZ-6.2: IT Certification Guaranteed, The Easy Way!

This document provides questions and answers related to the Fortinet NSE 5 - FortiAnalyzer 6.2 certification exam. It contains 30 multiple choice questions testing knowledge of FortiAnalyzer configurations, features, and functions including log collection, storage, reporting, and high availability clusters. Correct answers are provided to help study for and pass the certification.

Uploaded by

chaconjl
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
236 views10 pages

Exam NSE5 - FAZ-6.2: IT Certification Guaranteed, The Easy Way!

This document provides questions and answers related to the Fortinet NSE 5 - FortiAnalyzer 6.2 certification exam. It contains 30 multiple choice questions testing knowledge of FortiAnalyzer configurations, features, and functions including log collection, storage, reporting, and high availability clusters. Correct answers are provided to help study for and pass the certification.

Uploaded by

chaconjl
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 10

IT Certification Guaranteed, The Easy Way!

Exam : NSE5_FAZ-6.2

Title : Fortinet NSE 5 - FortiAnalyzer


6.2

Vendor : Fortinet

Version : V12.35

1
IT Certification Guaranteed, The Easy Way!

NO.1 If you upgrade your FortiAnalyzer firmware, what report elements can be affected?
A. Output profiles
B. Report settings
C. Report scheduling
D. Custom datasets
Answer: D

NO.2 Which statements are true regarding securing communications between FortiAnalyzer and
FortiGate with SSL? (Choose two.)
A. SSL is the default setting.
B. SSL communications are auto-negotiated between the two devices.
C. SSL can send logs in real-time only.
D. SSL encryption levels are globally set on FortiAnalyzer.
E. FortiAnalyzer encryption level must be equal to, or higher than, FortiGate.
Answer: A,D

NO.3 What statements are true regarding disk log quota? (Choose two)
A. The FortiAnalyzer stops logging once the disk log quota is met.
B. The FortiAnalyzer automatically sets the disk log quota based on the device.
C. The FortiAnalyzer can overwrite the oldest logs or stop logging once the disk log quota is met.
D. The FortiAnalyzer disk log quota is configurable, but has a minimum o 100mb a maximum based
on the reserved system space.
Answer: C,D

NO.4 By default, what happens when a log file reaches its maximum file size?
A. FortiAnalyzer overwrites the log files.
B. FortiAnalyzer stops logging.
C. FortiAnalyzer rolls the active log by renaming the file.
D. FortiAnalyzer forwards logs to syslog.
Answer: C

NO.5 View the Exhibit:

Why is the total quota less than the total system storage?

2
IT Certification Guaranteed, The Easy Way!

A. 3.6% of the system storage is already being used.


B. Some space is reserved for system use, such as storage of compression files, upload files, and
temporary report files
C. The oftpd process has not archived the logs yet
D. The logfiled process is just estimating the total quota
Answer: B

NO.6 How does FortiAnalyzer retrieve specific log data from the database?
A. SQL FROM statement
B. SQL GET statement
C. SQL SELECT statement
D. SQL EXTRACT statement
Answer: C

NO.7 What is the purpose of the following CLI command?

A. To add a log file checksum


B. To add the MD's hash value and authentication code
C. To add a unique tag to each log to prove that it came from this FortiAnalyzer
D. To encrypt log communications
Answer: A

NO.8 In FortiAnalyzer's FormView, source and destination IP addresses from FortiGate devices are
not resolving to a hostname. How can you resolve the source and destination IPs, without
introducing any additional performance impact to FortiAnalyzer?
A. Configure local DNS servers on FortiAnalyzer
B. Resolve IPs on FortiGate
C. Configure # set resolve-ip enable in the system FortiView settings
D. Resolve IPs on a per-ADOM basis to reduce delay on FortiView while IPs resolve
Answer: B

NO.9 Which statements are true regarding securing communications between FortiAnalyzer and
FortiGate with IPsec? (Choose two.)
A. Must configure the FortiAnalyzer end of the tunnel only--the FortiGate end is auto-negotiated.
B. Must establish an IPsec tunnel ID and pre-shared key.
C. IPsec cannot be enabled if SSL is enabled as well.
D. IPsec is only enabled through the CLI on FortiAnalyzer.
Answer: C

3
IT Certification Guaranteed, The Easy Way!

NO.10 On FortiAnalyzer, what is a wildcard administrator account?


A. An account that permits access to members of an LDAP group
B. An account that allows guest access with read-only privileges
C. An account that requires two-factor authentication
D. An account that validates against any user account on a FortiAuthenticator
Answer: D

NO.11 What remote authentication servers can you configure to validate your FortiAnalyzer
administrator logons? (Choose three)
A. RADIUS
B. Local
C. LDAP
D. PKI
E. TACACS+
Answer: A,C,E

NO.12 Which FortiAnalyzer feature allows you to retrieve the archived logs matching a specific
timeframe from another FortiAnalyzer device?
A. Log upload
B. Indicators of Compromise
C. Log forwarding an aggregation mode
D. Log fetching
Answer: D

NO.13 What are two of the key features of FortiAnalyzer? (Choose two.)
A. Centralized log repository
B. Cloud-based management
C. Reports
D. Virtual domains (VDOMs)
Answer: A,C

NO.14 Which statements are true of Administrative Domains (ADOMs) in FortiAnalyzer? (Choose
two.)
A. ADOMs are enabled by default.
B. ADOMs constrain other administrator's access privileges to a subset of devices in the device list.
C. Once enabled, the Device Manager, FortiView, Event Management, and Reports tab display per
ADOM.
D. All administrators can create ADOMs--not just the admin administrator.
Answer: B,C

NO.15 What can the CLI command # diagnose test application oftpd 3 help you to determine?
A. What devices and IP addresses are connecting to FortiAnalyzer
B. What logs, if any, are reaching FortiAnalyzer

4
IT Certification Guaranteed, The Easy Way!

C. What ADOMs are enabled and configured


D. What devices are registered and unregistered
Answer: A

NO.16 FortiAnalyzer centralizes which functions? (Choose three)


A. Network analysis
B. Graphical reporting
C. Content archiving / data mining
D. Vulnerability assessment
E. Security log analysis / forensics
Answer: B,C,E

NO.17 View the exhibit:

What does the 1000MB maximum for disk utilization refer to?
A. The disk quota for the FortiAnalyzer model
B. The disk quota for all devices in the ADOM
C. The disk quota for each device in the ADOM
D. The disk quota for the ADOM type
Answer: B

NO.18 FortiAnalyzer uses the Optimized Fabric Transfer Protocok (OFTP) over SSL for what purpose?
A. To upload logs to an SFTP server
B. To prevent log modification during backup
C. To send an identical set of logs to a second logging server
D. To encrypt log communication between devices
Answer: D

NO.19 Logs are being deleted from one of your ADOMs earlier that the configured setting for
archiving in your data policy. What is the most likely problem?
A. The total disk space is insufficient and you need to add other disk.
B. CPU resources are too high.
C. The ADOM disk quota is set too low based on log rates.
D. Logs in that ADOM are being forwarded in real-time to another FortiAnalyzer device.

5
IT Certification Guaranteed, The Easy Way!

Answer: C

NO.20 For proper log correlation between the logging devices and FortiAnalyzer, FortiAnalyzer and
all registered devices should:
A. Use DNS
B. Use host name resolution
C. Use real-time forwarding
D. Use an NTP server
Answer: D

NO.21 What are the operating modes of FortiAnalyzer? (Choose two)


A. Standalone
B. Manager
C. Analyzer
D. Collector
Answer: C,D

NO.22 Which statements are correct regarding FortiAnalyzer reports? (Choose two)
A. FortiAnalyzer provides the ability to create custom reports.
B. FortiAnalyzer glows you to schedule reports to run.
C. FortiAnalyzer includes pre-defined reports only.
D. FortiAnalyzer allows reporting for FortiGate devices only.
Answer: A,B

NO.23 View the exhibit.

What does the data point at 14:35 tell you?


A. FortiAnalyzer is dropping logs.
B. FortiAnalyzer is indexing logs faster than logs are being received.
C. FortiAnalyzer has temporarily stopped receiving logs so older logs' can be indexed.
D. The sqlplugind daemon is ahead in indexing by one log.
Logs are received then they are indexed, no logging server in the world can index logs faster than
they are received. When FAZ receives raw logs, they are inserted (indexed) by the SQL database and
the sqlplugind daemon, this graph shows that FAZ received 3 logs and sqlplugind indexed 4.

6
IT Certification Guaranteed, The Easy Way!

Answer: D

NO.24 What FortiView tool can you use to automatically build a dataset and chart based on a
filtered search result?
A. Chart Builder
B. Export to Report Chart
C. Dataset Library
D. Custom View
Answer: A

NO.25 What FortiView tool can you use to automatically build a dataset and chart based on a
filtered search result?
A. Custom View
B. Chart Builder
C. Dataset Library
D. Export to Report Chart
Answer: B

NO.26 What happens when a log file saved on FortiAnalyzer disks reaches the size specified in the
device log settings?
A. The log file is stored as a raw log and is available for analytic support.
B. The log file rolls over and is archived.
C. The log file is purged from the database.
D. The log file is overwritten.
Answer: B

NO.27 In order for FortiAnalyzer to collect logs from a FortiGate device, what configuration is
required? (Choose two.)
A. Remote logging must be enabled on FortiGate
B. Log encryption must be enabled
C. ADOMs must be enabled
D. FortiGate must be registered with FortiAnalyzer
Answer: A,D

NO.28 What statements are true regarding FortiAnalyzer 's treatment of high availability (HA)
dusters? (Choose two)
A. FortiAnalyzer distinguishes different devices by their serial number.
B. FortiAnalyzer receives logs from d devices in a duster.
C. FortiAnalyzer receives bgs only from the primary device in the cluster.
D. FortiAnalyzer only needs to know (he serial number of the primary device in the cluster-it
automaticaly discovers the other devices.
Answer: A,B

7
IT Certification Guaranteed, The Easy Way!

NO.29 What FortiGate process caches logs when FortiAnalyzer is not reachable?
A. logfiled
B. sqlplugind
C. oftpd
D. miglogd
Answer: D

NO.30 How can you configure FortiAnalyzer to permit administrator logins from only specific
locations?
A. Use static routes
B. Use administrative profiles
C. Use trusted hosts
D. Use secure protocols
Answer: C

NO.31 What is the recommended method of expanding disk space on a FortiAnalyzer VM?
A. From the VM host manager, add an additional virtual disk and use the #execute lvm extend <disk
number> command to expand the storage
B. From the VM host manager, expand the size of the existing virtual disk
C. From the VM host manager, expand the size of the existing virtual disk and use the # execute
format disk command to reformat the disk
D. From the VM host manager, add an additional virtual disk and rebuild your RAID array
Answer: A

NO.32 What must you configure on FortiAnalyzer to upload a FortiAnalyzer report to a supported
external server?
(Choose two.)
A. SFTP, FTP, or SCP server
B. Mail server
C. Output profile
D. Report scheduling
Answer: A,C

NO.33 What statements are true regarding the "store and upload" log transfer option between
FortiAnalyzer and FortiGate? (Choose three.)
A. All FortiGates can send logs to FortiAnalyzer using the store and upload option.
B. Only FortiGate models with hard disks can send logs to FortiAnalyzer using the store and upload
option.
C. Both secure communications methods (SSL and IPsec) allow the store and upload option.
D. Disk logging is enabled on the FortiGate through the CLI only.
E. Disk logging is enabled by default on the FortiGate.
Answer: B,C,D

8
IT Certification Guaranteed, The Easy Way!

NO.34 What purposes does the auto-cache setting on reports serve? (Choose two.)
A. To reduce report generation time
B. To automatically update the hcache when new logs arrive
C. To reduce the log insert lag rate
D. To provide diagnostics on report generation time
Answer: A,B

NO.35 Which tabs do not appear when FortiAnalyzer is operating in Collector mode?
A. FortiView
B. Event Management
C. Device Manger
D. Reporting
Answer: B

NO.36 How do you restrict an administrator's access to a subset of your organization's ADOMs?
A. Set the ADOM mode to Advanced
B. Assign the ADOMs to the administrator's account
C. Configure trusted hosts
D. Assign the default Super_User administrator profile
Answer: B

NO.37 How are logs forwarded when FortiAnalyzer is using aggregation mode?
A. Logs are forwarded as they are received and content files are uploaded at a scheduled time.
B. Logs and content files are stored and uploaded at a scheduled time.
C. Logs are forwarded as they are received.
D. Logs and content files are forwarded as they are received.
Answer: B

NO.38 What is the purpose of employing RAID with FortiAnalyzer?


A. To introduce redundancy to your log data
B. To provide data separation between ADOMs
C. To separate analytical and archive data
D. To back up your logs
Answer: A

NO.39 Which statements are true regarding securing communications between FortiAnalyzer and
FortiGate with SSL? (Choose two.)
A. SSL communications are auto-negotiated between the two devices.
B. SSL can send logs in real-time only.
C. FortiAnalyzer encryption level must be equal to, or higher than, FortiGate.
D. SSL encryption levels are globally set on FortiAnalyzer.
E. SSL is the default setting.
Answer: D,E

9
IT Certification Guaranteed, The Easy Way!

NO.40 You've moved a registered logging device out of one ADOM and into a new ADOM. What
happens when you rebuild the new ADOM database?
A. FortiAnalyzer resets the disk quota of the new ADOM to default.
B. FortiAnalyzer migrates archive logs to the new ADOM.
C. FortiAnalyzer migrates analytics logs to the new ADOM.
D. FortiAnalyzer removes logs from the old ADOM.
Answer: C

10

You might also like