[Nov-2021] Latest Fortinet NSE5_FAZ-6.2 exam dumps and online Test Engine
Fortinet NSE5_FAZ-6.2: Selling Network Security Analyst Products and Solutions
For more info read reference:
Exam Blueprint Preparatory Course FAQs and Guide
NEW QUESTION 16
What happens when a log file saved on FortiAnalyzer disks reaches the size specified in the device log settings?
- A. The log file is stored as a raw log and is available for analytic support.
- B. The log file rolls over and is archived.
- C. The log file is overwritten.
- D. The log file is purged from the database.
Answer: B
NEW QUESTION 17
For which two SAML roles can the FortiAnalyzer be configured? (Choose two.)
- A. Identity collector
- B. Identity provider
- C. Service provider
- D. Principal
Answer: B,C
Explanation:
Reference:
20the%20identity%20provider%20(IdP,external%20identity%20provider%20is%20available.
https://docs.fortinet.com/document/fortianalyzer/6.2.0/administration-guide/981386/saml-admin-authentication
NEW QUESTION 18
What is the purpose of employing RAID with FortiAnalyzer?
- A. To introduce redundancy to your log data
- B. To back up your logs
- C. To provide data separation between ADOMs
- D. To separate analytical and archive data
Answer: A
Explanation:
https://en.wikipedia.org/wiki/RAID#:~:text=RAID%20(%22Redundant%20Array%20of%20Inexpensive,%2C%20performance%20improvement%2C%20or%20both.
NEW QUESTION 19
What is the purpose of a predefined template on the FortiAnalyzer?
- A. It specifies the report layout which contains predefined texts, charts, and macros
- B. It contains predefined data to generate mock reports
- C. It can be edited and modified as required
- D. It specifies report settings which contains time period, device selection, and schedule
Answer: A
NEW QUESTION 20
Which two statements about log forwarding are true? (Choose two.)
- A. You can use aggregation mode only with another FortiAnalyzer.
- B. Logs are forwarded in real-time only.
- C. Forwarded logs cannot be filtered to match specific criteria.
- D. The client retains a local copy of the logs after forwarding.
Answer: B,D
NEW QUESTION 21
Why should you use an NTP server on FortiAnalyzer and all registered devices that log into FortiAnalyzer?
- A. To resolve host names
- B. To properly correlate logs
- C. To use real-time forwarding
- D. To improve DNS response times
Answer: B
NEW QUESTION 22
What is the purpose of employing RAID with FortiAnalyzer?
- A. To introduce redundancy to your log data
- B. To back up your logs
- C. To provide data separation between ADOMs
- D. To separate analytical and archive data
Answer: A
NEW QUESTION 23
What must you configure on FortiAnalyzer to upload a FortiAnalyzer report to a supported external server?
(Choose two.)
- A. Output profile
- B. SFTP, FTP, or SCP server
- C. Report scheduling
- D. Mail server
Answer: A,B
NEW QUESTION 24
You need to upgrade your FortiAnalyzer firmware.
What happens to the logs being sent to FortiAnalyzer from FortiGate during the time FortiAnalyzer is temporarily unavailable?
- A. FortiGate uses the miglogd process to cache the logs
- B. FortiAnalyzer uses log fetching to retrieve the logs when back online
- C. Logs are dropped
- D. The logfiled process stores logs in offline mode
Answer: A
NEW QUESTION 25
You have moved a registered logging device out of one ADOM and into a new ADOM.
What happens when you rebuild the new ADOM database?
- A. FortiAnalyzer migrates archive logs to the new ADOM.
- B. FortiAnalyzer resets the disk quota of the new ADOM to default.
- C. FortiAnalyzer removes analytics logs from the old ADOM.
- D. FortiAnalyzer migrates analytics logs to the new ADOM.
Answer: D
NEW QUESTION 26
What can the CLI command # diagnose test application oftpd 3 help you to determine?
- A. What ADOMs are enabled and configured
- B. What devices are registered and unregistered
- C. What logs, if any, are reaching FortiAnalyzer
- D. What devices and IP addresses are connecting to FortiAnalyzer
Answer: D
NEW QUESTION 27
What are the operating modes of FortiAnalyzer? (Choose two)
- A. Collector
- B. Manager
- C. Standalone
- D. Analyzer
Answer: A,D
NEW QUESTION 28
Which tabs do not appear when FortiAnalyzer is operating in Collector mode?
- A. Device Manger
- B. FortiView
- C. Reporting
- D. Event Management
Answer: D
NEW QUESTION 29
When you perform a system backup, what does the backup configuration contain? (Choose two.)
- A. System information
- B. Authorized devices logs
- C. Generated reports
- D. Device list
Answer: A,D
NEW QUESTION 30
View the exhibit.
What does the data point at 14:35 tell you?
- A. FortiAnalyzer has temporarily stopped receiving logs so older logs' can be indexed.
- B. The sqlplugind daemon is ahead in indexing by one log.
- C. FortiAnalyzer is dropping logs.
- D. FortiAnalyzer is indexing logs faster than logs are being received.
Answer: B
Explanation:
Explanation
Logs are received then they are indexed, no logging server in the world can index logs faster than they are received. When FAZ receives raw logs, they are inserted (indexed) by the SQL database and the sqlplugind daemon, this graph shows that FAZ received 3 logs and sqlplugind indexed 4.
NEW QUESTION 31
You've moved a registered logging device out of one ADOM and into a new ADOM. What happens when you rebuild the new ADOM database?
- A. FortiAnalyzer removes logs from the old ADOM.
- B. FortiAnalyzer migrates archive logs to the new ADOM.
- C. FortiAnalyzer resets the disk quota of the new ADOM to default.
- D. FortiAnalyzer migrates analytics logs to the new ADOM.
Answer: D
NEW QUESTION 32
On the RAID management page, the disk status is listed as Initializing.
What does the status Initializing indicate about what the FortiAnalyzer is currently doing?
- A. FortiAnalyzer is writing data to a newly added hard drive to restore it to an optimal state
- B. FortiAnalyzer is functioning normally
- C. FortiAnalyzer is writing to all of its hard drives to make the array fault tolerant
- D. FortiAnalyzer is ensuring that the parity data of a redundant drive is valid
Answer: C
Explanation:
Explanation/Reference: https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/4cb0dce6-dbef-11e9-
8977-00505692583a/FortiAnalyzer-5.6.10-Administration-Guide.pdf (40)
NEW QUESTION 33
In the FortiAnalyzer FortiView, source and destination IP addresses from FortiGate devices are not resolving to a hostname.
How can you resolve the source and destination IP addresses, without introducing any additional performance impact to FortiAnalyzer?
- A. Configure local DNS servers on FortiAnalyzer
- B. Resolve IP addresses on a per-ADOM basis to reduce delay on FortiView while IPs resolve
- C. Resolve IP addresses on FortiGate
- D. Configure # set resolve-ip enable in the system FortiView settings
Answer: D
Explanation:
Explanation/Reference: https://forum.fortinet.com/tm.aspx?m=156950
NEW QUESTION 34
Logs are being deleted from one of your ADOMs earlier that the configured setting for archiving in your data policy. What is the most likely problem?
- A. CPU resources are too high.
- B. The ADOM disk quota is set too low based on log rates.
- C. The total disk space is insufficient and you need to add other disk.
- D. Logs in that ADOM are being forwarded in real-time to another FortiAnalyzer device.
Answer: B
Explanation:
https://help.fortinet.com/fmgr/50hlp/56/5-6-1/FMG FAZ/1100_Storage/0017_Deleted%20device%20logs.htm
https://docs.fortinet.com/document/fortianalyzer/6.2.5/administration-guide/87802/automatic-deletion
NEW QUESTION 35
Which clause is considered mandatory in SELECT statements used by the FortiAnalyzer to generate reports?
- A. LIMIT
- B. FROM
- C. WHERE
- D. ORDER BY
Answer: C
NEW QUESTION 36
What happens when a log file saved on FortiAnalyzer disks reaches the size specified in the device log settings?
- A. The log file is overwritten
- B. The log file is stored as a raw log and is available for analytic support
- C. The log file is purged from the database
- D. The log file rolls over is archived
Answer: D
Explanation:
Explanation/Reference: https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/6d9f8fb5-6cf4-11e9-
81a4-00505692583a/FortiAnalyzer-6.0.5-Administration-Guide.pdf
NEW QUESTION 37
How do you restrict an administrator's access to a subset of your organization's ADOMs?
- A. Assign the ADOMs to the administrator's account
- B. Assign the default Super_User
- C. Configure trusted hosts
- D. Set the ADOM mode to Advanced
Answer: A
NEW QUESTION 38
......
New 2021 NSE5_FAZ-6.2 Test Tutorial (Updated 68 Questions): https://www.testsimulate.com/NSE5_FAZ-6.2-study-materials.html