Instant Download Fortinet: NSE5_FAZ-7.2 Free Updated Test Dumps
Valid NSE5_FAZ-7.2 FREE EXAM DUMPS QUESTIONS & ANSWERS
NEW QUESTION # 11
What FortiGate process caches logs when FortiAnalyzer is not reachable?
- A. logfiled
- B. sqlplugind
- C. oftpd
- D. miglogd
Answer: D
NEW QUESTION # 12
What are two benefits of using fabric connectors? (Choose two.)
- A. They allow FortiAnalyzer to send logs in real-time to public cloud accounts.
- B. Fabric connectors allow you to improve redundancy.
- C. Using fabric connectors is more efficient than using third-party polling with API.
- D. You do not need an additional license to send logs to the cloud platform.
Answer: A,B
NEW QUESTION # 13
Which two statements are true regarding fabric connectors? (Choose two.)
- A. Fabric connectors allow to save storage costs and improve redundancy.
- B. Configuring fabric connectors to send notification to ITSM platform upon incident creation Is more efficient than third-party information from the FortiAnalyzer API.
- C. Cloud-Out connections allow you to send real-time logs to pubic cloud accounts like Amazon S3, Azure Blob , and Google Cloud.
- D. Storage connector service does not require a separate license to send logs to cloud platform.
Answer: B,C
NEW QUESTION # 14
Which daemon is responsible for enforcing raw log file size?
- A. logfiled
- B. sqlplugind
- C. oftpd
- D. miglogd
Answer: A
NEW QUESTION # 15
What is the recommended method of expanding disk space on a FortiAnalyzer VM?
- A. From the VM host manager, expand the size of the existing virtual disk
- B. From the VM host manager, add an additional virtual disk and use the #execute lvm extend <disk number> command to expand the storage
- C. From the VM host manager, add an additional virtual disk and rebuild your RAID array
- D. From the VM host manager, expand the size of the existing virtual disk and use the # execute format disk command to reformat the disk
Answer: B
Explanation:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD40848
NEW QUESTION # 16
Refer to the exhibit.
Laptopt is used by several administrators to manage FortiAnalyzer. You want to configure a generic text filter that matches all login attempts to the web interface generated by any user other than "admin" and coming from Laptop1:
Which filter will achieve the desired result?
- A. operation-login & srcip==10.1.1.100 & dstip==10.1.1.210 & user==admin
- B. operation-login & performed_on=="GUI(10.1.1.210)' & user!=admin
- C. operation-login & dstip==10.1.1.210 & userl-admin
- D. operation-login & performed_on=="GUI(10.1.1.100)" & user!=admin
Answer: D
Explanation:
On there the task was to create a filter for failed logins from any other location but the local computer: "Add the text performed_on!~10.0.1.10. This includes any attempts coming from devices with an IP address that is not the one configured on the Local-Client computer."
NEW QUESTION # 17
Which two methods are the most common methods to control and restrict administrative access on FortiAnalyzer? (Choose two.)
- A. Administrative access profiles
- B. Security Fabric
- C. Trusted hosts
- D. Virtual domains
Answer: A,C
Explanation:
Reference:
https://docs2.fortinet.com/document/fortianalyzer/6.0.0/administration-guide/581222/trusted-hosts
NEW QUESTION # 18
FortiAnalyzer centralizes which functions? (Choose three)
- A. Vulnerability assessment
- B. Network analysis
- C. Content archiving / data mining
- D. Security log analysis / forensics
- E. Graphical reporting
Answer: C,D,E
NEW QUESTION # 19
A play book contains five tasks in total. An administrator executed the playbook and four out of five tasks finished successfully, but one task failed. What will be the status of the playbook after its execution?
- A. Failed
- B. Running
- C. Success
- D. Upstream_failed
Answer: A
Explanation:
Playbook jobs that include one or more failed tasks are labeled as Failed in Playbook Monitor. FortiAnalyzer_7.0_Study Guide page No: 247 Playbook jobs that include one or more failed tasks are labeled as Failed in Playbook Monitor. A failed status, however, does not mean that all tasks failed. Some individual actions may have been completed successfully.
NEW QUESTION # 20
You have recently grouped multiple FortiGate devices into a single ADOM. System Settings > Storage Info shows the quota used.
What does the disk quota refer to?
- A. The maximum disk utilization for each device in the ADOM
- B. The maximum disk utilization for the FortiAnalyzer model
- C. The maximum disk utilization for all devices in the ADOM
- D. The maximum disk utilization for the ADOM type
Answer: C
NEW QUESTION # 21
What is required to authorize a FortiGate on FortiAnalyzer using Fabric authorization?
- A. Valid FortiAnalyzer credentials
- B. The FortiGate serial number
- C. A pre-shared key
- D. A FortiGate ADOM
Answer: A
Explanation:
FortiAnalyzer_7.0_Study_Guide-Online.pdf page 93: The fourth method uses the Fortinet Security Fabric authorization process. This method requires that both FortiGate and FortiAnalyzer are running version 7.0.1 or higher. It is also required that the FortiGate administrator has valid credentials to log in on FortiAnalyzer and complete the registration.
https://docs.fortinet.com/document/fortianalyzer/7.2.1/administration-guide/13897/adding-a-fortigate-using-security-fabric-authorization
NEW QUESTION # 22
An administrator fortinet, is able to view logs and perform device management tasks, such as adding and removing registered devices. However, administrator fortinet is not able to create a mall server that can be used to send email.
What could be the problem?
- A. A trusted host is configured.
- B. Fortinet is assigned the Standard_ User administrator profile.
- C. Fortinet is assigned the Restricted_ User administrator profile.
- D. ADOM mode is configured with Advanced mode.
Answer: B
Explanation:
* Super_User, which, like in FortiGate, provides access to all device and system privileges.
* Standard_User, which provides read and write access to device privileges, but not system privileges.
* Restricted_User, which provides read access only to device privileges, but not system privileges. Access to the Management extensions is also removed.
* No_Permissions_User, which provides no system or device privileges. Can be used, for example, to temporarily remove access granted to existing admins.
FortiAnalyzer_7.0_Study_Guide-Online page 42
NEW QUESTION # 23
Which two statements about log forwarding are true? (Choose two.)
- A. Logs are forwarded in real-time only.
- B. Forwarded logs cannot be filtered to match specific criteria.
- C. You can use aggregation mode only with another FortiAnalyzer.
- D. The client retains a local copy of the logs after forwarding.
Answer: C,D
Explanation:
https://docs.fortinet.com/document/fortianalyzer/6.2.5/administration-guide/420493/modes
https://docs.fortinet.com/document/fortianalyzer/6.2.5/administration-guide/621804/log-forwarding
NEW QUESTION # 24
What statements are true regarding disk log quota? (Choose two)
- A. The FortiAnalyzer disk log quota is configurable, but has a minimum o 100mb a maximum based on the reserved system space.
- B. The FortiAnalyzer automatically sets the disk log quota based on the device.
- C. The FortiAnalyzer can overwrite the oldest logs or stop logging once the disk log quota is met.
- D. The FortiAnalyzer stops logging once the disk log quota is met.
Answer: A,C
NEW QUESTION # 25
What happens when a log file saved on FortiAnalyzer disks reaches the size specified in the device log settings?
- A. The log file is purged from the database.
- B. The log file rolls over and is archived.
- C. The log file is overwritten.
- D. The log file is stored as a raw log and is available for analytic support.
Answer: B
Explanation:
Reference:
81a4-00505692583a/FortiAnalyzer-6.0.5-Administration-Guide.pdf
https://docs.fortinet.com/document/fortianalyzer/6.2.5/administration-guide/355632/log-browse
NEW QUESTION # 26
Which two elements are contained in a system backup created on FortiAnalyzer? (Choose two.)
- A. Report information
- B. Logs from registered devices
- C. System information
- D. Database snapshot
Answer: A,C
Explanation:
What does the System Configuration backup include?
System information, such as the device IP address and administrative user information.
Device list, such as any devices you configured to allow log access.
Report information, such as any configured report settings, as well as all your custom report details. These are not the actual reports.
FortiAnalyzer_7.0_Study_Guide-Online pag. 29
FortiAnalyzer_7.0_Study_Guide-Online.pdf page 29: What does the System Configuration backup include?
* System information, such as the device IP address and administrative user information
* Device list, such as any devices you configured to allow log access
* Report information, such as any configured report settings, as well as all your custom report details. These are not the actual reports.
NEW QUESTION # 27
Refer to the exhibit.
What does the data point at 14:55 tell you?
- A. The received rate is almost at its maximum for this device
- B. Raw logs are reaching FortiAnalyzer faster than they can be indexed
- C. Logs are being dropped
- D. The sqlplugind daemon is behind in log indexing by two logs
Answer: B
NEW QUESTION # 28
......
Free NSE5_FAZ-7.2 Exam Braindumps Fortinet Pratice Exam: https://www.validdumps.top/NSE5_FAZ-7.2-exam-torrent.html
Practice Test for NSE5_FAZ-7.2 Certification Real 2024 Mock Exam: https://drive.google.com/open?id=1yjj1UFG2ePWxjKRr5eNWtTj2bdMrNn5x