Summer Sale - Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dpm65

FCP_FAZ_AD-7.4 FCP - FortiAnalyzer 7.4 Administrator Questions and Answers

Questions 4

Refer to the exhibit.

FCP_FAZ_AD-7.4 Question 4

What is the purpose of using the Chart Builder feature on FortiAnalyzer?

Options:

A.

To add a new chart under FortiView to be used in new reports

B.

To build a dataset and chart automatically, based on the filtered search results

C.

To add charts directly to generate reports in the current ADOM

D.

To build a chart automatically based on the top 100 log entries

Buy Now
Questions 5

Which two statements regarding FortiAnalyzer log forwarding modes are true? (Choose two.)

Options:

A.

Both modes, forwarding and aggregation, support encryption of logs between devices.

B.

In aggregation mode, you can forward logs to syslog and CEF servers.

C.

Forwarding mode forwards logs in real time only to other FortiAnalyzer devices.

D.

Aggregation mode stores logs and content files and uploads them to another FortiAnalyzer device at a scheduled time.

Buy Now
Questions 6

Which two elements are contained in a system backup created on FortiAnalyzer? (Choose two.)

Options:

A.

System information

B.

Logs from registered devices

C.

Report information

D.

Database snapshot

Buy Now
Questions 7

When you perform a system backup, what does the backup configuration contain? (Choose two.)

Options:

A.

Generated reports

B.

Device list

C.

Authorized devices logs

D.

System information

Buy Now
Questions 8

What are two effects of enabling auto-cache in a FortiAnalyzer report? (Choose two.)

Options:

A.

The size of newly generated reports is optimized to conserve disk space.

B.

FortiAnalyzer local cache is used to store generated reports.

C.

When new logs are received, the hard-cache data is updated automatically.

D.

The generation time for reports is decreased.

Buy Now
Questions 9

In order for FortiAnalyzer to collect logs from a FortiGate device, what configuration is required? (Choose two.)

Options:

A.

Remote logging must be enabled on FortiGate

B.

Log encryption must be enabled

C.

ADOMs must be enabled

D.

FortiGate must be registered with FortiAnalyzer

Buy Now
Questions 10

FortiAnalyzer uses the Optimized Fabric Transfer Protocok (OFTP) over SSL for what purpose?

Options:

A.

To upload logs to an SFTP server

B.

To prevent log modification during backup

C.

To send an identical set of logs to a second logging server

D.

To encrypt log communication between devices

Buy Now
Questions 11

Refer to the exhibit.

FCP_FAZ_AD-7.4 Question 11

Which two statements are true regarding enabling auto-cache on FortiAnalyzer? (Choose two.)

Options:

A.

Report size will be optimized to conserve disk space on FortiAnalyzer.

B.

Reports will be cached in the memory.

C.

This feature is automatically enabled for scheduled reports.

D.

Enabling auto-cache reduces report generation time for reports that require a long time to assemble datasets.

Buy Now
Questions 12

What happens when the IOC breach detection engine on FortiAnalyzer finds web logs that match a blocklisted IP address?

Options:

A.

The endpoint is marked as Compromised and. optionally, can be put in quarantine.

B.

FortiAnalyzer flags the associated host for further analysis.

C.

A new Infected entry is added for the corresponding endpoint.

D.

The detection engine classifies those logs as Suspicious

Buy Now
Questions 13

If you upgrade your FortiAnalyzer firmware, what report elements can be affected?

Options:

A.

Output profiles

B.

Report settings

C.

Report scheduling

D.

Custom datasets

Buy Now
Questions 14

What FortiGate process caches logs when FortiAnalyzer is not reachable?

Options:

A.

logfiled

B.

sqlplugind

C.

oftpd

D.

miglogd

Buy Now
Questions 15

Which statement when you are upgrading the firmware on an HA cluster made up of three FortiAnalyzer devices is true?

Options:

A.

You can perform the firmware upgrade using only a console connection.

B.

All FortiAnalyzer devices will be upgraded at the same time.

C.

Enabling uninterruptible-upgrade prevents normal operations from being interrupted during the upgrade.

D.

First, upgrade the secondary devices, and then upgrade the primary device.

Buy Now
Questions 16

An administrator has moved FortiGate A from the root ADOM to ADOM1.

Which two statements are true regarding logs? (Choose two.)

Options:

A.

Analytics logs will be moved to ADOM1 from the root ADOM automatically.

B.

Archived logs will be moved to ADOM1 from the root ADOM automatically.

C.

Logs will be presented in both ADOMs immediately after the move.

D.

Analytics logs will be moved to ADOM1 from the root ADOM after you rebuild the ADOM1 SQL database.

Buy Now
Questions 17

What is the purpose of trigger variables?

Options:

A.

To display statistics about the playbook runtime

B.

To use information from the trigger to filter the action in a task

C.

To provide the trigger information to make the playbook start running

D.

To store the start times of playbooks with On_Schedule triggers

Buy Now
Questions 18

Refer to the exhibit.

FCP_FAZ_AD-7.4 Question 18

Which image corresponds to the packet capture shown in the exhibit?

A)

FCP_FAZ_AD-7.4 Question 18

B)

FCP_FAZ_AD-7.4 Question 18

C)

FCP_FAZ_AD-7.4 Question 18

D)

FCP_FAZ_AD-7.4 Question 18

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 19

Refer to the exhibit.

FCP_FAZ_AD-7.4 Question 19

The exhibit shows the creation of a new administrator on FortiAnalyzer. The new account uses the credentials stored on an LDAP server.

Why would an administrator configure a password for this account?

Options:

A.

This password is used if the authentication server becomes unreachable.

B.

This password authenticates FortiAnalyzer aqainst the LDAP server.

C.

This password is set to comply with FortiAnalvzer password policy

D.

This password is required because this is a restricted user.

Buy Now
Questions 20

Which SQL query is in the correct order to query the database in the FortiAnslyzer?

Options:

A.

SELECT devid FROM Slog GROOP BY devid WHERE * user' =* USERl'

B.

SELECT devid WHERE 'u3er'='USERl' FROM $ log GROUP BY devid

C.

SELECT devid FROM Slog- WHERE *user' =' USERl' GROUP BY devid

D.

FROM Slog WHERE 'user* =' USERl' SELECT devid GROUP BY devid

Buy Now
Questions 21

Which two statements are true regarding log fetching on FortiAnalyzer? (Choose two.)

Options:

A.

A FortiAnalyzer device can perform either the fetch server or client role, and it can perform two roles at the same time with the same FortiAnalyzer devices at the other end.

B.

Log fetching can be done only on two FortiAnalyzer devices that are running the same firmware version.

C.

Log fetching allows the administrator to fetch analytics logs from another FortiAnalyzer for redundancy.

D.

Log fetching allows the administrator to run queries and reports against historical data by retrieving archived logs from one FortiAnalyzer device and sending them to another FortiAnalyzer device.

Buy Now
Questions 22

Which statements are true regarding securing communications between FortiAnalyzer and FortiGate with SSL? (Choose two.)

Options:

A.

SSL is the default setting.

B.

SSL communications are auto-negotiated between the two devices.

C.

SSL can send logs in real-time only.

D.

SSL encryption levels are globally set on FortiAnalyzer.

E.

FortiAnalyzer encryption level must be equal to, or higher than, FortiGate.

Buy Now
Questions 23

Which statement is true about sending notifications with incident updates?

Options:

A.

Notifications can be sent only when an incident is updated or deleted.

B.

If you use multiple fabric connectors, all connectors must have the same notification settings

C.

Notifications can be sent only by email.

D.

You can send notifications to multiple external platforms

Buy Now
Questions 24

Logs are being deleted from one of the ADOMs earlier than the configured setting for archiving in the data

policy.

What is the most likely problem?

Options:

A.

CPU resources are too high

B.

Logs in that ADOM are being forwarded, in real-time, to another FortiAnalyzer device

C.

The total disk space is insufficient and you need to add other disk

D.

The ADOM disk quota is set too low, based on log rates

Buy Now
Questions 25

Refer to the exhibit.

FCP_FAZ_AD-7.4 Question 25

Based on the partial outputs displayed, which devices can be members of a FortiAnalyzer Fabric?

Options:

A.

FortiAnalyzerl and FortiAnalyzer3

B.

FortiAnalyzer1 and FortiAnalyzer2

C.

All devices listed can be members

D.

FortiAnalyzer2 and FortiAnalyzer3

Buy Now
Questions 26

Which process is responsible for enforcing the archive file size?

Options:

A.

oftpd

B.

logfiled

C.

miglogd

D.

sqlplugind

Buy Now
Questions 27

What are two advantages of setting up fabric ADOM? (Choose two.)

Options:

A.

It can be used for fast data processing and log correlation

B.

It can be used to facilitate communication between devices in same Security Fabric

C.

It can include all Fortinet devices that are part of the same Security Fabric

D.

It can include only FortiGate devices that are part of the same Security Fabric

Buy Now
Questions 28

You are using RAID with a FortiAnalyzer that supports software RAID, and one of the hard disks on

FortiAnalyzer has failed.

What is the recommended method to replace the disk?

Options:

A.

Shut down FortiAnalyzer and then replace the disk

B.

Downgrade your RAID level, replace the disk, and then upgrade your RAID level

C.

Clear all RAID alarms and replace the disk while FortiAnalyzer is still running

D.

Perform a hot swap

Buy Now
Questions 29

Refer to the exhibit.

FCP_FAZ_AD-7.4 Question 29

What is the purpose of configuring FortiAnalyzer with the settings displayed in the image?

Options:

A.

To increase reliability

B.

To expand bandwidth

C.

To maximize resiliency

D.

To improve security

Buy Now
Questions 30

In Log View, you can use the Chart Builder feature to build a dataset and chart based on the filtered search results.

Similarly, which feature you can use for FortiView?

Options:

A.

Export to Report Chart

B.

Export to PDF

C.

Export to Chart Builder

D.

Export to Custom Chart

Buy Now
Questions 31

Which statement is true about ADOMs?

Options:

A.

A fabric ADOM can include all the device types supported by FortiAnalyzer.

B.

When a FortiAnalyzer Fabric is implemented the default ADOM mode is set to advanced.

C.

In normal mode, you cannot change the disk quota of the ADOM after its creation.

D.

You can change the ADOM mode only through the GUI.

Buy Now
Questions 32

How can you attach a report to an incident?

Options:

A.

By attaching it to an event handler alert

B.

By editing the settings of the desired report

C.

From the properties of an existing incident

D.

Saving it in JSON format, and then importing it

Buy Now
Questions 33

Refer to the exhibit.

FCP_FAZ_AD-7.4 Question 33

What does the data point at 12:20 indicate?

Options:

A.

The performance of FortiAnalyzer is below the baseline.

B.

FortiAnalyzer is using its cache to avoid dropping logs.

C.

The log insert lag time is increasing.

D.

The sqlplugind service is caught up with new logs.

Buy Now
Questions 34

Which two methods can you use to restrict administrative access on FortiAnalyzer? (Choose two.)

Options:

A.

Configure trusted hosts.

B.

Limit access to specific virtual domains.

C.

Fabric connectors to external LDAP servers.

D.

Use administrator profiles.

Buy Now
Questions 35

What statements are true regarding FortiAnalyzer 's treatment of high availability (HA) dusters? (Choose two)

Options:

A.

FortiAnalyzer distinguishes different devices by their serial number.

B.

FortiAnalyzer receives logs from d devices in a duster.

C.

FortiAnalyzer receives bgs only from the primary device in the cluster.

D.

FortiAnalyzer only needs to know (he serial number of the primary device in the cluster-it automaticaly discovers the other devices.

Buy Now
Questions 36

Which log will generate an event with the status Contained?

Options:

A.

An IPS log with action=pass.

B.

A WebFilter log with action=dropped.

C.

An AV log with action=quarantine.

D.

An AppControl log with action=blocked.

Buy Now
Questions 37

What must you configure on FortiAnalyzer to upload a FortiAnalyzer report to a supported external server?

(Choose two.)

Options:

A.

SFTP, FTP, or SCP server

B.

Mail server

C.

Output profile

D.

Report scheduling

Buy Now
Questions 38

Which two statements regarding the log synchronization states for HA on FortiAnalyzer are true? (Choose two.)

Options:

A.

With Initial Logs Sync, when you add a unit to an HA cluster, the primary device synchronizes its logs with the backup device.

B.

By default, Log Data Sync is disabled on all backup devices.

C.

When Log Data Sync is turned on, the backup device reboots and then rebuilds the log database with the synchronized logs.

D.

Log Data Sync provides real-time log synchronization to all backup devices.

Buy Now
Questions 39

What are offline logs on FortiAnalyzer?

Options:

A.

Compressed logs, which are also known as archive logs, are considered to be offline logs.

B.

When you restart FortiAnalyzer. all stored logs are considered to be offline logs.

C.

Logs that are indexed and stored in the SQL database.

D.

Logs that are collected from offline devices after they boot up.

Buy Now
Questions 40

What is required to authorize a FortiGate on FortiAnalyzer using Fabric authorization?

Options:

A.

A FortiGate ADOM

B.

The FortiGate serial number

C.

A pre-shared key

D.

Valid FortiAnalyzer credentials

Buy Now
Questions 41

Which log type does the FortiAnalyzer indicators of compromise feature use to identify infected hosts?

Options:

A.

Antivirus logs

B.

Web filter logs

C.

IPS logs

D.

Application control logs

Buy Now
Questions 42

Refer to the exhibit.

FCP_FAZ_AD-7.4 Question 42

The capture displayed was taken on a FortiAnalyzer.

Why is a single IP address shown as the source for all logs received?

Options:

A.

FortiAnalyzer is using the device MAC addresses to differentiate their logs.

B.

The logs belong to devices that are part of a high availability (HA) cluster.

C.

FortiAnalyzer is receiving logs from the root FortiGate of a Security Fabric.

D.

The device sending logs has two VDOMs in the same ADOM.

Buy Now
Questions 43

What statements are true regarding disk log quota? (Choose two)

Options:

A.

The FortiAnalyzer stops logging once the disk log quota is met.

B.

The FortiAnalyzer automatically sets the disk log quota based on the device.

C.

The FortiAnalyzer can overwrite the oldest logs or stop logging once the disk log quota is met.

D.

The FortiAnalyzer disk log quota is configurable, but has a minimum o 100mb a maximum based on the reserved system space.

Buy Now
Questions 44

Which two statements are true regarding ADOM modes? (Choose two.)

Options:

A.

You can only change ADOM modes through CLI.

B.

In normal mode, the disk quota of the ADOM is fixed and cannot be modified, but in advance mode, the disk quota of the ADOM is flexible because new devices are added to the ADOM.

C.

In an advanced mode ADOM. you can assign FortiGate VDOMs from a single FortiGate device to multiple FortiAnalyzer ADOMs.

D.

Normal mode is the default ADOM mode.

Buy Now
Questions 45

Which two methods can you use to send event notifications when an event occurs that matches a configured

event handler? (Choose two.)

Options:

A.

SMS

B.

Email

C.

SNMP

D.

IM

Buy Now
Questions 46

What is the purpose of a predefined template on the FortiAnalyzer?

Options:

A.

It can be edited and modified as required

B.

It specifies the report layout which contains predefined texts, charts, and macros

C.

It specifies report settings which contains time period, device selection, and schedule

D.

It contains predefined data to generate mock reports

Buy Now
Questions 47

What are offline logs on FortiAnalyzer?

Options:

A.

Compressed logs, also known as archive logs

B.

Logs that are indexed and stored in the SQL database

C.

Any logs collected from offline devices after they boot up

D.

Real-time logs that are not yet indexed

Buy Now
Questions 48

Which statement regarding the FortiAnalyzer Fabric is true?

Options:

A.

The Fabric supervisor collects logs from the Fabric members.

B.

Logging devices can register to the Fabric supervisor or to Fabric members.

C.

Fabric members support HA.

D.

Administrators can create new incidents from the Fabric supervisor.

Buy Now
Questions 49

Which process caches logs on FortiGate when FortiAnalyzer is not reachable?

Options:

A.

logfiled

B.

miglogd

C.

sqlplugind

D.

oftpd

Buy Now
Questions 50

By default, what happens when a log file reaches its maximum file size?

Options:

A.

FortiAnalyzer overwrites the log files.

B.

FortiAnalyzer stops logging.

C.

FortiAnalyzer rolls the active log by renaming the file.

D.

FortiAnalyzer forwards logs to syslog.

Buy Now
Questions 51

Refer to the exhibit.

FCP_FAZ_AD-7.4 Question 51

The exhibit shows “remoteservergroup” is an authentication server group with LDAP and RADIUS servers.

Which two statements express the significance of enabling “Match all users on remote server” when configuring a new administrator? (Choose two.)

Options:

A.

It creates a wildcard administrator using LDAP and RADIUS servers.

B.

Administrator can log in to FortiAnalyzer using their credentials on remote servers LDAP and RADIUS.

C.

Use remoteadmin from LDAP and RADIUS servers will be able to log in to FortiAnalyzer at anytime.

D.

It allows administrators to use two-factor authentication.

Buy Now
Questions 52

Refer to the exhibit.

FCP_FAZ_AD-7.4 Question 52

Which statement is correct regarding the event displayed?

Options:

A.

The security risk was blocked or dropped.

B.

The security event risk is considered open.

C.

An incident was created from this event.

D.

The risk source is isolated.

Buy Now
Questions 53

How do you restrict an administrator’s access to a subset of your organization’s ADOMs?

Options:

A.

Set the ADOM mode to Advanced

B.

Assign the ADOMs to the administrator’s account

C.

Configure trusted hosts

D.

Assign the default Super_User administrator profile

Buy Now
Questions 54

Refer to the exhibit.

FCP_FAZ_AD-7.4 Question 54

Based on the partial outputs displayed, which devices can be members of a FortiAnalyzer Fabric?

Options:

A.

FortiAnalyzer1 and FortiAnalyzer3

B.

All devices listed can be members.

C.

FortiAnalyzer1 and FortiAnalyzer2

D.

FortiAnalyzer2 and FortiAnalyzer3

Buy Now
Exam Code: FCP_FAZ_AD-7.4
Exam Name: FCP - FortiAnalyzer 7.4 Administrator
Last Update: Aug 12, 2025
Questions: 183

PDF + Testing Engine

$57.75  $164.99

Testing Engine

$43.75  $124.99
buy now FCP_FAZ_AD-7.4 testing engine

PDF (Q&A)

$36.75  $104.99
buy now FCP_FAZ_AD-7.4 pdf
dumpsmate guaranteed to pass
24/7 Customer Support

DumpsMate's team of experts is always available to respond your queries on exam preparation. Get professional answers on any topic of the certification syllabus. Our experts will thoroughly satisfy you.

Site Secure

mcafee secure

TESTED 18 Aug 2025