Fortinet FCP_FAZ_AD-7.4 FCP – FortiAnalyzer 7.4 Administrator Online Training
Fortinet FCP_FAZ_AD-7.4 Online Training
The questions for FCP_FAZ_AD-7.4 were last updated at Feb 22,2025.
- Exam Code: FCP_FAZ_AD-7.4
- Exam Name: FCP - FortiAnalyzer 7.4 Administrator
- Certification Provider: Fortinet
- Latest update: Feb 22,2025
Refer to the exhibit.
The exhibit shows the creation of a new administrator on FortiAnalyzer. The new account uses the credentials stored on an LDAP server.
Why would an administrator configure a password for this account?
- A . This password is used if the authentication server becomes unreachable.
- B . This password authenticates FortiAnalyzer aqainst the LDAP server.
- C . This password is set to comply with FortiAnalvzer password policy
- D . This password is required because this is a restricted user.
In a Fortinet Security Fabric, what can make an upstream FortiGate create traffic logs associated with sessions initiated on downstream FortiGate devices?
- A . The traffic destination is another FortiGate in the fabric.
- B . The upstream FortiGate is configured to do NAT
- C . Log redundancy is configured in the fabric.
- D . The downstream device cannot connect to FortiAnalyzer.
Which two statements about high availability (HA) on FortiAnalyzer are true? (Choose two.)
- A . FortiAnalyzer HA supports synchronization of logs as well as some system and configuration settings.
- B . FortiAnalyzer HA active-passive mode can function without VRRP.
- C . All devices in a FortiAnalyzer HA cluster must run in the same operation mode, either analyzer mode or collector mode.
- D . All devices in a FortiAnalyzer HA cluster must have the same available disk space.
Which two statements about deleting ADOMs are true? (Choose two.)
- A . Logs must be purged or migrated before you can delete an ADOM.
- B . ADOMs with registered devices cannot be deleted.
- C . Default ADOMs cannot be deleted.
- D . The status of the ADOMs must be unlocked.
Refer to the exhibit.
The capture displayed was taken on a FortiAnalyzer.
Why is a single IP address shown as the source for all logs received?
- A . FortiAnalyzer is using the device MAC addresses to differentiate their logs.
- B . The logs belong to devices that are part of a high availability (HA) cluster.
- C . FortiAnalyzer is receiving logs from the root FortiGate of a Security Fabric.
- D . The device sending logs has two VDOMs in the same ADOM.
What does the disk status Degraded mean for RAID management?
- A . The hard drive is no longer being used by the RAID controller.
- B . One or more drives are missing from the FortiAnalyzer unit.
- C . The device is writing data to the disk to restore the volume to an optimal state.
- D . FortiAnalyzer determined that the parity data in the disk is not valid.
Which process is responsible for enforcing the log file size?
- A . oftpd
- B . miglogd
- C . sqlplugind
- D . logfiled
Which two statements about FortiAnalyzer operating modes are true? (Choose two.)
- A . When in collector mode, FortiAnalyzer offloads the log receiving task to the analyzer.
- B . When in analyzer mode, FortiAnalyzer supports event management and reporting features.
- C . For the collector, you should allocate most of the disk space to analytics logs.
- D . Analyzer mode is the default operating mode.
Which two statements regarding FortiAnalyzer log forwarding modes are true? (Choose two.)
- A . Both modes, forwarding and aggregation, support encryption of logs between devices.
- B . In aggregation mode, you can forward logs to syslog and CEF servers.
- C . Forwarding mode forwards logs in real time only to other FortiAnalyzer devices.
- D . Aggregation mode stores logs and content files and uploads them to another FortiAnalyzer device at a scheduled time.
You are trying to initiate an authorization request from FortiGate to FortiAnalyzer, but the Security Fabric window does not open when you click Authorize.
Which two reasons can cause this to happen? (Choose two.)
- A . A pre-shared key needs to be established on both sides.
- B . The management computer does not have connectivity to the authorization IP address and port combination.
- C . The Security Fabric root is unauthorized and needs to be added as a trusted host.
- D . The fabric authorization settings on FortiAnalyzer are misconfigured.