Fortinet FCP_FAZ_AN-7.4 Fortinet FCP – FortiAnalyzer 7.4 Analyst Online Training
Fortinet FCP_FAZ_AN-7.4 Online Training
The questions for FCP_FAZ_AN-7.4 were last updated at Feb 22,2025.
- Exam Code: FCP_FAZ_AN-7.4
- Exam Name: Fortinet FCP - FortiAnalyzer 7.4 Analyst
- Certification Provider: Fortinet
- Latest update: Feb 22,2025
What is included in the disk quota for each ADOM on the FortiAnalyzer?
- A . SQL tables and archive files
- B . Raw logs and archive files
- C . Archive logs and analytics logs
- D . Raw logs, archive files, SQL database tables
What are analytics logs on FortiAnalyzer?
- A . Log type Traffic logs.
- B . Logs that roll over when the log file reaches a specific size.
- C . Logs that are indexed and stored in the SQL.
- D . Raw logs that are compressed and saved to a log file.
Refer to the exhibit.
Laptop1 is used by several administrators to manage FortiAnalyzer. You want to configure a generic text filter that matches all login attempts to the web interface generated by any user other than “admin" and coming from Laptop1.
Which filter will achieve the desired result?
- A . operation-login & performed_on=="GUI(10.1.1.100)" & user!=admin
- B . operation-login & srcip==10.1.1.100 & dstip==10.1.1.210 & user==admin
- C . operation-login & dstip==10.1.1.210 & userl-admin
- D . operation-login & performed_on=="GUI(10.1.1.210)’ & user!=admin
Consider the CLI command:
What is the purpose of the command?
- A . To add a unique tag to each log to prove that it came from this FortiAnalyzer
- B . To add a log file checksum
- C . To encrypt log communications
- D . To add the MD5 hash value and authentication code
What two things should an administrator do to view Compromised Hosts on FortiAnalyzer? (Choose two.)
- A . Enable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent to FortiAnalyzer.
- B . Enable device detection on an interface on the FortiGate devices that are connected to the FortiAnalyzer.
- C . Subscribe FortiAnalyzer to FortiGuard to keep its local threat database up-to-date.
- D . Make sure all endpoints are reachable by FortiAnalyzer.
What database language does FortiAnalyzer use for logging and reporting?
- A . XQuery
- B . XML
- C . SQL
- D . Java
An administrator has configured the following settings:
config system global
set log-checksum md5-auth
end
What is the significance of executing this command?
- A . This command records the log file MD5 hash value.
- B . This command records passwords in log files and encrypts them.
- C . This command encrypts log transfer between FortiAnalyzer and other devices
- D . This command records the log file MD5 hash value and authentication code.
What is the main purpose of using an NTP server on FortiAnalyzer and all of its registered devices?
- A . Log correlation
- B . Host name resolution
- C . Log collection
- D . Real-time forwarding
You have recently grouped multiple FortiGate devices into a single ADOM. System Settings > Storage Info shows the quota used.
What does the disk quota refer to?
- A . The maximum disk utilization for each device in the ADOM
- B . The maximum disk utilization for the FortiAnalyzer model
- C . The maximum disk utilization for the ADOM type
- D . The maximum disk utilization for all devices in the ADOM
Which two methods can you use to send event notifications when an event occurs that matches a configured event handler? (Choose two.)
- A . SMS
- B . Email
- C . SNMP
- D . IM