Fortinet NSE5_FAZ-6.2 Fortinet NSE 5 – FortiAnalyzer 6.2 Online Training
Fortinet NSE5_FAZ-6.2 Online Training
The questions for NSE5_FAZ-6.2 were last updated at Nov 26,2024.
- Exam Code: NSE5_FAZ-6.2
- Exam Name: Fortinet NSE 5 - FortiAnalyzer 6.2
- Certification Provider: Fortinet
- Latest update: Nov 26,2024
View the exhibit:
What does the 1000MB maximum for disk utilization refer to?
- A . The disk quota for the FortiAnalyzer model
- B . The disk quota for all devices in the ADOM
- C . The disk quota for each device in the ADOM
- D . The disk quota for the ADOM type
When you perform a system backup, what does the backup configuration contain? (Choose two.)
- A . Generated reports
- B . Device list
- C . Authorized devices logs
- D . System information
Which two of the following must you configure on FortiAnalyzer to email a FortiAnalyzer report externally? (Choose two.)
- A . Mail server
- B . Output profile
- C . SFTP server
- D . Report scheduling
B,C
Reference:
https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/6d9f8fb5-6cf4-11e9-81a4-00505692583a/FortiAnalyzer-6.0.5-Administration-Guide.pdf (119)
You are using RAID with a FortiAnalyzer that supports software RAID, and one of the hard disks on FortiAnalyzer has failed.
What is the recommended method to replace the disk?
- A . Shut down FortiAnalyzer and then replace the disk
- B . Downgrade your RAID level, replace the disk, and then upgrade your RAID level
- C . Clear all RAID alarms and replace the disk while FortiAnalyzer is still running
- D . Perform a hot swap
D
Explanation:
Reference: https://www.fortinetguru.com/2016/04/system-settings/6/
What statements are true regarding disk log quota? (Choose two)
- A . The FortiAnalyzer stops logging once the disk log quota is met.
- B . The FortiAnalyzer automatically sets the disk log quota based on the device.
- C . The FortiAnalyzer can overwrite the oldest logs or stop logging once the disk log quota is met.
- D . The FortiAnalyzer disk log quota is configurable, but has a minimum o 100mb a maximum based on the reserved system space.
What purposes does the auto-cache setting on reports serve? (Choose two.)
- A . To reduce report generation time
- B . To automatically update the hcache when new logs arrive
- C . To reduce the log insert lag rate
- D . To provide diagnostics on report generation time
A,B
Explanation:
Reference: https://docs.fortinet.com/document/fortianalyzer/6.0.0/administration-guide/282280/enabling-autocache
Which two statements about log forwarding are true? (Choose two.)
- A . Forwarded logs cannot be filtered to match specific criteria.
- B . Logs are forwarded in real-time only.
- C . The client retains a local copy of the logs after forwarding.
- D . You can use aggregation mode only with another FortiAnalyzer.
B,C
Explanation:
Reference: www.fortinetguru.com/2020/07/log-forwarding-fortianalyzer-fortios-6-2-3/
Which statements are true of Administrative Domains (ADOMs) in FortiAnalyzer? (Choose two.)
- A . ADOMs are enabled by default.
- B . ADOMs constrain other administrator’s access privileges to a subset of devices in the device list.
- C . Once enabled, the Device Manager, FortiView, Event Management, and Reports tab display per ADOM.
- D . All administrators can create ADOMs–not just the admin administrator.
What are the operating modes of FortiAnalyzer? (Choose two)
- A . Standalone
- B . Manager
- C . Analyzer
- D . Collector
View the exhibit.
What does the data point at 14:35 tell you?
- A . FortiAnalyzer is dropping logs.
- B . FortiAnalyzer is indexing logs faster than logs are being received.
- C . FortiAnalyzer has temporarily stopped receiving logs so older logs’ can be indexed.
- D . The sqlplugind daemon is ahead in indexing by one log.
D
Explanation:
Logs are received then they are indexed, no logging server in the world can index logs faster than they are received. When FAZ receives raw logs, they are inserted
(indexed) by the SQL database and the sqlplugind daemon, this graph shows that FAZ received 3 logs and sqlplugind indexed 4.