This is a timed quiz.
You have 1 hour to complete the 44 questions in this quiz.
On FortiAnalyzer, what is a wildcard administrator account?
An account that permits access to members of a LDAP group
An account that allows guest access with read-only privileges
An account that requires two-factor authentication
An account that validates against any user account on a FortiAuthenticator
Which FortiAnalyzer feature allows you to retrieve the archived logs matching a specific timeframe from another FortiAnalyzer device?
Log forwarding in aggregation mode
log upload
log fetching
Indicators of Compromise
How does FortiAnalyzer retrieve specific log data from the database?
SQL FROM statement
SQL GET statement
SQL SELECT statement
SQL EXTRACT statement
Logs are being deleted from one of your ADOMs earlier than the configured setting for archiving in data policy. What is the most likely problem?
Logs in that ADOM are being forwarded in real-time to another Fortianalyzer device
CPU resources are too high
The ADOM disk quota is set too low based on log rates
The total disk space is insufficient and you need to add other disk
What FortiView tool can you use to automatically build a dataset and chart based on a filtered search result
Chart Builder
Dataset Library
Custom View
Export to Report Chart
FortiAnalyzer uses the Optimized Fabric Transfer Protocol (OFTP) over SSL for what purpose?
To prevent log modification during backup
To send an identical set of logs to a second logging server
To encrypt log communication between devices
To upload logs to a SFTP server
What is the recommended method of expanding disk space on a FortiAnalyzer VM?
From the VM host manager, add an additional virtual disk and use the #execute lvm extend <disk number> command to expand the storage
From the VM host manager, expand the size of the existing virtual disk
From the VM host manager, add an additional disk and rebuild your RAID array
From the VM host manager, expand the size of the existing virtual disk and use the #execute format disk command to reformat the disk
What FortiGate process caches logs when FortiAnalyzer is not reachable?
oftpd
miglogd
sqlplugind
logfield
What is the purpose of the followinf CLI command?
To add the MD5´s hash value only
To encrypt log communications
To add unique tag to each log to provide that it came from this FortiAnalyzer
To add a log file checksum
In FortiAnalyzer´s FortiView, source and destination IP addresses from FortiGate devices are not resolving to a hostname. How can you resolve the source and destination IPs, without introducing any additional performance impact to FortiAnalyzer?
Configure # set resolve-ip enable in the system FortiView settings
Resolve IPs on FortiGate
Configure local DNS server on FortiAnalyzer
Resolve IPs a per-ADOM basis to reduce delay on FortiView while IPs resolve
What is the purpose of employing RAID with FortiAnalyzer?
To provide data separation between ADOMs
To separate analytical and archive data
To back up your logs
To introduce redundancy to your log data
What happens when a log file saved on FortiAnalyzer disk reaches the size spechified in the device log settings?
The log file is stored as a raw log and is available for analytic support
The log file rolls over and is archived
The log file is purged from the database
The log file is overwritten
Why is the total quota less than the total system storage?
The oftpd process has not archived the logs yet
The logfield process is just estimating the total quota
Some space is reserved for system use, such as storage of compression files, and temporary report files
3.6% of the system storage is already being used
In order for FortiAnalyzer to collect logs from a FortiGate device, what configuration is required? (Choose two.)
ADOMs must be enabled
Log encryption must be enabled
FortiGate must be registered with FortiAnalyzer
Remote logging must be enabled on FortiGate
What can the CLI command # diagnose test application oftpd 3 help you to determine?
What logs, if any, are reaching FortiAnalyzer
What ADOMs are enabled and configured
What devices and IP addresses are connecting to FortiAnalyzer
What devices are registered and unregistered
If you upgrade your FortiAnalyzer firmware, what report elements can be affected?
Report settings
Report scheduling
Output profiles
Custom datasets
How are logs forwarded when FortiAnalyzer is using aggregation mode?
Logs and content files are stored and uploaded at a schedule time
Logs and content files are forwwarded as they are received
Logs are forwarded ad they are received
Logs are forwarded as they are received and content files are uploaded at a scheduled time
For proper log correlation between the logging devices and FortiAnalyzer, FortiAnalyzer and all registred devices should:
Use DNS
Use host name resolution
Use an NTP server
Use real-time forwarding
What must you configure on FortiAnalyzer report to a supported external server? (Choose two.)
Output profile
SFTP, FTP, or SCP server
Mail server
What does the 1000 MB maximum for disk utilization refer to?
The disk quota for each device in the ADOM
The disk quota for the ADOM type
The disk quota for all devices in the ADOM
The disk quota for thhe FortiAnalyzer model
What purposes does the auto-cache setting on reports server? (Choose two.)
To automatically updates the hcache when new logs arrive
To provide diagnostics on report generation time
To reduce the log insert lag rate
To reduce report generation time
What does the data point at 14:35 tell you?
The sqlplugind daemon is ahead in indexing bt one log
FortiAnalyzer is indexing logs faster than logs are being received
FortiAnalyzer is dropping logs
FortiAnalyzer has temporarily stopped receiving logs so older logs can
You've moved a registered logging device out of one ADOM and into a new ADOM. What happens when you rebuild the new ADOM database?
FortiAnalyzer resets the disk quota of the new ADOM to default
FortiAnalyzer migrates analytics logs to the new ADOM
FortiAnalyzer removes analytics logs from the old ADOM
FortiAnalyzer migrates archive logs to the new ADOM
How can you confoigure FortiAnalzyzer to permit administrator logins from only specific locations?
Use trusted hosts
use administrative profiles
Use secure protocols
Use static routes
What are three different methods you can employ to send event notifications when an event occurs that matches aconfigured event handler?
Email
SMS
SNMP
IM
Syslog
What is the problem with the following SQL SELECT statement?
SELECT dstip as Destination IP, count(*) as session FROM $log-traffic GROUP BY dstip WHERE - 5filter and dstip is not null.
The clauses are not coded in the right sequence.
The clauses are not a log type.
The FROM clause is not required.
SQL queries are case-sensitive.
What remote authentication servers can you configure to validate your FortiAnalyzer administrator logons? (Choose three)
RADIUS
Local
LDAP
PKI
TACACS+
How does the Log View page display logs when ADOMs are enabled?
The Log View page displays logs in ADOMs together so they appear as singledevice.
The Log View page displays logs per ADOM.
The Logs View page cannot display raw logs when ADOMs are enabled.
The Log View page cannot display logs h real-time when ADOMs are enabled.
If RAID isnt supported, what are other types of backup mechanisms ie.methods to preserve your log data in the event of disk failure, deletion, or corruption? (Choose three)
Backing up logs through the Web-based manager or CLI.
Forwarding logs a syslog server.
Uploading logs to an FTP, SFTP, or SCP server.
Archiving logs.
Enabling full archiving.
Refer to the exhibits
You can't use SQL syntax h the Search field of the FortiView > Log View page.
Case Sensitive Search is enabled.
There are no logs that include https as a service.
You can´t search for logs from the FortiView > Log View page.
What is "hot swapping"?
Hot swapping means administrators can confine FortiAnalyzer to write to allhard device in order to make the array fault tolerant.
Hot swapping means administrators can replace a failed disk on devices that support software RAID while the device is still running.
Hot swapping means administrators can ensue the party data of a redundant drive is valid while the device is still running.
Hot swapping means administrators can replace a fated d* on devices that support hardware RAID while the device is still running.
What are the limitations when creating a chart using the Custom Chart wizard? (Choose two)
You cannot search multiple log types (for example, $log-traffic, $log-webfilter).
You cannot select the format of the data - all charts are table charts by default.
You can only create custom charts within the root ADOM only.
You can only select from two variable charts.
What statements are true regarding Administrative Domains (ADOMs)? (Choose three)
ADOMs are a way to group devices for administrators to monitor and manage.
Administrators with the standard_user administrator profile can view all ADOMs.
The Web-based navigation changes when ADOMs are enabled.
The admin administrator can assign one device to multiple ADOMs.
The admin administrator can assign more than one ADOM to a single administrator.
What are the operating modes of FortiAnalyzer? (Choose two)
Standalone
Manager
Analyzer
Collector
What should you always do after erasing the configuration on flash?
Run the excecute reset all-settings command.
Run the execute reboot command.
Run the execute format disk command.
Perform a system backup.
Which external servers can you configure to validate administrator logins? (Choose two)
Syslog.
Administrator logins can only be valdated locally by FortiAnalyzer
RADIUS.
LDAP.
Which database language does FortiAnalyzer support for the purposes of logging and reporting?
SQL.
SSH.
XML.
Which statements about macros are true? (Choose two.)
Macros are abbreviated dataset queries.
Macros are supported in FortiGate ADOMs only
Macros do not need to be associated with a chart
Macros cannot be customized
Which FortiAnalyzer features allow you to automatically build a dataset and based on a filtered search result? (Choose two.)
Chart Builder.
Export to Report Chart (FortiView).
Dataset Library.
Custom View.
When you move a FortiGate device from one ADOM to a new ADOM, what is the purpose of rebuilding the new ADOM database?
To run reports on the device's analytics logs in the new ADOM.
To remove the device's analytics logs from the old ADOM.
To reset the disk quota enforcement to default
To migrate the archive logs to the new ADOM
What compreises (makes up) the disk quota?
SQL tables and archives files.
Archive logs and analytics logs.
Raw logs, archive files, SQL database tables.
Raw logs and archives files
What are event handlers?
Alert notifications
SNMP traps
Threats identified by FortiGuard
Specific matched conditions in the raw logs
It is best practice to upload FortiAnalyzer local logs to a remote server. Which remote servers are supported for the upload? (Choose three.)
SCP
TCP
SFTP
FTP
UDP
How do you restrict an administrator's access to a subset of your organization's ADOMs?
Set the ADOM mode to Advanced.
Configure trusted hosts.
Assign the ADOMs to the administrator´s account.
Assign the default Super_User administrator profile.