Fortinet NSE5_FAZ-7.2 Exam Practice Questions (P. 4)
- Full Access (46 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #16
Why must you wait for several minutes before you run a playbook that you just created?
- AFortiAnalyzer needs that time to parse the new playbook.Most Voted
- BFortiAnalyzer needs that time to back up the current playbooks.
- CFortiAnalyzer needs that time to ensure there are no other playbooks running.
- DFortiAnalyzer needs that time to debug the new playbook.
Correct Answer:
A
A

Indeed, after crafting a new playbook in FortiAnalyzer, it's mandatory to wait a few minutes before its execution. This delay allows the system sufficient time to properly parse and assimilate the playbook into its operations. Kicking off a playbook too soon, especially if it's configured with an ON_DEMAND trigger, can result in operational errors, as the system hasn't had the necessary time to fully integrate the new configurations. Being aware of this ensures smoother and error-free playbook implementations.
send
light_mode
delete
Question #17
Refer to the exhibit.

Based on the partial outputs displayed, which devices can be members of a FortiAnalyzer Fabric?

Based on the partial outputs displayed, which devices can be members of a FortiAnalyzer Fabric?
- AFortiAnalyzer1 and FortiAnalyzer3
- BFortiAnalyzer1 and FortiAnalyzer2
- CAll devices listed can be membersMost Voted
- DFortiAnalyzer2 and FortiAnalyzer3
Correct Answer:
B
B
send
light_mode
delete
Question #18
An administrator has configured the following settings:
config system fortiview setting
set resolve-ip enable
end
What is the significance of running this command?
config system fortiview setting
set resolve-ip enable
end
What is the significance of running this command?
- AUse this command only if the source IP addresses are not resolved on FortiGate.
- BIt resolves the source and destination IP addresses to a hostname in FortiView on FortiAnalyzer.
- CIt resolves the destination IP address to a hostname in FortiView on FortiAnalyzer.Most Voted
- DYou must configure local DNS servers on FortiGate for this command to resolve IP addresses on FortiAnalyzer.
Correct Answer:
B
B

The command 'set resolve-ip enable' in the FortiAnalyzer FortiView settings is pivotal as it enables the resolution of both source and destination IP addresses into hostnames. This feature is dependent on the system DNS settings configured on FortiAnalyzer, which facilitates more intuitive and easier-to-understand reports and logs by translating numerical IP addresses to human-readable hostnames, thus enhancing the analysis and monitoring processes.
send
light_mode
delete
Question #19
Refer to the exhibit.

Laptop1 is used by several administrators to manage FortiAnalyzer. You want to configure a generic text filter that matches all login attempts to the web interface generated by any user other than “admin”, and coming from Laptop1.
Which filter will achieve the desired result?

Laptop1 is used by several administrators to manage FortiAnalyzer. You want to configure a generic text filter that matches all login attempts to the web interface generated by any user other than “admin”, and coming from Laptop1.
Which filter will achieve the desired result?
- Aoperation~login & dstip==10.1.1.210 & user!~admin
- Boperation~login & srcip==10.1.1.100 & dstip==10.1.1.210 & user==admin
- Coperation~login & performed_on=="GUI(10.1.1.210)" & user!=admin
- Doperation~login & performed_on=="GUI(10.1.1.100)" & user!=adminMost Voted
Correct Answer:
D
D
send
light_mode
delete
Question #20
Which two actions should an administrator take to view Compromised Hosts on FortiAnalyzer? (Choose two.)
- AEnable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent to FortiAnalyzer.Most Voted
- BSubscribe FortiAnalyzer to FortiGuard to keep its local threat database up to date.Most Voted
- CMake sure all endpoints are reachable by FortiAnalyzer.
- DEnable device detection on the FortiGate devices that are sending logs to FortiAnalyzer.
Correct Answer:
AB
AB

To effectively spot Compromised Hosts on your FortiAnalyzer, it's crucial to first empower FortiGate devices with web filtering in their firewall policies. Ensure these logs are transmitted to FortiAnalyzer as this provides the necessary data for analysis. Likewise, keeping FortiAnalyzer's local threat database updated by subscribing to FortiGuard optimizes the detection accuracy of potential threats, as fresh intel is crucial for robust security measures. Together, these settings bolster the system’s capacity to identify and react to security threats depicted in the logs.
send
light_mode
delete
All Pages