Best Way To Study For Fortinet NSE5_FAZ-7.0 Exam Brilliant NSE5_FAZ-7.0 Exam Questions PDF
Updated Verified Pass NSE5_FAZ-7.0 Exam - Real Questions and Answers
NEW QUESTION # 56
What two things should an administrator do to view Compromised Hosts on FortiAnalyzer? (Choose two.)
- A. Enable device detection on an interface on the FortiGate devices that are connected to the FortiAnalyzer.
- B. Enable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent to FortiAnalyzer.
- C. Make sure all endpoints are reachable by FortiAnalyzer.
- D. Subscribe FortiAnalyzer to FortiGuard to keep its local threat database up-to-date.
Answer: A,D
NEW QUESTION # 57
What must you configure on FortiAnalyzer to upload a FortiAnalyzer report to a supported external server?
(Choose two.)
- A. Output profile
- B. Report scheduling
- C. SFTP, FTP, or SCP server
- D. Mail server
Answer: A,D
Explanation:
https://docs.fortinet.com/document/fortianalyzer/6.0.2/administration-guide/598322/creating-output-profiles
NEW QUESTION # 58
You have recently grouped multiple FortiGate devices into a single ADOM. System Settings > Storage Info shows the quota used.
What does the disk quota refer to?
- A. The maximum disk utilization for all devices in the ADOM
- B. The maximum disk utilization for the FortiAnalyzer model
- C. The maximum disk utilization for each device in the ADOM
- D. The maximum disk utilization for the ADOM type
Answer: A
NEW QUESTION # 59
Refer to the exhibit.
What does the data point at 14:55 tell you?
- A. The sqlplugind daemon is behind in log indexing by two logs
- B. Logs are being dropped
- C. The received rate is almost at its maximum for this device
- D. Raw logs are reaching FortiAnalyzer faster than they can be indexed
Answer: D
NEW QUESTION # 60
Which statement is true about sending notifications with incident updates?
- A. Notifications can be sent only by email.
- B. If you use multiple fabric connectors, all connectors must have the same notification settings
- C. Notifications can be sent only when an incident is updated or deleted.
- D. You can send notifications to multiple external platforms
Answer: C
NEW QUESTION # 61
By default, what happens when a log file reaches its maximum file size?
- A. FortiAnalyzer rolls the active log by renaming the file.
- B. FortiAnalyzer stops logging.
- C. FortiAnalyzer overwrites the log files.
- D. FortiAnalyzer forwards logs to syslog.
Answer: A
NEW QUESTION # 62
Refer to the exhibits.

How many events will be added to the incident created after running this playbook?
- A. Thirteen events will be added.
- B. No events will be added.
- C. Five events will be added.
- D. Ten events will be added.
Answer: D
NEW QUESTION # 63
An administrator has configured the following settings:
config system global
set log-checksum md5-auth
end
What is the significance of executing this command?
- A. This command records the log file MD5 hash value.
- B. This command records passwords in log files and encrypts them.
- C. This command encrypts log transfer between FortiAnalyzer and other devices.
- D. This command records the log file MD5 hash value and authentication code.
Answer: D
NEW QUESTION # 64
Logs are being deleted from one of the ADOMs earlier than the configured setting for archiving in the data policy.
What is the most likely problem?
- A. The total disk space is insufficient and you need to add other disk
- B. CPU resources are too high
- C. The ADOM disk quota is set too low, based on log rates
- D. Logs in that ADOM are being forwarded, in real-time, to another FortiAnalyzer device
Answer: C
Explanation:
Reference:
20logs.htm
NEW QUESTION # 65
For which two SAML roles can the FortiAnalyzer be configured? (Choose two.)
- A. Principal
- B. Service provider
- C. Identity provider
- D. Identity collector
Answer: B,C
Explanation:
Reference:
20the%20identity%20provider%20(IdP,external%20identity%20provider%20is%20available.
https://docs.fortinet.com/document/fortianalyzer/6.2.0/administration-guide/981386/saml-admin-authentication
NEW QUESTION # 66
For which two purposes would you use the command set log checksum? (Choose two.)
- A. To help protect against man-in-the-middle attacks during log upload from FortiAnalyzer to an SFTP server
- B. To send an identical set of logs to a second logging server
- C. To encrypt log communications
- D. To prevent log modification or tampering
Answer: A,D
NEW QUESTION # 67
What statements are true regarding disk log quota? (Choose two)
- A. The FortiAnalyzer disk log quota is configurable, but has a minimum o 100mb a maximum based on the reserved system space.
- B. The FortiAnalyzer stops logging once the disk log quota is met.
- C. The FortiAnalyzer automatically sets the disk log quota based on the device.
- D. The FortiAnalyzer can overwrite the oldest logs or stop logging once the disk log quota is met.
Answer: A,D
NEW QUESTION # 68
What is the purpose of the following CLI command?
- A. To add the MD's hash value and authentication code
- B. To add a log file checksum
- C. To add a unique tag to each log to prove that it came from this FortiAnalyzer
- D. To encrypt log communications
Answer: B
Explanation:
https://docs2.fortinet.com/document/fortianalyzer/6.0.3/cli-reference/849211/global
NEW QUESTION # 69
After you have moved a registered logging device out of one ADOM and into a new ADOM, what is the purpose of running the following CLI command?
execute sql-local rebuild-adom <new-ADOM-name>
- A. To remove the analytics logs of the device from the old database
- B. To reset the disk quota enforcement to default
- C. To populate the new ADOM with analytical logs for the moved device, so you can run reports
- D. To migrate the archive logs to the new ADOM
Answer: C
Explanation:
NEW QUESTION # 70
Which two statements are true regarding high availability (HA) on FortiAnalyzer? (Choose two.)
- A. All devices in a FortiAnalyzer HA cluster must run in the same operation mode: analyzer or collector.
- B. FortiAnalyzer HA supports synchronization of logs as well as some system and configuration settings.
- C. FortiAnalyzer HA implementation is supported by many public cloud infrastructures such as AWS, Microsoft Azure, and Google Cloud.
- D. FortiAnalyzer HA can function without VRRP. and VRRP is required only if you have more than two FortiAnalyzer devices in a cluster.
Answer: A,B
Explanation:
Reference:
FortiAnalyzer HA implementation works only in networks where Virtual Router Redundancy Protocol (VRRP) is permitted. Therefore it may not be supported by some public cloud infrastructures.
NEW QUESTION # 71
Which two of the following must you configure on FortiAnalyzer to email a FortiAnalyzer report externally?
(Choose two.)
- A. SFTP server
- B. Output profile
- C. Report scheduling
- D. Mail server
Answer: B,D
NEW QUESTION # 72
......
Fortinet NSE5_FAZ-7.0 exam is a certification test designed to evaluate the skills and knowledge of candidates in using FortiAnalyzer 7.0 to manage and analyze network security events. NSE5_FAZ-7.0 exam is ideal for professionals who work with Fortinet products and are responsible for monitoring and analyzing network security information. It is a comprehensive, vendor-neutral exam that covers all aspects of FortiAnalyzer 7.0.
Updated PDF (New 2023) Actual Fortinet NSE5_FAZ-7.0 Exam Questions: https://surepass.free4dump.com/NSE5_FAZ-7.0-real-dump.html