Pass the Fortinet Fortinet Certified Professional Security Operations FCP_FAZ_AN-7.4 Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

A playbook contains five tasks in total. An administrator runs the playbook and four out of five tasks finish successfully, but one task fails.

What will be the status of the playbook after it is run?

Options:

A.

Attention required


B.

Upstream_failed


C.

Failed


D.

Success


Expert Solution
Questions # 2:

You created a playbook on FortiAnalyzer that uses a FortiOS connector.

When configuring the FortiGate side, which type of trigger must be used so that the actions in an automation stich are available in the FortiOS connector?

Options:

A.

FortiAnalyzer Event Handler


B.

Fabric Connector event


C.

FortiOS Event Log


D.

Incoming webhook


Expert Solution
Questions # 3:

Exhibit.

Question # 3

What is the purpose of using the Chart Builder feature On FortiAnalyzer?

Options:

A.

To build a chart automatically based on the top 100 log entries


B.

To add charts directly to generate reports in the current ADOM.


C.

To add a new chart under FortiView to be used in new reports


D.

To build a dataset and chart based on the filtered search results


Expert Solution
Questions # 4:

You must find a specific security event log in the FortiAnalyzer logs displayed in FortiView, but, so far, you have been uncuccessful.

Which two tasks should you perform to investigate why you are having this issue? (Choose two.)

Options:

A.

Open .gz log files in FortiView.


B.

Rebuild the SQL database and check FortiView.


C.

Review the ADOM data policy


D.

Check logs in the Log Browse


Expert Solution
Questions # 5:

You are trying to configure a task in the playbook editor to run a report.

However, when you try to select the desired playbook, you do to see it listed.

What is the reason?

Options:

A.

The report does not have auto-cache and extended log filtering enabled.


B.

The playbook is currently running and will be available after it is finished.


C.

You must create a trigger to run the report first.


D.

The report has no result and must be reconfigured.


Expert Solution
Questions # 6:

Exhibit.

Question # 6

A fortiAnalyzer analyst is customizing a SQL query to use in a report.

Which SQL query should the analyst run to get the expected results?

A)

Question # 6

B)

Question # 6

C)

Question # 6

D)

Question # 6

Options:

A.

Option A


B.

Option B


C.

Option C


D.

Option D


Expert Solution
Questions # 7:

Exhibit.

Question # 7

Based on the partial outputs displayed, which devices can be members of a FotiAnalyzer Fabric?

Options:

A.

FortiAnalayzer1 and FortiAnalyzer3


B.

FortiAnalyzer1 and FortiAnalyzer2


C.

FortiAnalyzer2 and FortiAnalyzer3


D.

All devices listed can be members.


Expert Solution
Questions # 8:

As part of your analysis, you discover that a Medium severity level incident is fully remediated.

You change the incident status to Closed:Remediated.

Which statement about your update is true?

Options:

A.

The incident can no longer be deleted.


B.

The corresponding event will be marked as Mitigated.


C.

The incident dashboard will be updated.


D.

The incident severity will be lowered.


Expert Solution
Questions # 9:

Which statement correctly describes one Difference between templates and reports?

Options:

A.

Reports provide mora configuration options than templates


B.

Templates can be cloned, but reports cannot be cloned.


C.

Reports support macros, but templates do not.


D.

Template are mapped to device groups. while reports are mapped to ADOMs


Expert Solution
Questions # 10:

You find that as part of your role as an analyst, you frequently search log View using the same parameters.

Instead of defining your search filters repeatedly, what can you do to save time?

Options:

A.

Configure a custom dashboard.


B.

Configure a custom view.


C.

Configure a data selector.


D.

Configure a marco and apply it to device groups.


Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions