Pass the Fortinet Fortinet Certified Professional Security Operations FCP_FAZ_AN-7.4 Questions and answers with CertsForce

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which log will generate an event with the status Contained?

Options:

A.

An AV log with action=quarantine.


B.

An IPS log with action=pass.


C.

A WebFilter log will action=dropped.


D.

An AppControl log with action=blocked.


Expert Solution
Questions # 12:

Refer to the exhibit.

Question # 12

What can you conclude about the output?

Options:

A.

The low indexing values require investigation.


B.

The output is not ADOM specific.


C.

There are more event logs than traffic logs.


D.

The log rate higher than the message rate is not normal.


Expert Solution
Questions # 13:

Refer to the exhibit with partial output:

Question # 13

Your colleague exported a playbook and has sent it to you for review. You open the file in a text editor and observer the output as shown in the exhibit.

Which statement about the export is true?

Options:

A.

The export data type is zipped.


B.

The playbook is misconfigured.


C.

The option to include the connector was not selected.


D.

Your colleague put a password on the export.


Expert Solution
Questions # 14:

Exhibit.

Question # 14

What can you conclude from this output?

Options:

A.

There is not disk quota allocated to quarantining files.


B.

FGT_B is the Security Fabric root.


C.

The allocated disk quote to ADOM1 is 3 GB.


D.

Archive logs are using more space than analytic logs.


Expert Solution
Questions # 15:

You are tasked with finding logs corresponding to a suspected attack on your network.

You need to use an interface where all identified threats within timeframe are listed and organized. You also need to be able to quickly export the information to a PDF file.

Where can you go to accomplish this task?

Options:

A.

Log Browse


B.

Log View


C.

Fabric View


D.

FortiView


Expert Solution
Questions # 16:

Which two statements about exporting and importing playbacks are true? (Choose two.)

Options:

A.

A playbook that was disabled when it was exported mil be disabled when it is imported.


B.

Playbooks can so imported 10 a different FortiAnayzer device, but only if the connectors already exist


C.

You can import a playbook even if there is another one win the same name in the destination


D.

You can export only one playbook at a time.


Expert Solution
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions