New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Fortinet Fortinet Certified Professional Security Operations FCP_FAZ_AN-7.6 Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

Which statement correctly describes one Difference between templates and reports?

Options:

A.

Reports provide mora configuration options than templates


B.

Templates can becloned, but reports cannot be cloned.


C.

Reports support macros, but templates do not.


D.

Template are mapped to device groups. while reports are mapped to ADOMs


Expert Solution
Questions # 2:

(Refer to the exhibit.

Question # 2

Which statement about the displayed event is correct? (Choose one answer))

Options:

A.

An incident was created from this event.


B.

The risk source is isolated.


C.

The security risk was escalated.


D.

The security event risk is considered open.


Expert Solution
Questions # 3:

Exhibit.

Question # 3

Which statement about the event displayed is correct?

Options:

A.

The risk source is isolated.


B.

The security risk was blocked or dropped.


C.

The security event risk is considered open.


D.

An incident was created from this event.


Expert Solution
Questions # 4:

(Which two statements about FortiAnalyzer Fabric deployments are true? (Choose two answers))

Options:

A.

Supervisors can be in high availability (HA) for redundancy purposes only.


B.

Fabric members can operate in analyzer mode only.


C.

Fabric members do not forward their logs to the supervisor.


D.

Supervisors and members must be in the same time zone.


Expert Solution
Questions # 5:

After generating a report, you notice the information you where expecting to see is not included in it. However, you confirm that the logs are there.

Options:

A.

Check the time frame covered by thereport.


B.

Disable auto-cache.


C.

Increase the report utilization quota.


D.

Test the dataset


Expert Solution
Questions # 6:

What are two effects of enabling auto-cache in a FortiAnalyzer report? (Choose two.)

Options:

A.

The generation time for reports is decreased.


B.

When new logs are received, the hard-cache data is updated automatically.


C.

FortiAnalyzer local cache is used to store generated reports.


D.

The size of newly generated reports is optimized to conserve disk space.


Expert Solution
Questions # 7:

Whathappens when the indicator of compromise (IOC) engine on FortiAnalyzer finds web logs that match blacklisted IP addresses?

Options:

A.

FortiAnalyzer flags the associated host for further analysis.


B.

A new infected entry is added for the corresponding endpoint under Compromised Hosts.


C.

The detection engine classifies those logs as Suspicious.


D.

The endpoint is marked as Compromised and, optionally, can be put in quarantine.


Expert Solution
Questions # 8:

Which statement regarding macros on FortiAnalyzer is true?

Options:

A.

Macros are predefined templates for reports and cannot be customized.


B.

Macros are useful in generating excel log files automatically based on the report settings.


C.

Macros are ADOM-specific and each ADOM type have unique macros relevant to that ADOM.


D.

Macros are supported only on the FortiGate ADOMs.


Expert Solution
Questions # 9:

Exhibit.

What can you conclude about these search results? (Choose two.)

Options:

A.

They can be downloaded to a file.


B.

They are sortable by columns and customizable.


C.

They are not available for analysis in FortiView.


D.

They were searched by using textmode.


Expert Solution
Questions # 10:

Which statement about SQL SELECT queries is true?

Options:

A.

They can be used to purge log entries from the database.


B.

They must be followed immediately by a WHEREclause.


C.

They can be used to display the database schema.


D.

They are not used in macros.


Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions