New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Fortinet Fortinet Certified Professional Security Operations FCP_FAZ_AN-7.6 Questions and answers with CertsForce

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

When managing incidents on FortiAnlyzer, what must an analyst be aware of?

Options:

A.

You can manually attach generated reports to incidents.


B.

The status of the incident is always linked to the status of the attach event.


C.

Severity incidents rated with the level High have an initial service-level agreement (SLA) response time of 1 hour.


D.

Incidents must be acknowledged before they can be analyzed.


Expert Solution
Questions # 12:

Which two statements regarding FortiAnalyzer operating modes are true? (Choose two.)

Options:

A.

When running in collector mode, FortiAnalyzer can forward logs to a syslog server.


B.

FortiAnalyzer runs in collector mode by default unless it is configured for HA.


C.

You can create and edit reports when FortiAnalyzer is running in collector mode.


D.

A topology with FortiAnalyzeer devices running in both modes can improve their performance.


Expert Solution
Questions # 13:

What are the two methods you can use to send notifications when an event is generated by an event handler? (Choose two answers)

Options:

A.

Send SNMP trap.


B.

Send an alert through the FortiGuard server.


C.

Send an alert through Fabric connectors.


D.

Send SMS notification


Expert Solution
Questions # 14:

(How does FortiAnalyzer block indicators? (Choose one answer))

Options:

A.

It uses an automation script to update FortiGate with the block list.


B.

It uses a FortiManager connector to send the block list.


C.

It uses a FortiClient EMS connector to send the block list.


D.

It uses a webhook to allow FortiGate to send the block list.


Expert Solution
Questions # 15:

Which two statement regarding the outbreak detection service are true? (Choose two.)

Options:

A.

An additional license is required.


B.

It automatically downloads new event handlers and reports.


C.

Outbreak alerts are available on the root ADOM only.


D.

New alerts are received by email.


Expert Solution
Questions # 16:

Refer to the exhibit.

What can you conclude about the output?

Options:

A.

The low indexing values require investigation.


B.

The output is not ADOM specific.


C.

There are more event logs thantraffic logs.


D.

The log rate higher than the message rate is not normal.


Expert Solution
Questions # 17:

Which two statements about exporting and importing playbacks are true? (Choose two.)

Options:

A.

A playbook that was disabled when it was exported mil be disabled when it is imported.


B.

Playbooks can soimported 10 a different FortiAnayzer device, but only if the connectors already exist


C.

You can import a playbook even if there is another one win the same name in the destination


D.

You can export only one playbook at a time.


Expert Solution
Questions # 18:

What is the purpose of using data selectors when configuring event handlers?

Options:

A.

They filter the types of logs that FortiAnalyzer can accept from registered devices.


B.

They download new filters can be used in event handlers.


C.

They apply their filter criteria to the entire event handler so that you don’t have to configure the same criteria in the individual rules.


D.

They are common filters that can be appliedsimultaneously to all event handlers.


Expert Solution
Questions # 19:

After a generated a repot, you notice the information you were expecting to see in not included in it. However, you confirm that the logs are there:

Which two actions should you perform? (Choose two.)

Options:

A.

Check the time frame covered by the report.


B.

Disable auto-cache.


C.

Increase the report utilization quota.


D.

Test the dataset.


Expert Solution
Questions # 20:

What is the purpose of playbook trigger variables?

Options:

A.

To display statistics about the playbook runtime


B.

To use information from the trigger to filter the action in a task


C.

To provide the trigger information to make the playbook start running


D.

To store the start the times of playbooks with On_Schedule triggers


Expert Solution
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions