Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: s2p65

Easiest Solution 2 Pass Your Certification Exams

FCP_FAZ_AN-7.6 Fortinet NSE 5 - FortiAnalyzer 7.6 Analyst Free Practice Exam Questions (2026 Updated)

Prepare effectively for your Fortinet FCP_FAZ_AN-7.6 Fortinet NSE 5 - FortiAnalyzer 7.6 Analyst certification with our extensive collection of free, high-quality practice questions. Each question is designed to mirror the actual exam format and objectives, complete with comprehensive answers and detailed explanations. Our materials are regularly updated for 2026, ensuring you have the most current resources to build confidence and succeed on your first attempt.

Page: 1 / 1
Total 67 questions

Which two statements about local logs on FortiAnalyzer are true? (Choose two.)

A.

They are not supported in FortiView.

B.

You can view playbook logs for all ADOMs in the root ADOM.

C.

Event logs show system-wide information, whereas application logs are ADOM specific.

D.

Event logs are available only in the root ADOM.

After a generated a repot, you notice the information you were expecting to see in not included in it. However, you confirm that the logs are there:

Which two actions should you perform? (Choose two.)

A.

Check the time frame covered by the report.

B.

Disable auto-cache.

C.

Increase the report utilization quota.

D.

Test the dataset.

After generating a report, you notice the information you where expecting to see is not included in it. However, you confirm that the logs are there.

A.

Check the time frame covered by thereport.

B.

Disable auto-cache.

C.

Increase the report utilization quota.

D.

Test the dataset

Which statement about automation connectors in FortiAnalyzer is true?

A.

An ADOM with the Fabric type comes with multiple connectors configured.

B.

The local connector becomes available after you configured any external connector.

C.

The local connector becomes available after you connectors are displayed.

D.

The actions available with FortiOS connectors are determined by automation rules configured on FortiGate.

Which two statement regarding the outbreak detection service are true? (Choose two.)

A.

An additional license is required.

B.

It automatically downloads new event handlers and reports.

C.

Outbreak alerts are available on the root ADOM only.

D.

New alerts are received by email.

What is the purpose of running the command diagnose sql status sqlreportd?

A.

To view a list of scheduled reports

B.

To list the current SQL processes running

C.

To display the SQL query connections and hcache status

D.

To identify the database log insertion status

(Which two parameters does FortiAnalyzer use to identify an indicator of compromise (IOC)? (Choose two answers))

A.

IP address

B.

URL

C.

Policy ID

D.

Application category

Which SQL query is in the correct order to query to database in the FortiAnalyzer?

A.

SELECT devid FROM $log GROUP BY devid WHERE ‘user’,,’ users1’

B.

SELECT FROM $log WHERE devid ‘user’,, USER1’ GROUP BY devid

C.

SELCT devid WHERE ’user’-‘ USER1’ FROM $log GROUP By devid

D.

SELECT devid FROM $log WHERE ‘user’=’ GROUP BY devid

Which two statements about playbook execution are true? (Choose two)

A.

FortiAnalyzer will not commit changes made by a Failed playbook

B.

The Playbook Monitor provides troubleshooting logs

C.

You can run the default debugging playbook to investigate playbook errors.

D.

Even I the playbook status is Failed, individual tasks may have succeeded.

You need to move reports between two ADOMs.

Which two statements are true? (Choose two.)

A.

The ADOMs must be compatible types.

B.

The date and time will be appended to the original report name to avoid conflicts.

C.

All charts and datasets associated with the report will be imported together.

D.

You need to convert the reports into templates first.

Why must you wait for several minutes before you run a playbook that you just created?

A.

FortiAnalyzer needs that time to parse the new playbook.

B.

FortiAnalyzer needs that time to debug the new playbook.

C.

FortiAnalyzer needs that time to back up the current playbooks.

D.

FortiAnalyzer needs that time to ensure there are no other playbooks running.

What is the purpose of using data selectors when configuring event handlers?

A.

They filter the types of logs that FortiAnalyzer can accept from registered devices.

B.

They download new filters can be used in event handlers.

C.

They apply their filter criteria to the entire event handler so that you don’t have to configure the same criteria in the individual rules.

D.

They are common filters that can be appliedsimultaneously to all event handlers.

An administrator on your team has configured multiple reports to run periodically. Management has an additional request that all new generated reports be sent to a company email inbox for accessibility. The mail server has already been configured on FortiAnalyzer.

Which item must configure on FortiAnalyzer so that emails are sent when the reports are generated?

A.

Enable the option to email all repots under the mail server.

B.

Add amailto: option within the report layouts.

C.

Enable email notification under the report calendar.

D.

Enable an output profile on the reports.

Which two actions should an administrator take to vide Compromised Hosts on FortiAnalyzer? (Choose two.)

A.

Enable device detection on the FotiGate device that are sending logs to FortiAnalyzer.

B.

Enable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent to fortiAnalyzer.

C.

Make sure all endpoints are reachable by FortiAnalyzer.

D.

Subscribe FortiAnalyzer to FortiGuard to keep its local threat database up to date.

As part of your analysis, you discover that an incident is a false positive.

You change the incident status to Closed: False Positive.

Which statement about your update is true?

A.

The audit history log will be updated.

B.

The corresponding event will be marked as mitigated.

C.

The incident will bedeleted.

D.

The incident number will be changed

Refer to Exhibit:

Whatdoes the data point at 21:20 indicate?

A.

FortiAnalyzer is indexing logs faster than logs are being received.

B.

The fortilogd daemon is ahead in indexing by one log.

C.

The SQL database requires a rebuild because of high receive lag.

D.

FortiAnalyzer is temporarily buffering received logs so older logs can be indexed first.

Refer to Exhibit:

Client-1 is trying to access the internet for web browsing.

All FortiGate devices in the topology are part of a Security Fabric with logging to FortiAnalyzer configured. All firewall policies have logging enabled. All web filter profiles are configured to log only violations.

Which statement about the logging behavior for this specific traffic flow is true?

A.

Only FGT-B will create traffic logs.

B.

FGT-B will see the MAC address of FGT-A as the destination and notifies FGT-A to log this flow.

C.

FGT B will create traffic logs and will create web filter logs if it detects a violation.

D.

Only FGT-A will create web filter logs if it detects a violation.

You discover that a few reports are taking a long tine lo generate. Which two steps can you Like to troubleshoot? (Choose two.)

A.

Remove old reports from the hcache

B.

Enable auto-cache and run the reports again

C.

Increase the ADOM reports quota

D.

Review report diagnostics

Refer to the exhibit.

What can you conclude about the output?

A.

The low indexing values require investigation.

B.

The output is not ADOM specific.

C.

There are more event logs thantraffic logs.

D.

The log rate higher than the message rate is not normal.

(Refer to the exhibit.

Which statement about the displayed event is correct? (Choose one answer))

A.

An incident was created from this event.

B.

The risk source is isolated.

C.

The security risk was escalated.

D.

The security event risk is considered open.

Page: 1 / 1
Total 67 questions
Copyright © 2014-2026 Solution2Pass. All Rights Reserved