[Q50-Q71] Free Sample Questions to Practice NSE5_FAZ-7.2 Certification Test Engine [Apr-2024]

Share

Free Sample Questions to Practice NSE5_FAZ-7.2 Certification Test Engine [Apr-2024]

2024 Valid NSE5_FAZ-7.2 Real Exam Questions, practice NSE 5 Network Security Analyst

NEW QUESTION # 50
Which two elements are contained in a system backup created on FortiAnalyzer? (Choose two.)

  • A. Database snapshot
  • B. System information
  • C. Report information
  • D. Logs from registered devices

Answer: B,C

Explanation:
What does the System Configuration backup include?
System information, such as the device IP address and administrative user information.
Device list, such as any devices you configured to allow log access.
Report information, such as any configured report settings, as well as all your custom report details. These are not the actual reports.
FortiAnalyzer_7.0_Study_Guide-Online pag. 29
FortiAnalyzer_7.0_Study_Guide-Online.pdf page 29: What does the System Configuration backup include?
* System information, such as the device IP address and administrative user information
* Device list, such as any devices you configured to allow log access
* Report information, such as any configured report settings, as well as all your custom report details. These are not the actual reports.


NEW QUESTION # 51
View the exhibit:

What does the 1000MB maximum for disk utilization refer to?

  • A. The disk quota for the FortiAnalyzer model
  • B. The disk quota for all devices in the ADOM
  • C. The disk quota for each device in the ADOM
  • D. The disk quota for the ADOM type

Answer: B

Explanation:
https://docs.fortinet.com/document/fortianalyzer/6.2.0/administration-guide/743670/configuring-log-storage-policy


NEW QUESTION # 52
What happens when the IOC breach detection engine on FortiAnalyzer finds web logs that match a blocklisted IP address?

  • A. A new Infected entry is added for the corresponding endpoint.
  • B. The detection engine classifies those logs as Suspicious
  • C. The endpoint is marked as Compromised and. optionally, can be put in quarantine.
  • D. FortiAnalyzer flags the associated host for further analysis.

Answer: C


NEW QUESTION # 53
Which two methods can you use to send event notifications when an event occurs that matches a configured event handler? (Choose two.)

  • A. Email
  • B. IM
  • C. SMS
  • D. SNMP

Answer: A,D

Explanation:
Reference:
FortiAnalyzer_Admin_Guide/1800_Events/0200_Event_handlers/0600_Create_event_handlers.htm


NEW QUESTION # 54
Which FortiAnalyzer feature allows you to use a proactive approach when managing your network security?

  • A. Outbreak alert services
  • B. Threat hunting
  • C. FortiView Monitor
  • D. Incidents dashboards

Answer: B

Explanation:
FortiAnalyzer_7.0_Study_Guide-Online.pdf page 217: Threat hunting consists in proactively searching for suspicious or potentially risky network activity in your environment. The proactive approach will help administrator find any threats that might have eluded detection by the current security solutions or configurations.


NEW QUESTION # 55
Which two statements express the advantages of grouping similar reports? (Choose two.)

  • A. Improve report completion time.
  • B. Conserve disk space on FortiAnalyzer by grouping multiple similar reports.
  • C. Provides a better summary of reports.
  • D. Reduce the number of hcache tables and improve auto-hcache completion time.

Answer: A,D


NEW QUESTION # 56
Which statement about the FortiSIEM management extension is correct?

  • A. It can be installed as a dedicated VM.
  • B. Allows you to manage the entire life cycle of a threat or breach.
  • C. Its use of the available disk space is capped at 50%.
  • D. It requires a licensed FortiSIEM supervisor.

Answer: B


NEW QUESTION # 57
Consider the CLI command:

What is the purpose of the command?

  • A. To encrypt log communications
  • B. To add a unique tag to each log to prove that it came from this FortiAnalyzer
  • C. To add the MD5 hash value and authentication code
  • D. To add a log file checksum

Answer: D

Explanation:
https://docs.fortinet.com/document/fortianalyzer/6.2.5/cli-reference/849211/global


NEW QUESTION # 58
Refer to the exhibit.

What does the data point at 12:20 indicate?

  • A. The sqlplugind service is caught up with new logs.
  • B. FortiAnalyzer is using its cache to avoid dropping logs.
  • C. The log insert lag time is increasing.
  • D. The performance of FortiAnalyzer is below the baseline.

Answer: C


NEW QUESTION # 59
Which statement describes a dataset in FortiAnalyzer?

  • A. They are used to set the data included in templates.
  • B. They determine what data is retrieved from the database.
  • C. They define the chart types to be used in reports.
  • D. hey provide the layout used for reports.

Answer: B


NEW QUESTION # 60
FortiAnalyzer centralizes which functions? (Choose three)

  • A. Vulnerability assessment
  • B. Network analysis
  • C. Content archiving / data mining
  • D. Security log analysis / forensics
  • E. Graphical reporting

Answer: C,D,E


NEW QUESTION # 61
A playbook contains five tasks in total. An administrator runs the playbook and four out of five tasks finish successfully, but one task fails. What will be the status of the playbook after it is run?

  • A. Upstream_failed
  • B. Running
  • C. Failed
  • D. Success

Answer: C


NEW QUESTION # 62
What must you configure on FortiAnalyzer to upload a FortiAnalyzer report to a supported external server?
(Choose two.)

  • A. Report scheduling
  • B. Output profile
  • C. SFTP, FTP, or SCP server
  • D. Mail server

Answer: B,C

Explanation:
https://docs.fortinet.com/document/fortianalyzer/6.0.2/administration-guide/598322/creating-output-profiles


NEW QUESTION # 63
What is the purpose of the following CLI command?

  • A. To encrypt log communications
  • B. To add a unique tag to each log to prove that it came from this FortiAnalyzer
  • C. To add a log file checksum
  • D. To add the MD's hash value and authentication code

Answer: C

Explanation:
https://docs2.fortinet.com/document/fortianalyzer/6.0.3/cli-reference/849211/global


NEW QUESTION # 64
What does the disk status Degraded mean for RAID management?

  • A. One or more drives are missing from the FortiAnalyzer unit. The drive is no longer available to the operating system.
  • B. The FortiAnalyzer device is writing data to a newly added hard drive in order to restore the hard drive to an optimal state.
  • C. The hard driveiIs no longer being used by the RAID controller
  • D. The FortiAnalyzer device is writing to all the hard drives on the device in order to make the array fault tolerant.

Answer: C


NEW QUESTION # 65
What happens when a log file saved on FortiAnalyzer disks reaches the size specified in the device log settings?

  • A. The log file rolls over and is archived.
  • B. The log file is purged from the database.
  • C. The log file is overwritten.
  • D. The log file is stored as a raw log and is available for analytic support.

Answer: A

Explanation:
Reference:
81a4-00505692583a/FortiAnalyzer-6.0.5-Administration-Guide.pdf
https://docs.fortinet.com/document/fortianalyzer/6.2.5/administration-guide/355632/log-browse


NEW QUESTION # 66
What is the purpose of output variables?

  • A. To save all the task settings when a playbook is exported
  • B. To use the output of the previous task as the input of the current task
  • C. To store playbook execution statistics
  • D. To display details of the connectors used by a playbook

Answer: B

Explanation:
FortiAnalyzer_7.0_Study_Guide-Online.pdf page 242: Output variables allow you to use the output from a preceding task as an input to the current task.
"Output variables allow you to use the output from a preceding task as an input to the current task." FortiAnalyzer_7.0_Study_Guide-Online page 242


NEW QUESTION # 67
An administrator fortinet, is able to view logs and perform device management tasks, such as adding and removing registered devices. However, administrator fortinet is not able to create a mall server that can be used to send email.
What could be the problem?

  • A. A trusted host is configured.
  • B. ADOM mode is configured with Advanced mode.
  • C. Fortinet is assigned the Restricted_ User administrator profile.
  • D. Fortinet is assigned the Standard_ User administrator profile.

Answer: D

Explanation:
* Super_User, which, like in FortiGate, provides access to all device and system privileges.
* Standard_User, which provides read and write access to device privileges, but not system privileges.
* Restricted_User, which provides read access only to device privileges, but not system privileges. Access to the Management extensions is also removed.
* No_Permissions_User, which provides no system or device privileges. Can be used, for example, to temporarily remove access granted to existing admins.
FortiAnalyzer_7.0_Study_Guide-Online page 42


NEW QUESTION # 68
By default, what happens when a log file reaches its maximum file size?

  • A. FortiAnalyzer overwrites the log files.
  • B. FortiAnalyzer forwards logs to syslog.
  • C. FortiAnalyzer stops logging.
  • D. FortiAnalyzer rolls the active log by renaming the file.

Answer: D


NEW QUESTION # 69
Refer to the exhibit.

Which image corresponds to the packet capture shown in the exhibit?

  • A.
  • B.
  • C.
  • D.

Answer: C


NEW QUESTION # 70
For which two SAML roles can the FortiAnalyzer be configured? (Choose two.)

  • A. Service provider
  • B. Identity collector
  • C. Principal
  • D. Identity provider

Answer: A,D

Explanation:
Reference:
20the%20identity%20provider%20(IdP,external%20identity%20provider%20is%20available.
https://docs.fortinet.com/document/fortianalyzer/6.2.0/administration-guide/981386/saml-admin-authentication In FortiAnalyzer, SAML can be enabled across all Security Fabric devices, enabling smooth movement between devices for the administrator by means of single sign-on (SSO).
FortiAnalyzer can play the role of the identity provider (IdP), the service provider (SP), or Fabric SP, when an external identity provider is available.
FortiAnalyzer_7.0_Study_Guide-Online pag. 48


NEW QUESTION # 71
......

Genuine NSE5_FAZ-7.2 Exam Dumps Free Demo Valid QA's: https://www.prepawaytest.com/Fortinet/NSE5_FAZ-7.2-practice-exam-dumps.html

Latest Success Metrics For Actual NSE5_FAZ-7.2 Exam (Updated 138 Questions): https://drive.google.com/open?id=1WzL19a0r3TSRfVuT9hNLBW31WFVi101V

Contact Us

If you have any question please leave me your email address, we will reply and send email to you in 12 hours.

Our Working Time: ( GMT 0:00-15:00 )
From Monday to Saturday

Support: Contact now