|Which two of the following must you configure on FortiAnalyzer to email a FortiAnalyzer report externally?
(Choose two.) Mail server Output profile SFTP server Report scheduling.
For which two purposes would you use the command set log checksum? (Choose two.) To help protect against man-in-the-middle attacks during log upload from FortiAnalyzer to an SFTP server To prevent log modification or tampering To encrypt log communications To send an identical set of logs to a second logging server.
Refer to the exhibit.
What does the data point at 14:55 tell you? The received rate is almost at its maximum for this device The sqlplugind daemon is behind in log indexing by two logs
Logs are being dropped Raw logs are reaching FortiAnalyzer faster than they can be indexed.
You are using RAID with a FortiAnalyzer that supports software RAID, and one of the hard disks on
FortiAnalyzer has failed.
What is the recommended method to replace the disk? Shut down FortiAnalyzer and then replace the disk Downgrade your RAID level, replace the disk, and then upgrade your RAID level Clear all RAID alarms and replace the disk while FortiAnalyzer is still running Perform a hot swap.
On the RAID management page, the disk status is listed as Initializing.
What does the status Initializing indicate about what the FortiAnalyzer is currently doing? FortiAnalyzer is ensuring that the parity data of a redundant drive is valid FortiAnalyzer is writing data to a newly added hard drive to restore it to an optimal state FortiAnalyzer is writing to all of its hard drives to make the array fault tolerant FortiAnalyzer is functioning normally.
In the FortiAnalyzer FortiView, source and destination IP addresses from FortiGate devices are not resolving to
How can you resolve the source and destination IP addresses, without introducing any additional performance
impact to FortiAnalyzer? Resolve IP addresses on a per-ADOM basis to reduce delay on FortiView while IPs resolve Configure # set resolve-ip enable in the system FortiView settings Configure local DNS servers on FortiAnalyzer Resolve IP addresses on FortiGate.
You have recently grouped multiple FortiGate devices into a single ADOM. System Settings > Storage Info
shows the quota used.
What does the disk quota refer to? The maximum disk utilization for each device in the ADOM The maximum disk utilization for the FortiAnalyzer model The maximum disk utilization for the ADOM type The maximum disk utilization for all devices in the ADOM.
Why should you use an NTP server on FortiAnalyzer and all registered devices that log into FortiAnalyzer? To properly correlate logs To use real-time forwarding To resolve host names To improve DNS response times.
You need to upgrade your FortiAnalyzer firmware.
What happens to the logs being sent to FortiAnalyzer from FortiGate during the time FortiAnalyzer is
temporarily unavailable? FortiAnalyzer uses log fetching to retrieve the logs when back online FortiGate uses the miglogd process to cache the logs The logfiled process stores logs in offline mode Logs are dropped.
After you have moved a registered logging device out of one ADOM and into a new ADOM, what is the purpose
of running the following CLI command?
execute sql-local rebuild-adom <new-ADOM-name> To reset the disk quota enforcement to default To remove the analytics logs of the device from the old database To migrate the archive logs to the new ADOM To populate the new ADOM with analytical logs for the moved device, so you can run reports.
If a hard disk fails on a FortiAnalyzer that supports software RAID, what should you do to bring the
FortiAnalyzer back to functioning normally, without losing data? Hot swap the disk Replace the disk and rebuild the RAID manually Take no action if the RAID level supports a failed disk Shut down FortiAnalyzer and replace the disk.
Which FortiAnalyzer feature allows you to retrieve the archived logs matching a specific timeframe, from
another FortiAnalyzer device? Log fetching Indicators of compromise Log forwarding in aggregation mode Log upload.
If you upgrade the FortiAnalyzer firmware, which report element can be affected? Custom datasets Report scheduling Report settings Output profiles.
FortiAnalyzer reports are dropping analytical data from 15 days ago, even though the data policy setting for
analytics logs is 60 days.
What is the most likely problem? Quota enforcement is acting on analytical data before a report is complete Logs are rolling before the report is run CPU resources are too high Disk utilization for archive logs is set for 15 days.
Which log type does the FortiAnalyzer indicators of compromise feature use to identify infected hosts? Antivirus logs Web filter logs IPS logs Application control logs.
Which two purposes does the auto-cache setting on reports serve? (Choose two.) It automatically updates the hcache when new logs arrive It reduces report generation time It provides diagnostics on report generation time It reduces the log insert lag rate.
In order for FortiAnalyzer to collect logs from a FortiGate device, which two configurations are required?
(Choose two.) FortiGate must be registered with FortiAnalyzer Remote logging must be enabled on FortiGate ADOMs must be enabled Log encryption must be enabled.
Which two settings must you configure on FortiAnalyzer to allow non-local administrators to authenticate to
FortiAnalyzer with any user account in a single LDAP group? (Choose two.) A local wildcard administrator account A remote LDAP server A trusted host profile that restricts access to the LDAP group An administrator group.
When you perform a system backup, what does the backup configuration contain? (Choose two.) Generated reports Device list Authorized devices logs System information.
Which clause is considered mandatory in SELECT statements used by the FortiAnalyzer to generate reports? FROM LIMIT WHERE ORDER BY.
What is the purpose of a dataset query in FortiAnalyzer? It sorts log data into tables It extracts the database schema It retrieves log data from the database It injects log data into the database.
Logs are being deleted from one of the ADOMs earlier than the configured setting for archiving in the data policy.
What is the most likely problem? CPU resources are too high Logs in that ADOM are being forwarded, in real-time, to another FortiAnalyzer device The total disk space is insufficient and you need to add other disk The ADOM disk quota is set too low, based on log rates.
Which two constraints can impact the amount of reserved disk space required by FortiAnalyzer? (Choose two.) License type Disk size Total quota RAID level.
What happens when a log file saved on FortiAnalyzer disks reaches the size specified in the device log settings? The log file is overwritten The log file is stored as a raw log and is available for analytic support The log file rolls over is archived The log file is purged from the database.
Which two statements about log forwarding are true? (Choose two.) Forwarded logs cannot be filtered to match specific criteria. Logs are forwarded in real-time only. The client retains a local copy of the logs after forwarding. You can use aggregation mode only with another FortiAnalyzer.
Which two methods can you use to send event notifications when an event occurs that matches a configured
event handler? (Choose two.) SMS Email SNMP IM.
You have moved a registered logging device out of one ADOM and into a new ADOM.
What happens when you rebuild the new ADOM database? FortiAnalyzer migrates analytics logs to the new ADOM. FortiAnalyzer removes analytics logs from the old ADOM. FortiAnalyzer resets the disk quota of the new ADOM to default. FortiAnalyzer migrates archive logs to the new ADOM.
Consider the CLI command:
What is the purpose of the command? To add a unique tag to each log to prove that it came from this FortiAnalyzer To add the MD5 hash value and authentication code To add a log file checksum To encrypt log communications.
How are logs forwarded when FortiAnalyzer is configured to use aggregation mode? Logs are forwarded as they are received. Logs are forwarded as they are received and content files are uploaded at a scheduled time Logs and content files are stored and uploaded at a scheduled time. Logs and content files are forwarded as they are received.
Refer to the exhibit.
What does the data point at 14:35 tell you? FortiAnalyzer is indexing logs faster than logs are being received. FortiAnalyzer has temporarily stopped receiving logs so older logs can be indexed. FortiAnalyzer is dropping logs The fortilogd daemon is ahead in indexing by one log.
What is the main purpose of using an NTP server on FortiAnalyzer and all of its registered devices? Log correlation Host name resolution Log collection Real-time forwarding.
FortiAnalyzer uses the Optimized Fabric Transfer Protocol (OFTP) over SSL for which purpose? To send an identical set of logs to a second logging server To encrypt log communication between devices To upload logs to an SFTP server To prevent log modification during backup.
What are two advantages of setting up fabric ADOM? (Choose two.) It can be used for fast data processing and log correlation It can be used to facilitate communication between devices in same Security Fabric It can include all Fortinet devices that are part of the same Security Fabric It can include only FortiGate devices that are part of the same Security Fabric.
What is the purpose of a predefined template on the FortiAnalyzer? It can be edited and modified as required It specifies the report layout which contains predefined texts, charts, and macros It specifies report settings which contains time period, device selection, and schedule It contains predefined data to generate mock reports.
How does FortiAnalyzer retrieve specific log data from the database? SQL EXTRACT statement SQL GET statement SQL FROM statement SQL SELECT statement.
Which FortiGate process caches logs when FortiAnalyzer is not reachable? sqlplugind miglogd logfiled oftpd.
Refer to the exhibit.
What does the 1000MB maximum for disk utilization refer to? The disk quota for each device in the ADOM The disk quota for all devices in the ADOM The disk quota for the FortiAnalyzer model The disk quota for the ADOM type.
For which two SAML roles can the FortiAnalyzer be configured? (Choose two.) Principal Service provider Identity collector Identity provider.
Refer to the exhibit.
Why is the total quota less than the total system storage? Some space is reserved for system use, such as storage of compression files, upload files, and temporary report files 3.6% of the system storage is already being used The logfiled process is just estimating the total quota The oftpd process has not archived the logs yet.