Fortinet NSE5-FAZ-6-4 Exam Questions

Questions for the NSE5-FAZ-6-4 were updated on : Nov 14 ,2024

Page 1 out of 7. Viewing questions 1-15 out of 94

Question 1

Which two methods are the most common methods to control and restrict administrative access on
FortiAnalyzer? (Choose two.)

  • A. Virtual domains
  • B. Administrative access profiles
  • C. Trusted hosts
  • D. Security Fabric
Answer:

BC

User Votes:
A
50%
B
50%
C
50%
D
50%

Explanation:
Reference:
https://docs2.fortinet.com/document/fortianalyzer/6.0.0/administration-
guide/219292/administrator-profiles
https://docs2.fortinet.com/document/fortianalyzer/6.0.0/administration-guide/581222/trusted-
hosts

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 2

Which daemon is responsible for enforcing raw log file size?

  • A. logfiled
  • B. oftpd
  • C. sqlplugind
  • D. miglogd
Answer:

A

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 3

An administrator has configured the following settings:
config system global
set log-checksum md5-auth
end
What is the significance of executing this command?

  • A. This command records the log file MD5 hash value.
  • B. This command records passwords in log files and encrypts them.
  • C. This command encrypts log transfer between FortiAnalyzer and other devices.
  • D. This command records the log file MD5 hash value and authentication code.
Answer:

D

User Votes:
A
50%
B
50%
C
50%
D
50%

Explanation:
Reference:
https://docs.fortinet.com/document/fortianalyzer/6.4.6/administration-
guide/410387/appendix-b-log-integrity-and-secure-log-transfer

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 4

Which two of the following must you configure on FortiAnalyzer to email a FortiAnalyzer report
externally?
(Choose two.)

  • A. Mail server
  • B. Output profile
  • C. SFTP server
  • D. Report scheduling
Answer:

AB

User Votes:
A
50%
B
50%
C
50%
D
50%

Explanation:
Reference:
https://docs.fortinet.com/document/fortianalyzer/6.0.2/administration-
guide/598322/creating-output-profiles

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 5

For which two purposes would you use the command set log checksum? (Choose two.)

  • A. To help protect against man-in-the-middle attacks during log upload from FortiAnalyzer to an SFTP server
  • B. To prevent log modification or tampering
  • C. To encrypt log communications
  • D. To send an identical set of logs to a second logging server
Answer:

A, B

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 6

Refer to the exhibit.

What does the data point at 14:55 tell you?

  • A. The received rate is almost at its maximum for this device
  • B. The sqlplugind daemon is behind in log indexing by two logs
  • C. Logs are being dropped
  • D. Raw logs are reaching FortiAnalyzer faster than they can be indexed
Answer:

D

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 7

You are using RAID with a FortiAnalyzer that supports software RAID, and one of the hard disks on
FortiAnalyzer has failed.
What is the recommended method to replace the disk?

  • A. Shut down FortiAnalyzer and then replace the disk
  • B. Downgrade your RAID level, replace the disk, and then upgrade your RAID level
  • C. Clear all RAID alarms and replace the disk while FortiAnalyzer is still running
  • D. Perform a hot swap
Answer:

A

User Votes:
A
50%
B
50%
C
50%
D
50%

Explanation:

https://community.fortinet.com/t5/FortiAnalyzer/Technical-Note-How-to-swap-Hard-Disk-on-
FortiAnalyzer/ta-
p/194997?externalID=FD41397#:~:text=If%20a%20hard%20disk%20on,process%20known%20as%20
hot%20swapping

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 8

On the RAID management page, the disk status is listed as Initializing.
What does the status Initializing indicate about what the FortiAnalyzer is currently doing?

  • A. FortiAnalyzer is ensuring that the parity data of a redundant drive is valid
  • B. FortiAnalyzer is writing data to a newly added hard drive to restore it to an optimal state
  • C. FortiAnalyzer is writing to all of its hard drives to make the array fault tolerant
  • D. FortiAnalyzer is functioning normally
Answer:

C

User Votes:
A
50%
B
50%
C
50%
D
50%

Explanation:
Reference:
https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/4cb0dce6-
dbef-11e9
-
8977-00505692583a/FortiAnalyzer-5.6.10-Administration-Guide.pdf (40)

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 9

In the FortiAnalyzer FortiView, source and destination IP addresses from FortiGate devices are not
resolving to a hostname.
How can you resolve the source and destination IP addresses, without introducing any additional
performance impact to FortiAnalyzer?

  • A. Resolve IP addresses on a per-ADOM basis to reduce delay on FortiView while IPs resolve
  • B. Configure # set resolve-ip enable in the system FortiView settings
  • C. Configure local DNS servers on FortiAnalyzer
  • D. Resolve IP addresses on FortiGate
Answer:

D

User Votes:
A
50%
B
50%
C
50%
D
50%

Explanation:
https://packetplant.com/fortigate-and-fortianalyzer-resolve-source-and-destination-ip/
As a best practice, it is recommended to resolve IPs on the FortiGate end. This is because you get
both source and destination, and it offloads the work from FortiAnalyzer. On FortiAnalyzer, this IP
resolution does destination IPs only

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 10

You have recently grouped multiple FortiGate devices into a single ADOM. System Settings > Storage
Info
shows the quota used.
What does the disk quota refer to?

  • A. The maximum disk utilization for each device in the ADOM
  • B. The maximum disk utilization for the FortiAnalyzer model
  • C. The maximum disk utilization for the ADOM type
  • D. The maximum disk utilization for all devices in the ADOM
Answer:

D

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 11

Why should you use an NTP server on FortiAnalyzer and all registered devices that log into
FortiAnalyzer?

  • A. To properly correlate logs
  • B. To use real-time forwarding
  • C. To resolve host names
  • D. To improve DNS response times
Answer:

A

User Votes:
A
50%
B
50%
C
50%
D
50%

Explanation:

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 12

You need to upgrade your FortiAnalyzer firmware.
What happens to the logs being sent to FortiAnalyzer from FortiGate during the time FortiAnalyzer is
temporarily unavailable?

  • A. FortiAnalyzer uses log fetching to retrieve the logs when back online
  • B. FortiGate uses the miglogd process to cache the logs
  • C. The logfiled process stores logs in offline mode
  • D. Logs are dropped
Answer:

B

User Votes:
A
50%
B
50%
C
50%
D
50%

Explanation:

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 13

After you have moved a registered logging device out of one ADOM and into a new ADOM, what is
the
purpose of running the following CLI command?
execute sql-local rebuild-adom <new-ADOM-name>

  • A. To reset the disk quota enforcement to default
  • B. To remove the analytics logs of the device from the old database
  • C. To migrate the archive logs to the new ADOM
  • D. To populate the new ADOM with analytical logs for the moved device, so you can run reports
Answer:

D

User Votes:
A
50%
B
50%
C
50%
D
50%

Explanation:

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 14

If a hard disk fails on a FortiAnalyzer that supports software RAID, what should you do to bring the
FortiAnalyzer back to functioning normally, without losing data?

  • A. Hot swap the disk
  • B. Replace the disk and rebuild the RAID manually
  • C. Take no action if the RAID level supports a failed disk
  • D. Shut down FortiAnalyzer and replace the disk
Answer:

D

User Votes:
A
50%
B
50%
C
50%
D
50%

Explanation:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD46446#:~:text=On%20FortiAnalyzer%2F
FortiManager%20devices%20that,to%20exchanging%20the%20hard%20disk
.
If a hard disk on a FortiAnalyzer unit fails, it must be replaced. On FortiAnalyzer devices that support
hardware RAID, the hard disk can be replaced while the unit is still running known as hot swapping.
On FortiAnalyzer units with software RAID, the device must be shutdown prior to exchanging the
hard disk.
Reference:
https://community.fortinet.com/t5/FortiAnalyzer/Technical-Note-How-to-swap-Hard-
Disk-on-FortiAnalyzer/ta-
p/194997?externalID=FD41397#:~:text=If%20a%20hard%20disk%20on,process%20known%20as%20
hot%20swapping

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 15

If you upgrade the FortiAnalyzer firmware, which report element can be affected?

  • A. Custom datasets
  • B. Report scheduling
  • C. Report settings
  • D. Output profiles
Answer:

A

User Votes:
A
50%
B
50%
C
50%
D
50%

Explanation:
https://docs.fortinet.com/document/fortianalyzer/6.2.5/upgrade-guide/669300/checking-reports

Discussions
vote your answer:
A
B
C
D
0 / 1000
To page 2