Questions for the NSE5-FAZ-6-4 were updated on : Nov 14 ,2024
Which two methods are the most common methods to control and restrict administrative access on
FortiAnalyzer? (Choose two.)
BC
Explanation:
Reference:
https://docs2.fortinet.com/document/fortianalyzer/6.0.0/administration-
guide/219292/administrator-profiles
https://docs2.fortinet.com/document/fortianalyzer/6.0.0/administration-guide/581222/trusted-
hosts
Which daemon is responsible for enforcing raw log file size?
A
An administrator has configured the following settings:
config system global
set log-checksum md5-auth
end
What is the significance of executing this command?
D
Explanation:
Reference:
https://docs.fortinet.com/document/fortianalyzer/6.4.6/administration-
guide/410387/appendix-b-log-integrity-and-secure-log-transfer
Which two of the following must you configure on FortiAnalyzer to email a FortiAnalyzer report
externally?
(Choose two.)
AB
Explanation:
Reference:
https://docs.fortinet.com/document/fortianalyzer/6.0.2/administration-
guide/598322/creating-output-profiles
For which two purposes would you use the command set log checksum? (Choose two.)
A, B
Refer to the exhibit.
What does the data point at 14:55 tell you?
D
You are using RAID with a FortiAnalyzer that supports software RAID, and one of the hard disks on
FortiAnalyzer has failed.
What is the recommended method to replace the disk?
A
Explanation:
https://community.fortinet.com/t5/FortiAnalyzer/Technical-Note-How-to-swap-Hard-Disk-on-
FortiAnalyzer/ta-
p/194997?externalID=FD41397#:~:text=If%20a%20hard%20disk%20on,process%20known%20as%20
hot%20swapping
On the RAID management page, the disk status is listed as Initializing.
What does the status Initializing indicate about what the FortiAnalyzer is currently doing?
C
Explanation:
Reference:
https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/4cb0dce6-
dbef-11e9
-
8977-00505692583a/FortiAnalyzer-5.6.10-Administration-Guide.pdf (40)
In the FortiAnalyzer FortiView, source and destination IP addresses from FortiGate devices are not
resolving to a hostname.
How can you resolve the source and destination IP addresses, without introducing any additional
performance impact to FortiAnalyzer?
D
Explanation:
https://packetplant.com/fortigate-and-fortianalyzer-resolve-source-and-destination-ip/
As a best practice, it is recommended to resolve IPs on the FortiGate end. This is because you get
both source and destination, and it offloads the work from FortiAnalyzer. On FortiAnalyzer, this IP
resolution does destination IPs only
You have recently grouped multiple FortiGate devices into a single ADOM. System Settings > Storage
Info
shows the quota used.
What does the disk quota refer to?
D
Why should you use an NTP server on FortiAnalyzer and all registered devices that log into
FortiAnalyzer?
A
Explanation:
You need to upgrade your FortiAnalyzer firmware.
What happens to the logs being sent to FortiAnalyzer from FortiGate during the time FortiAnalyzer is
temporarily unavailable?
B
Explanation:
After you have moved a registered logging device out of one ADOM and into a new ADOM, what is
the
purpose of running the following CLI command?
execute sql-local rebuild-adom <new-ADOM-name>
D
Explanation:
If a hard disk fails on a FortiAnalyzer that supports software RAID, what should you do to bring the
FortiAnalyzer back to functioning normally, without losing data?
D
Explanation:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD46446#:~:text=On%20FortiAnalyzer%2F
FortiManager%20devices%20that,to%20exchanging%20the%20hard%20disk
.
If a hard disk on a FortiAnalyzer unit fails, it must be replaced. On FortiAnalyzer devices that support
hardware RAID, the hard disk can be replaced while the unit is still running known as hot swapping.
On FortiAnalyzer units with software RAID, the device must be shutdown prior to exchanging the
hard disk.
Reference:
https://community.fortinet.com/t5/FortiAnalyzer/Technical-Note-How-to-swap-Hard-
Disk-on-FortiAnalyzer/ta-
p/194997?externalID=FD41397#:~:text=If%20a%20hard%20disk%20on,process%20known%20as%20
hot%20swapping
If you upgrade the FortiAnalyzer firmware, which report element can be affected?
A
Explanation:
https://docs.fortinet.com/document/fortianalyzer/6.2.5/upgrade-guide/669300/checking-reports