Refer to the exhibit.
Which image corresponds to the packet capture shown in the exhibit?
A)
B)
C)
D)
What happens when a log file saved on FortiAnalyzer disks reaches the size specified in the device log
settings?
FortiAnalyzer reports are dropping analytical data from 15 days ago, even though the data policy setting for
analytics logs is 60 days.
What is the most likely problem?
How do you restrict an administrator’s access to a subset of your organization’s ADOMs?
Which clause is considered mandatory in SELECT statements used by the FortiAnalyzer to generate reports?
Refer to the exhibit.
The exhibit shows the creation of a new administrator on FortiAnalyzer. The new account uses the credentials stored on an LDAP server.
Why would an administrator configure a password for this account?
Refer to the exhibit.
Based on the partial outputs displayed, which devices can be members of a FortiAnalyzer Fabric?
Refer to the exhibit.
Based on the partial outputs displayed, which devices can be members of a FortiAnalyzer Fabric?
Which item must you configure on FortiAnalyzer to email generated reports automatically?
An administrator has moved a FortiGate device from the root ADOM to ADOM1.
Which two statements are true regarding logs? (Choose two.)
Which two statements are true regarding FortiAnalyzer operating modes? (Choose two.)
An administrator has moved FortiGate A from the root ADOM to ADOM1. However, the administrator is not able to generate reports for FortiGate A in ADOM1.
What should the administrator do to solve this issue?
You need to upgrade your FortiAnalyzer firmware.
What happens to the logs being sent to FortiAnalyzer from FortiGate during the time FortiAnalyzer is
temporarily unavailable?
Refer to the exhibit.
Which image corresponds to the packet capture shown in the exhibit?
In FortiAnalyzer’s FormView, source and destination IP addresses from FortiGate devices are not resolving to
a hostname. How can you resolve the source and destination IPs, without introducing any additional
performance impact to FortiAnalyzer?
A playbook contains five tasks in total. An administrator runs the playbook and four out of five tasks finish successfully, but one task fails. What will be the status of the playbook after it is run?
Refer to the exhibit.
The exhibit shows the creation of a new administrator on FortiAnalyzer.
What are two effects of enabling the choice Match all users on remote server when configuring a new administrator? (Choose two.)
Which two elements are contained in a system backup created on FortiAnalyzer? (Choose two.)
In order for FortiAnalyzer to collect logs from a FortiGate device, what configuration is required? (Choose two.)
Which two statements are true about FortiAnalyzer log forwarding modes? (Choose two.)
If the primary FortiAnalyzer in an HA cluster fails, how is the new primary elected?
Which two statements express the advantages of grouping similar reports? (Choose two.)
Which two elements are contained in a system backup created on FortiAnalyzer? (Choose two.)
What are two effects of enabling auto-cache in a FortiAnalyzer report? (Choose two.)
What happens when the IOC breach detection engine on FortiAnalyzer finds web logs that match a blocklisted IP address?
An administrator fortinet, is able to view logs and perform device management tasks, such as adding and removing registered devices. However, administrator fortinet is not able to create a mall server that can be used to send email.
What could be the problem?
Refer to the exhibit.
The exhibit shows “remoteservergroup” is an authentication server group with LDAP and RADIUS servers.
Which two statements express the significance of enabling “Match all users on remote server” when configuring a new administrator? (Choose two.)
Refer to the exhibits.
How many events will be added to the incident created after running this playbook?
Which two statements are correct regarding the export and import of playbooks? (Choose two.)
You’ve moved a registered logging device out of one ADOM and into a new ADOM. What happens when you rebuild the new ADOM database?
You finished registering a FortiGate device. After traffic starts to flow through FortiGate, you notice that only some of the logs expected are being received on FortiAnalyzer.
What could be the reason for the logs not arriving on FortiAnalyzer?
Which two actions should an administrator take to view Compromised Hosts on FortiAnalyzer? (Choose two.)
Refer to the exhibit, which shows the HA configuration settings of a FortiAnalyzer device.
The administrator wants to join this FortiAnalyzer to an existing HA cluster. What can you conclude from the configuration displayed?
If you upgrade the FortiAnalyzer firmware, which report element can be affected?
Refer to the exhibit.
Which two statements are true regarding enabling auto-cache on FortiAnalyzer? (Choose two.)
Which two settings must you configure on FortiAnalyzer to allow non-local administrators to authenticate on FortiAnalyzer with any user account in a single LDAP group? (Choose two.)
An administrator has configured the following settings:
config system global
set log-checksum md5-auth
end
What is the significance of executing this command?
What FortiView tool can you use to automatically build a dataset and chart based on a filtered search result?
Which two statements are true regarding log fetching on FortiAnalyzer? (Choose two.)