Exam4Training

Fortinet NSE5_FAZ-7.2 Fortinet NSE 5 – FortiAnalyzer 7.2 Online Training

Question #1

Which two methods are the most common methods to control and restrict administrative access on FortiAnalyzer? (Choose two.)

  • A . Virtual domains
  • B . Administrative access profiles
  • C . Trusted hosts
  • D . Security Fabric

Reveal Solution Hide Solution

Correct Answer: BC
BC

Explanation:

Reference:

https://docs2.fortinet.com/document/fortianalyzer/6.0.0/administration-guide/219292/administrator-profiles

https://docs2.fortinet.com/document/fortianalyzer/6.0.0/administration-guide/581222/trusted-hosts

Question #2

Which daemon is responsible for enforcing raw log file size?

  • A . logfiled
  • B . oftpd
  • C . sqlplugind
  • D . miglogd

Reveal Solution Hide Solution

Correct Answer: A
Question #3

An administrator has configured the following settings:

config system global

set log-checksum md5-auth

end

What is the significance of executing this command?

  • A . This command records the log file MD5 hash value.
  • B . This command records passwords in log files and encrypts them.
  • C . This command encrypts log transfer between FortiAnalyzer and other devices.
  • D . This command records the log file MD5 hash value and authentication code.

Reveal Solution Hide Solution

Correct Answer: D
D

Explanation:

Reference: https://docs.fortinet.com/document/fortianalyzer/6.4.6/administration-guide/410387/appendix-b-log-integrity-and-secure-log-transfer

Question #4

Which two of the following must you configure on FortiAnalyzer to email a FortiAnalyzer report externally? (Choose two.)

  • A . Mail server
  • B . Output profile
  • C . SFTP server
  • D . Report scheduling

Reveal Solution Hide Solution

Correct Answer: AB
AB

Explanation:

Reference: https://docs.fortinet.com/document/fortianalyzer/6.0.2/administration-guide/598322/creating-output-profiles

Question #5

For which two purposes would you use the command set log checksum? (Choose two.)

  • A . To help protect against man-in-the-middle attacks during log upload from FortiAnalyzer to an SFTP server
  • B . To prevent log modification or tampering
  • C . To encrypt log communications
  • D . To send an identical set of logs to a second logging server

Reveal Solution Hide Solution

Correct Answer: A, B
A, B

Explanation:

To prevent logs from being tampered with while in storage, you can add a log checksum using the config

system global command. You can configure FortiAnalyzer to record a log file hash value, timestamp, and

authentication code when the log is rolled and archived and when the log is uploaded (if that feature is

enabled). This can also help against man-in-the-middle only for the transmission from FortiAnalyzer to an

SSH File Transfer Protocol (SFTP) server during log upload.

FortiAnalyzer_7.0_Study_Guide-Online page 149

Question #6

Refer to the exhibit.

What does the data point at 14:55 tell you?

  • A . The received rate is almost at its maximum for this device
  • B . The sqlplugind daemon is behind in log indexing by two logs
  • C . Logs are being dropped
  • D . Raw logs are reaching FortiAnalyzer faster than they can be indexed

Reveal Solution Hide Solution

Correct Answer: D
Question #7

You are using RAID with a FortiAnalyzer that supports software RAID, and one of the hard disks on FortiAnalyzer has failed.

What is the recommended method to replace the disk?

  • A . Shut down FortiAnalyzer and then replace the disk
  • B . Downgrade your RAID level, replace the disk, and then upgrade your RAID level
  • C . Clear all RAID alarms and replace the disk while FortiAnalyzer is still running
  • D . Perform a hot swap

Reveal Solution Hide Solution

Correct Answer: A
A

Explanation:

https://community.fortinet.com/t5/FortiAnalyzer/Technical-Note-How-to-swap-Hard-Disk-on-FortiAnalyzer/ta-p/194997?externalID=FD41397#:~:text=If%20a%20hard%20disk%20on,process%20known%20as%20hot%20swapping


Question #8

On the RAID management page, the disk status is listed as Initializing.

What does the status Initializing indicate about what the FortiAnalyzer is currently doing?

  • A . FortiAnalyzer is ensuring that the parity data of a redundant drive is valid
  • B . FortiAnalyzer is writing data to a newly added hard drive to restore it to an optimal state
  • C . FortiAnalyzer is writing to all of its hard drives to make the array fault tolerant
  • D . FortiAnalyzer is functioning normally

Reveal Solution Hide Solution

Correct Answer: C
C

Explanation:

Reference: https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/4cb0dce6-dbef-11e9-8977-00505692583a/FortiAnalyzer-5.6.10-Administration-Guide.pdf (40)

Question #9

In the FortiAnalyzer FortiView, source and destination IP addresses from FortiGate devices are not resolving to a hostname.

How can you resolve the source and destination IP addresses, without introducing any additional performance impact to FortiAnalyzer?

  • A . Resolve IP addresses on a per-ADOM basis to reduce delay on FortiView while IPs resolve
  • B . Configure # set resolve-ip enable in the system FortiView settings
  • C . Configure local DNS servers on FortiAnalyzer
  • D . Resolve IP addresses on FortiGate

Reveal Solution Hide Solution

Correct Answer: D
D

Explanation:

https://packetplant.com/fortigate-and-fortianalyzer-resolve-source-and-destination-ip/

“As a best practice, it is recommended to resolve IPs on the FortiGate end. This is because you get both source and destination, and it offloads the work from FortiAnalyzer. On FortiAnalyzer, this IP resolution does destination IPs only”

Question #10

You have recently grouped multiple FortiGate devices into a single ADOM. System Settings > Storage Info shows the quota used.

What does the disk quota refer to?

  • A . The maximum disk utilization for each device in the ADOM
  • B . The maximum disk utilization for the FortiAnalyzer model
  • C . The maximum disk utilization for the ADOM type
  • D . The maximum disk utilization for all devices in the ADOM

Reveal Solution Hide Solution

Correct Answer: D

Question #11

Why should you use an NTP server on FortiAnalyzer and all registered devices that log into FortiAnalyzer?

  • A . To properly correlate logs
  • B . To use real-time forwarding
  • C . To resolve host names
  • D . To improve DNS response times

Reveal Solution Hide Solution

Correct Answer: A
A

Explanation:



Question #12

You need to upgrade your FortiAnalyzer firmware.

What happens to the logs being sent to FortiAnalyzer from FortiGate during the time FortiAnalyzer is temporarily unavailable?

  • A . FortiAnalyzer uses log fetching to retrieve the logs when back online
  • B . FortiGate uses the miglogd process to cache the logs
  • C . The logfiled process stores logs in offline mode
  • D . Logs are dropped

Reveal Solution Hide Solution

Correct Answer: B
B

Explanation:



Question #13

After you have moved a registered logging device out of one ADOM and into a new ADOM, what is the purpose of running the following CLI command?

execute sql-local rebuild-adom <new-ADOM-name>

  • A . To reset the disk quota enforcement to default
  • B . To remove the analytics logs of the device from the old database
  • C . To migrate the archive logs to the new ADOM
  • D . To populate the new ADOM with analytical logs for the moved device, so you can run reports

Reveal Solution Hide Solution

Correct Answer: D
D

Explanation:

FortiAnalyzer_7.0_Study_Guide-Online.pdf page 128: Are the device analytics logs required for reports in the new ADOM? If so, rebuild the new ADOM database


Question #14

If a hard disk fails on a FortiAnalyzer that supports software RAID, what should you do to bring the FortiAnalyzer back to functioning normally, without losing data?

  • A . Hot swap the disk
  • B . Replace the disk and rebuild the RAID manually
  • C . Take no action if the RAID level supports a failed disk
  • D . Shut down FortiAnalyzer and replace the disk

Reveal Solution Hide Solution

Correct Answer: D
D

Explanation:

https://kb.fortinet.com/kb/documentLink.do?externalID=FD46446#:~:text=On%20FortiAnalyzer%2F FortiManager%20devices%20that,to%20exchanging%20the%20hard%20disk.

If a hard disk on a FortiAnalyzer unit fails, it must be replaced. On FortiAnalyzer devices that support hardware RAID, the hard disk can be replaced while the unit is still running C known as hot swapping. On FortiAnalyzer units with software RAID, the device must be shutdown prior to exchanging the hard disk.

Reference: https://community.fortinet.com/t5/FortiAnalyzer/Technical-Note-How-to-swap-Hard-Disk-on-FortiAnalyzer/ta-p/194997?externalID=FD41397#:~:text=If%20a%20hard%20disk%20on,process%20known%20as%20hot%20swapping

Question #15

If you upgrade the FortiAnalyzer firmware, which report element can be affected?

  • A . Custom datasets
  • B . Report scheduling
  • C . Report settings
  • D . Output profiles

Reveal Solution Hide Solution

Correct Answer: A
A

Explanation:

https://docs.fortinet.com/document/fortianalyzer/6.2.5/upgrade-guide/669300/checking-reports

Question #16

FortiAnalyzer reports are dropping analytical data from 15 days ago, even though the data policy setting for analytics logs is 60 days.

What is the most likely problem?

  • A . Quota enforcement is acting on analytical data before a report is complete
  • B . Logs are rolling before the report is run
  • C . CPU resources are too high
  • D . Disk utilization for archive logs is set for 15 days

Reveal Solution Hide Solution

Correct Answer: B
B

Explanation:

Reference: https://forum.fortinet.com/tm.aspx?m=138806

Question #17

Which log type does the FortiAnalyzer indicators of compromise feature use to identify infected hosts?

  • A . Antivirus logs
  • B . Web filter logs
  • C . IPS logs
  • D . Application control logs

Reveal Solution Hide Solution

Correct Answer: B
B

Explanation:

Reference: https://help.fortinet.com/fa/faz50hlp/60/6-0-2/Content/FortiAnalyzer_Admin_Guide/3600_FortiView/0200_Using_FortiView/1200_Compromised_hosts_page.htm?TocPath=FortiView%7CUsing%20FortiView%7C_____6

Question #18

Which two settings must you configure on FortiAnalyzer to allow non-local administrators to authenticate to FortiAnalyzer with any user account in a single LDAP group? (Choose two.)

  • A . A local wildcard administrator account
  • B . A remote LDAP server
  • C . A trusted host profile that restricts access to the LDAP group
  • D . An administrator group

Reveal Solution Hide Solution

Correct Answer: A, B
A, B

Explanation:

Reference: https://kb.fortinet.com/kb/documentLink.do?externalID=FD38567

Question #19

When you perform a system backup, what does the backup configuration contain? (Choose two.)

  • A . Generated reports
  • B . Device list
  • C . Authorized devices logs
  • D . System information

Reveal Solution Hide Solution

Correct Answer: B, D
B, D

Explanation:

https://help.fortinet.com/fa/cli-olh/5-6-5/Content/Document/1400_execute/backup.htm

Reference: https://help.fortinet.com/fauth/5-2/Content/Admin%20Guides/5_2%20Admin%20Guide/300/301_Dashboard.htm

Question #20

Which clause is considered mandatory in SELECT statements used by the FortiAnalyzer to generate reports?

  • A . FROM
  • B . LIMIT
  • C . WHERE
  • D . ORDER BY

Reveal Solution Hide Solution

Correct Answer: A
A

Explanation:

Reference: https://kb.fortinet.com/kb/documentLink.do?externalID=FD48500



Question #21

What is the purpose of a dataset query in FortiAnalyzer?

  • A . It sorts log data into tables
  • B . It extracts the database schema
  • C . It retrieves log data from the database
  • D . It injects log data into the database

Reveal Solution Hide Solution

Correct Answer: C
C

Explanation:

Reference: https://docs2.fortinet.com/document/fortianalyzer/6.0.4/administration-guide/148744/creating-datasets

Question #22

Logs are being deleted from one of the ADOMs earlier than the configured setting for archiving in the data policy.

What is the most likely problem?

  • A . CPU resources are too high
  • B . Logs in that ADOM are being forwarded, in real-time, to another FortiAnalyzer device
  • C . The total disk space is insufficient and you need to add other disk
  • D . The ADOM disk quota is set too low, based on log rates

Reveal Solution Hide Solution

Correct Answer: D
D

Explanation:

Reference: https://help.fortinet.com/fmgr/50hlp/56/5-6-1/FMG-FAZ/1100_Storage/0017_Deleted%20device%20logs.htm

Question #23

Which two constraints can impact the amount of reserved disk space required by FortiAnalyzer? (Choose two.)

  • A . License type
  • B . Disk size
  • C . Total quota
  • D . RAID level

Reveal Solution Hide Solution

Correct Answer: B, D
B, D

Explanation:

https://docs.fortinet.com/document/fortianalyzer/6.2.5/administration-guide/368682/disk-space-allocation

Question #24

View the exhibit:

What does the 1000MB maximum for disk utilization refer to?

  • A . The disk quota for the FortiAnalyzer model
  • B . The disk quota for all devices in the ADOM
  • C . The disk quota for each device in the ADOM
  • D . The disk quota for the ADOM type

Reveal Solution Hide Solution

Correct Answer: B
B

Explanation:

https://docs.fortinet.com/document/fortianalyzer/6.2.0/administration-guide/743670/configuring-log-storage-policy

Question #25

You’ve moved a registered logging device out of one ADOM and into a new ADOM.

What happens when you rebuild the new ADOM database?

  • A . FortiAnalyzer resets the disk quota of the new ADOM to default.
  • B . FortiAnalyzer migrates archive logs to the new ADOM.
  • C . FortiAnalyzer migrates analytics logs to the new ADOM.
  • D . FortiAnalyzer removes logs from the old ADOM.

Reveal Solution Hide Solution

Correct Answer: C
C

Explanation:

https://kb.fortinet.com/kb/documentLink.do?externalID=FD40383

Question #26

What happens when a log file saved on FortiAnalyzer disks reaches the size specified in the device log

settings?

  • A . The log file is stored as a raw log and is available for analytic support.
  • B . The log file rolls over and is archived.
  • C . The log file is purged from the database.
  • D . The log file is overwritten.

Reveal Solution Hide Solution

Correct Answer: B
B

Explanation:

Reference:

https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/6d9f8fb5-6cf4-11e9-

81a4-00505692583a/FortiAnalyzer-6.0.5-Administration-Guide.pdf

https://docs.fortinet.com/document/fortianalyzer/6.2.5/administration-guide/355632/log-browse

Question #27

What is the purpose of employing RAID with FortiAnalyzer?

  • A . To introduce redundancy to your log data
  • B . To provide data separation between ADOMs
  • C . To separate analytical and archive data
  • D . To back up your logs

Reveal Solution Hide Solution

Correct Answer: A
A

Explanation:

https://en.wikipedia.org/wiki/RAID#:~:text=RAID%20(%22Redundant%20Array%20of%20Inexpensive,%2C%20performance%20improvement%2C%20or%20both.

Question #28

Which FortiAnalyzer feature allows you to retrieve the archived logs matching a specific timeframe from another FortiAnalyzer device?

  • A . Log upload
  • B . Indicators of Compromise
  • C . Log forwarding an aggregation mode
  • D . Log fetching

Reveal Solution Hide Solution

Correct Answer: D
D

Explanation:

https://docs.fortinet.com/document/fortianalyzer/6.2.0/administration-guide/651442/fetcher-management

Question #29

What is the recommended method of expanding disk space on a FortiAnalyzer VM?

  • A . From the VM host manager, add an additional virtual disk and use the #execute lvm extend <disk number> command to expand the storage
  • B . From the VM host manager, expand the size of the existing virtual disk
  • C . From the VM host manager, expand the size of the existing virtual disk and use the # execute format disk command to reformat the disk
  • D . From the VM host manager, add an additional virtual disk and rebuild your RAID array

Reveal Solution Hide Solution

Correct Answer: A
A

Explanation:

https://kb.fortinet.com/kb/documentLink.do?externalID=FD40848

Question #30

How are logs forwarded when FortiAnalyzer is using aggregation mode?

  • A . Logs are forwarded as they are received and content files are uploaded at a scheduled time.
  • B . Logs and content files are stored and uploaded at a scheduled time.
  • C . Logs are forwarded as they are received.
  • D . Logs and content files are forwarded as they are received.

Reveal Solution Hide Solution

Correct Answer: B
B

Explanation:

https://www.fortinetguru.com/2020/07/log-forwarding-fortianalyzer-fortios-6-2-3/

https://docs.fortinet.com/document/fortianalyzer/6.2.0/administration-guide/420493/modes

Reference: https://docs.fortinet.com/document/fortianalyzer/6.2.0/cookbook/63238/what-is-the-difference-between-log-forward-and-log-aggregation-modes

Question #31

How do you restrict an administrator’s access to a subset of your organization’s ADOMs?

  • A . Set the ADOM mode to Advanced
  • B . Assign the ADOMs to the administrator’s account
  • C . Configure trusted hosts
  • D . Assign the default Super_User administrator profile

Reveal Solution Hide Solution

Correct Answer: B
B

Explanation:

https://docs.fortinet.com/document/fortianalyzer/6.2.5/administration-guide/717578/assigning-administrators-to-an-adom

Question #32

In order for FortiAnalyzer to collect logs from a FortiGate device, what configuration is required? (Choose two.)

  • A . Remote logging must be enabled on FortiGate
  • B . Log encryption must be enabled
  • C . ADOMs must be enabled
  • D . FortiGate must be registered with FortiAnalyzer

Reveal Solution Hide Solution

Correct Answer: AD
AD

Explanation:

Pg 70: “after you add and register a FortiGate device with the FortiAnalyzer unit, you must also ensure that the FortiGate device is configured to send logs to the FortiAnalyzer unit.”

https://docs.fortinet.com/uploaded/files/4614/FortiAnalyzer-5.4.6-Administration%20Guide.pdf

Pg 45: “ADOMs must be enabled to support the logging and reporting of NON-FORTIGATE devices, such as FortiCarrier, FortiClientEMS, FortiMail, FortiWeb, FortiCache, and FortiSandbox.”

Question #33

What can the CLI command # diagnose test application oftpd 3 help you to determine?

  • A . What devices and IP addresses are connecting to FortiAnalyzer
  • B . What logs, if any, are reaching FortiAnalyzer
  • C . What ADOMs are enabled and configured
  • D . What devices are registered and unregistered

Reveal Solution Hide Solution

Correct Answer: A
A

Explanation:

https://docs.fortinet.com/document/fortianalyzer/6.2.5/cli-reference/395556/test#test_application

Question #34

What FortiView tool can you use to automatically build a dataset and chart based on a filtered search result?

  • A . Chart Builder
  • B . Export to Report Chart
  • C . Dataset Library
  • D . Custom View

Reveal Solution Hide Solution

Correct Answer: B
Question #35

In FortiAnalyzer’s FormView, source and destination IP addresses from FortiGate devices are not resolving to a hostname.

How can you resolve the source and destination IPs, without introducing any additional performance impact to FortiAnalyzer?

  • A . Configure local DNS servers on FortiAnalyzer
  • B . Resolve IPs on FortiGate
  • C . Configure # set resolve-ip enable in the system FortiView settings
  • D . Resolve IPs on a per-ADOM basis to reduce delay on FortiView while IPs resolve

Reveal Solution Hide Solution

Correct Answer: B
Question #36

What must you configure on FortiAnalyzer to upload a FortiAnalyzer report to a supported external server? (Choose two.)

  • A . SFTP, FTP, or SCP server
  • B . Mail server
  • C . Output profile
  • D . Report scheduling

Reveal Solution Hide Solution

Correct Answer: AC
AC

Explanation:

https://docs.fortinet.com/document/fortianalyzer/6.0.2/administration-guide/598322/creating-output-profiles

Question #37

View the exhibit.

Why is the total quota less than the total system storage?

  • A . 3.6% of the system storage is already being used.
  • B . Some space is reserved for system use, such as storage of compression files, upload files, and temporary report files
  • C . The oftpd process has not archived the logs yet
  • D . The logfiled process is just estimating the total quota

Reveal Solution Hide Solution

Correct Answer: B
B

Explanation:

https://docs.fortinet.com/document/fortianalyzer/6.2.5/administration-guide/368682/disk-space-allocation

Question #38

What purposes does the auto-cache setting on reports serve? (Choose two.)

  • A . To reduce report generation time
  • B . To automatically update the hcache when new logs arrive
  • C . To reduce the log insert lag rate
  • D . To provide diagnostics on report generation time

Reveal Solution Hide Solution

Correct Answer: AB
AB

Explanation:

Reference: https://docs.fortinet.com/document/fortianalyzer/6.0.0/administration-guide/282280/enabling-autocache

Question #39

If you upgrade your FortiAnalyzer firmware, what report elements can be affected?

  • A . Output profiles
  • B . Report settings
  • C . Report scheduling
  • D . Custom datasets

Reveal Solution Hide Solution

Correct Answer: D
Question #40

How does FortiAnalyzer retrieve specific log data from the database?

  • A . SQL FROM statement
  • B . SQL GET statement
  • C . SQL SELECT statement
  • D . SQL EXTRACT statement

Reveal Solution Hide Solution

Correct Answer: A
A

Explanation:

https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/137bb60e-ff37-11e8-8524-f8bc1258b856/fortianalyzer-fortigate-sql-technote-40-mr2.pdf

Question #41

On FortiAnalyzer, what is a wildcard administrator account?

  • A . An account that permits access to members of an LDAP group
  • B . An account that allows guest access with read-only privileges
  • C . An account that requires two-factor authentication
  • D . An account that validates against any user account on a FortiAuthenticator

Reveal Solution Hide Solution

Correct Answer: A
A

Explanation:

https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/747268/configuring-wildcard-admin-accounts

Question #42

For proper log correlation between the logging devices and FortiAnalyzer, FortiAnalyzer and all registered devices should:

  • A . Use DNS
  • B . Use host name resolution
  • C . Use real-time forwarding
  • D . Use an NTP server

Reveal Solution Hide Solution

Correct Answer: D
Question #43

What FortiGate process caches logs when FortiAnalyzer is not reachable?

  • A . logfiled
  • B . sqlplugind
  • C . oftpd
  • D . miglogd

Reveal Solution Hide Solution

Correct Answer: D
D

Explanation:

Reference: https://forum.fortinet.com/tm.aspx?m=143106

Question #44

FortiAnalyzer uses the Optimized Fabric Transfer Protocok (OFTP) over SSL for what purpose?

  • A . To upload logs to an SFTP server
  • B . To prevent log modification during backup
  • C . To send an identical set of logs to a second logging server
  • D . To encrypt log communication between devices

Reveal Solution Hide Solution

Correct Answer: D
Question #45

How can you configure FortiAnalyzer to permit administrator logins from only specific locations?

  • A . Use static routes
  • B . Use administrative profiles
  • C . Use trusted hosts
  • D . Use secure protocols

Reveal Solution Hide Solution

Correct Answer: C
C

Explanation:

https://docs.fortinet.com/document/fortianalyzer/6.2.5/administration-guide/186508/trusted-hosts

Question #46

Logs are being deleted from one of your ADOMs earlier that the configured setting for archiving in your data policy.

What is the most likely problem?

  • A . The total disk space is insufficient and you need to add other disk.
  • B . CPU resources are too high.
  • C . The ADOM disk quota is set too low based on log rates.
  • D . Logs in that ADOM are being forwarded in real-time to another FortiAnalyzer device.

Reveal Solution Hide Solution

Correct Answer: C
C

Explanation:

https://help.fortinet.com/fmgr/50hlp/56/5-6-1/FMGFAZ/1100_Storage/0017_Deleted%20device%20logs.htm

https://docs.fortinet.com/document/fortianalyzer/6.2.5/administration-guide/87802/automatic-deletion

Question #47

What is the purpose of the following CLI command?

  • A . To add a log file checksum
  • B . To add the MD’s hash value and authentication code
  • C . To add a unique tag to each log to prove that it came from this FortiAnalyzer
  • D . To encrypt log communications

Reveal Solution Hide Solution

Correct Answer: A
A

Explanation:

https://docs2.fortinet.com/document/fortianalyzer/6.0.3/cli-reference/849211/global

Question #48

View the exhibit.

What does the data point at 14:35 tell you?

  • A . FortiAnalyzer is dropping logs.
  • B . FortiAnalyzer is indexing logs faster than logs are being received.
  • C . FortiAnalyzer has temporarily stopped receiving logs so older logs’ can be indexed.
  • D . The sqlplugind daemon is ahead in indexing by one log.

Reveal Solution Hide Solution

Correct Answer: B
B

Explanation:

https://docs.fortinet.com/document/fortianalyzer/6.2.5/administration-guide/47690/insert-rate-vs-receive-rate-widget

Question #49

What remote authentication servers can you configure to validate your FortiAnalyzer administrator logons? (Choose three)

  • A . RADIUS
  • B . Local
  • C . LDAP
  • D . PKI
  • E . TACACS+

Reveal Solution Hide Solution

Correct Answer: ACE
Question #50

What statements are true regarding disk log quota? (Choose two)

  • A . The FortiAnalyzer stops logging once the disk log quota is met.
  • B . The FortiAnalyzer automatically sets the disk log quota based on the device.
  • C . The FortiAnalyzer can overwrite the oldest logs or stop logging once the disk log quota is met.
  • D . The FortiAnalyzer disk log quota is configurable, but has a minimum o 100mb a maximum based on the reserved system space.

Reveal Solution Hide Solution

Correct Answer: CD
Exit mobile version