Ultimate Guide to Prepare NSE5_FAZ-6.4 with Accurate PDF Questions [Jan 14, 2022]
Pass Fortinet With SureTorrent Exam Dumps
NEW QUESTION 49
On FortiAnalyzer, what is a wildcard administrator account?
- A. An account that validates against any user account on a FortiAuthenticator
- B. An account that permits access to members of an LDAP group
- C. An account that allows guest access with read-only privileges
- D. An account that requires two-factor authentication
Answer: B
Explanation:
https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/747268/configuring-wildcard-admin-accounts
NEW QUESTION 50
If a hard disk fails on a FortiAnalyzer that supports software RAID, what should you do to bring the FortiAnalyzer back to functioning normally, without losing data?
- A. Replace the disk and rebuild the RAID manually
- B. Shut down FortiAnalyzer and replace the disk
- C. Take no action if the RAID level supports a failed disk
- D. Hot swap the disk
Answer: B
Explanation:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD46446#:~:text=On%20FortiAnalyzer%2FFortiManager%20devices%20that,to%20exchanging%20the%20hard%20disk.
If a hard disk on a FortiAnalyzer unit fails, it must be replaced. On FortiAnalyzer devices that support hardware RAID, the hard disk can be replaced while the unit is still running - known as hot swapping. On FortiAnalyzer units with software RAID, the device must be shutdown prior to exchanging the hard disk.
NEW QUESTION 51
A rogue administrator was accessing FortiAnalyzer without permission, and you are tasked to see what activity was performed by that rogue administrator on FortiAnalyzer.
What can you do on FortiAnalyzer to accomplish this?
- A. Click FortiView and generate a report for that administrator.
- B. Click Task Monitor and view the tasks performed by that administrator.
- C. Click Log View and generate a report for that administrator.
- D. View the tasks performed by the rogue administrator in Fabric View.
Answer: B
NEW QUESTION 52
Which log type does the FortiAnalyzer indicators of compromise feature use to identify infected hosts?
- A. Antivirus logs
- B. Application control logs
- C. Web filter logs
- D. IPS logs
Answer: C
Explanation:
Reference:
FortiAnalyzer_Admin_Guide/3600_FortiView/0200_Using_FortiView/1200_Compromised_hosts_page.htm?
TocPath=FortiView%7CUsing%20FortiView%7C_____6
NEW QUESTION 53
You have recently grouped multiple FortiGate devices into a single ADOM. System Settings > Storage Info shows the quota used.
What does the disk quota refer to?
- A. The maximum disk utilization for the FortiAnalyzer model
- B. The maximum disk utilization for all devices in the ADOM
- C. The maximum disk utilization for each device in the ADOM
- D. The maximum disk utilization for the ADOM type
Answer: B
NEW QUESTION 54
What are two advantages of setting up fabric ADOM? (Choose two.)
- A. It can be used for fast data processing and log correlation
- B. It can include only FortiGate devices that are part of the same Security Fabric
- C. It can be used to facilitate communication between devices in same Security Fabric
- D. It can include all Fortinet devices that are part of the same Security Fabric
Answer: A,D
Explanation:
https://docs.fortinet.com/document/fortianalyzer/6.2.5/administration-guide/448471/creating-a-security-fabric-adom
NEW QUESTION 55
What is the main purpose of using an NTP server on FortiAnalyzer and all of its registered devices?
- A. Log collection
- B. Real-time forwarding
- C. Host name resolution
- D. Log correlation
Answer: A
NEW QUESTION 56
What are the operating modes of FortiAnalyzer? (Choose two)
- A. Standalone
- B. Collector
- C. Manager
- D. Analyzer
Answer: B,D
NEW QUESTION 57
Which two statements are true regarding ADOM modes? (Choose two.)
- A. Normal mode is the default ADOM mode.
- B. You can only change ADOM modes through CLI.
- C. In normal mode, the disk quota of the ADOM is fixed and cannot be modified, but in advance mode, the disk quota of the ADOM is flexible because new devices are added to the ADOM.
- D. In an advanced mode ADOM. you can assign FortiGate VDOMs from a single FortiGate device to multiple FortiAnalyzer ADOMs.
Answer: A,D
NEW QUESTION 58
Which two statements about log forwarding are true? (Choose two.)
- A. The client retains a local copy of the logs after forwarding.
- B. Logs are forwarded in real-time only.
- C. You can use aggregation mode only with another FortiAnalyzer.
- D. Forwarded logs cannot be filtered to match specific criteria.
Answer: A,C
Explanation:
https://docs.fortinet.com/document/fortianalyzer/6.2.5/administration-guide/420493/modes
https://docs.fortinet.com/document/fortianalyzer/6.2.5/administration-guide/621804/log-forwarding
NEW QUESTION 59
Which FortiAnalyzer feature allows you to retrieve the archived logs matching a specific timeframe from another FortiAnalyzer device?
- A. Log fetching
- B. Log forwarding an aggregation mode
- C. Log upload
- D. Indicators of Compromise
Answer: A
Explanation:
https://docs.fortinet.com/document/fortianalyzer/6.2.0/administration-guide/651442/fetcher-management
NEW QUESTION 60
Which statements are true regarding securing communications between FortiAnalyzer and FortiGate with IPsec? (Choose two.)
- A. IPsec is only enabled through the CLI on FortiAnalyzer.
- B. IPsec cannot be enabled if SSL is enabled as well.
- C. Must establish an IPsec tunnel ID and pre-shared key.
- D. Must configure the FortiAnalyzer end of the tunnel only--the FortiGate end is auto-negotiated.
Answer: B
NEW QUESTION 61
What two things should an administrator do to view Compromised Hosts on FortiAnalyzer? (Choose two.)
- A. Subscribe FortiAnalyzer to FortiGuard to keep its local threat database up-to-date.
- B. Enable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent to FortiAnalyzer.
- C. Make sure all endpoints are reachable by FortiAnalyzer.
- D. Enable device detection on an interface on the FortiGate devices that are connected to the FortiAnalyzer.
Answer: A,B
NEW QUESTION 62
By default, what happens when a log file reaches its maximum file size?
- A. FortiAnalyzer rolls the active log by renaming the file.
- B. FortiAnalyzer stops logging.
- C. FortiAnalyzer overwrites the log files.
- D. FortiAnalyzer forwards logs to syslog.
Answer: A
NEW QUESTION 63
What can the CLI command # diagnose test application oftpd 3 help you to determine?
- A. What devices are registered and unregistered
- B. What ADOMs are enabled and configured
- C. What devices and IP addresses are connecting to FortiAnalyzer
- D. What logs, if any, are reaching FortiAnalyzer
Answer: C
Explanation:
https://docs.fortinet.com/document/fortianalyzer/6.2.5/cli-reference/395556/test#test_application
NEW QUESTION 64
How are logs forwarded when FortiAnalyzer is using aggregation mode?
- A. Logs are forwarded as they are received and content files are uploaded at a scheduled time.
- B. Logs and content files are stored and uploaded at a scheduled time.
- C. Logs and content files are forwarded as they are received.
- D. Logs are forwarded as they are received.
Answer: B
Explanation:
https://www.fortinetguru.com/2020/07/log-forwarding-fortianalyzer-fortios-6-2-3/
https://docs.fortinet.com/document/fortianalyzer/6.2.0/administration-guide/420493/modes
NEW QUESTION 65
Refer to the exhibit.
What does the data point at 14:55 tell you?
- A. Logs are being dropped
- B. The received rate is almost at its maximum for this device
- C. Raw logs are reaching FortiAnalyzer faster than they can be indexed
- D. The sqlplugind daemon is behind in log indexing by two logs
Answer: C
NEW QUESTION 66
Consider the CLI command:
What is the purpose of the command?
- A. To add a log file checksum
- B. To add a unique tag to each log to prove that it came from this FortiAnalyzer
- C. To add the MD5 hash value and authentication code
- D. To encrypt log communications
Answer: A
Explanation:
https://docs.fortinet.com/document/fortianalyzer/6.2.5/cli-reference/849211/global
NEW QUESTION 67
Why should you use an NTP server on FortiAnalyzer and all registered devices that log into FortiAnalyzer?
- A. To improve DNS response times
- B. To resolve host names
- C. To use real-time forwarding
- D. To properly correlate logs
Answer: D
Explanation:
NEW QUESTION 68
Which two of the following must you configure on FortiAnalyzer to email a FortiAnalyzer report externally?
(Choose two.)
- A. Output profile
- B. Report scheduling
- C. SFTP server
- D. Mail server
Answer: A,D
NEW QUESTION 69
Logs are being deleted from one of the ADOMs earlier than the configured setting for archiving in the data policy.
What is the most likely problem?
- A. CPU resources are too high
- B. The ADOM disk quota is set too low, based on log rates
- C. The total disk space is insufficient and you need to add other disk
- D. Logs in that ADOM are being forwarded, in real-time, to another FortiAnalyzer device
Answer: B
Explanation:
Reference:
20logs.htm
NEW QUESTION 70
What remote authentication servers can you configure to validate your FortiAnalyzer administrator logons? (Choose three)
- A. RADIUS
- B. TACACS+
- C. PKI
- D. Local
- E. LDAP
Answer: A,B,E
NEW QUESTION 71
Which daemon is responsible for enforcing raw log file size?
- A. sqlplugind
- B. logfiled
- C. oftpd
- D. miglogd
Answer: B
NEW QUESTION 72
......
Latest NSE5_FAZ-6.4 Exam Dumps - Valid and Updated Dumps: https://www.suretorrent.com/NSE5_FAZ-6.4-exam-guide-torrent.html
Fully Updated NSE5_FAZ-6.4 Dumps - 100% Same Q&A In Your Real Exam: https://drive.google.com/open?id=1zgKYC689ggwaffq6hzekJMm7WaYTENyd