没有合适的资源?快使用搜索试试~ 我知道了~
NSE5-FAZ-7.0.pdf
1.该资源内容由用户上传,如若侵权请联系客服进行举报
2.虚拟产品一经售出概不退款(资源遇到问题,请及时私信上传者)
2.虚拟产品一经售出概不退款(资源遇到问题,请及时私信上传者)
版权申诉
0 下载量 63 浏览量
2023-07-05
09:30:13
上传
评论
收藏 1.35MB PDF 举报
温馨提示
试读
31页
NSE5_FAZ-7.0 刚刚通过 内容非常稳
资源推荐
资源详情
资源评论
Fortinet
NSE5_FAZ-7.0 Exam
Fortinet NSE 5 - FortiAnalyzer 7.0
Questions & Answers
Question 1
Which two methods are the most common methods to control and restrict administrative access on FortiAnalyzer? (Choose
two.)
A. Virtual domains
B. Administrative access profiles
C. Trusted hosts
D. Security Fabric
Correct Answer: BC
Explanation/Reference:
https://docs2.fortinet.com/document/fortianalyzer/6.0.0/administrationguide/219292/administrator-profiles
https://docs2.fortinet.com/document/fortianalyzer/6.0.0/administration-guide/581222/trusted-hosts
Question 2
Which daemon is responsible for enforcing raw log file size?
A. logfiled
B. oftpd
C. sqlplugind
D. miglogd
Correct Answer: A
Explanation/Reference:
Question 3
An administrator has configured the following settings:
config system global
set log-checksum md5-auth
end
What is the significance of executing this command?
A. This command records the log file MD5 hash value.
B. This command records passwords in log files and encrypts them.
C. This command encrypts log transfer between FortiAnalyzer and other devices.
D. This command records the log tile MD5 hash value and authentication code.
Correct Answer: D
Explanation/Reference:
https://docs.fortinet.com/document/fortianalyzer/6.4.6/administrationguide/410387/appendix-b-log-integrity-and-secure-
log-transfer
Question 4
Which two of the following must you configure on FortiAnalyzer to email a FortiAnalyzer report externally? (Choose two.)
A. Mail server
B. Output profile
C. SFTP server
D. Report scheduling
Correct Answer: AB
Explanation/Reference:
https://docs.fortinet.com/document/fortianalyzer/6.0.2/administrationguide/598322/creating-output-profiles
Question 5
*For which two purposes would you use the command set log checksum? (Choose two.)
A. To help protect against man-in-the-middle attacks during log upload from FortiAnalyzer to an SFTP server
B. To prevent log modification or tampering
C. To encrypt log communications
D. To send an identical set of logs to a second logging server
Correct Answer: AB
Explanation/Reference:
To prevent the log in the store from being modified, you can add a log checksum by using the config system global
command. When the log is split, archived, and the log is uploaded (if the feature is enabled), you can configure the
FortiAnalyzer to log the log file hash value, timestamp, and authentication code. This can help defend against man-in-the-
middle attacks when uploading log transmission data from the FortiAnalyzer to the SFTP server.
Question 6
Refer to the exhibit.
What does the data point at 14:55 tell you?
A. The received rate is almost at its maximum for this device
B. The sqlplugind daemon is behind in log indexing by two logs
C. Logs are being dropped
D. Raw logs are reaching FortiAnalyzer faster than they can be indexed
Correct Answer: D
Explanation/Reference:
Question 7
You are using RAID with a FortiAnalyzer that supports software RAID, and one of the hard disks on FortiAnalyzer has failed.
What is the recommended method to replace the disk?
A. Shut down FortiAnalyzer and then replace the disk
B. Downgrade your RAID level, replace the disk, and then upgrade your RAID level
C. Clear all RAID alanns and replace the disk while FortiAnalyzer is still running
D. Perform a hot swap
Correct Answer: A
Explanation/Reference:
supports hot swapping on hardware RAID only.so it is recommended that on FortiAnalyzer devices with software RAID you
should shutdown FortiAnalyzer pnor to exchanging the hard disk.
https://community.fortinet.com/t5/FortiAnalyzer/Technical-Note-How-to-swap-Hard-Disk-onFortiAnalyzer/
tap/194997?extemaliD=FD41397#:??:text=rf>/o20a%20hard%20disk%20on,process%20known%20as%20hot %20swapping
Question 8
On the RAID management page, the disk status is listed as Initializing.
What does the status Initializing indicate about what the FortiAnalyzer is currently doing?
A. FortiAnalyzer is ensuring that the parity data of a redundant drive is valid
B. FortiAnalyzer is writing data to a newly added hard drive to restore it to an optimal state
C. FortiAnalyzer is writing to all of its hard drives to make the array fault tolerant
D. FortiAnalyzer is functioning normally
Correct Answer: C
Explanation/Reference:
https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/4cb0dce6-dbef-11e9-8977-
00505692583a/FortiAnalyzer-5.6.10-Administration-Guide.pdf
Question 9
In FortiAnalyzer's FormView, source and destination IP addresses from FortiGate devices are not resolving to a hostname.
How can you resolve the source and destination IPs, without introducing any additional performance impact to
FortiAnalyzer?
A. Resolve IP addresses on a per-ADOM basis to reduce delay on Forti View while IPs resolve
B. Configure# set resolve-ip enable in the system FortiView settings
C. Configure local DNS servers on ForriAnalyzer
D. Resolve lP addresses on FortiGate
Correct Answer: D
Explanation/Reference:
https://packetplant.com/fortigate-and-fortianalyzer-resolve-source-and-destination-ip/
'As a best practice, it is recommended to resolve IPs on the FortiGate end. This is because you get both source and
destination, and it offloads the work from FortiAnalyzer.On FortiAnalyzer, this IP resolution does destination IPs only'
Question 10
You have recently grouped multiple FortiGate devices into a single ADOM.
System Settings> Storage lnfo shows the quota used.
What does the disk quota refer to?
A. The maximum disk utilization for each device in the ADOM
B. The maximum disk utilization for the FortiAnalyzer model
C. The maximum disk utilization for the ADOM type
D. The maximum disk utilization for all devices in the ADOM
Correct Answer: D
Explanation/Reference:
Question 11
Why should you use an NTP server on FortiAnalyzer and all registered devices that log into fortiAnalyzer?
A. To properly correlate logs
B. To use real-time forwarding
C. To resolve host names
D. To improve DNS response times
Correct Answer: A
Explanation/Reference:
Question 12
You need to upgrade your FortiAnalyzer firmware.
What happens to the logs being sent to FortiAnalyzer from FortiGate during the time FortiAnalyzer is temporarily
unavailable?
A. FortiAnalyzer uses log fetching to retrieve the logs when back online
B. FortiGate uses the miglogd process to cache the logs
C. The logfiled process stores logs in offline mode
D. Logs are dropped
Correct Answer: B
Explanation/Reference:
If FortiAnalyzer becomes unavailable to FortiGate for any reason, FortiGate uses its migfo;d process to cache the logs.There
is a maximum value to the cache size, and the miglogd process will drop cached logs. When the connection between the
two devices is restored, the miglogd process begins to send the cached logs to FortiAnalyzer.Therefore, the FoniGate buffer
will keeps logs long enough to sustain a.reboot of your FortiAnalyzer (if you are upgrading the firmware, for example).But it
is not intended for a lengthy FortiAnalyzer outage.
Question 13
*After you have moved a registered logging device out of one ADOM and into a new ADOM, what is the purpose of running
the following CLI command?
execute sql-local rebuild-adorn <new-ADOM-name.'>
A. To reset the disk quota enforcement to default
B. To remove the analytics logs of the device from the old database
C. To migrate the archive logs to the new ADOM
D. To populate the new ADOM with analytical logs for the moved device, so you can run reports
Correct Answer: D
Explanation/Reference:
Are the device's analytics logs required for reports in the new ADOM? If so, rebuild the new ADOM database:
Question 14
If a hard disk fails on a FortiAnalyzer that supports software RAID, what should you do to bring the FortiAnalyzer back to
functioning normally, without losing data?
A. Hot swap the disk
B. Replace the disk and rebuild the RAlD manually
C. Take no action if the RAID level supports a failed disk
D. Shut down FortiAnalyzer and replace the disk
Correct Answer: D
Explanation/Reference:
If a hard disk on a FortiAnalyzer unit fails, it must be replaced.On FortiAnalyzer devices that support hardware RAID,the
hard disk can be replaced while the unit is still running'" known as hot swapping.
On FortiAnalyzer units with software RAID, the device must be shutdown prior to exchanging the hard disk.
Question 15
If you upgrade the FortiAnalyzer firmware, which report element can be affected?
A. Custom datasets
B. Report scheduling
C. Report settings
D. Output profiles
Correct Answer: A
Explanation/Reference:
Question 16
FortiAnalyzer reports are dropping analytical data from 15 days ago, even though the data policy setting for analytics logs is
60 days.
What is the most likely problem?
A. Quota enforcement is acting on analytical data before a report is complete
B. Logs are rolling before the report is run
C. CPU resources are too high
D. Disk utilization for archive logs is set for 15 days
Correct Answer: B
Explanation/Reference:
https://forum.fortinet.com/tm.aspx?m=138806
Question 17
Which log type does the FortiAnalyzer indicators of compromise feature use to identify infected hosts?
A. Antivirus logs
B. Web filter logs
C. IPS logs
D. Application control logs
Correct Answer: B
Explanation/Reference:
FortiAnalyzer 通过根据每个最终用户的以下日志中的事件 IP、域和 URL 检查威胁数据库来识别可能的受损主机:
网络过滤器日志。
DNS 日志。
流量日志。
电子邮件筛选器日志(适用于 FortiMail 设备)。
Question 18
Which two settings must you configure on FortiAnalyzer to allow non-local administrators to authenticate to FortiAnalyzer
with any user account in a single LDAP group? (Choose two.)
A. A local wildcard administrator account
B. A remote LDAP server
C. A trusted host profile that restricts access to the LDAP group
D. An administrator group
Correct Answer: AB
Explanation/Reference:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD38567
Question 19
When you perform a system backup, what does the backup configuration contain? (Choose two.)
A. Generated reports
B. Device Iist
C. Authorized devices logs
D. System information
Correct Answer: BD
Explanation/Reference:
Question 20
Which clause is considered mandatory in SELECT statements used by the FortiAnalyzer to generate reports?
A. FROM
B. LIMIT
C. WHERE
D. ORDER BY
Correct Answer: A
Explanation/Reference:
FROM is the only mandatory clause required to form a SELECT statement: the rest of the clauses are optional and serve to
filter or limit, aggregate or combine.and control the sort.It is also important to note that the clauses must be coded in a
剩余30页未读,继续阅读
资源评论
优质网络系统领域创作者
- 粉丝: 2974
- 资源: 2414
下载权益
C知道特权
VIP文章
课程特权
开通VIP
上传资源 快速赚钱
- 我的内容管理 展开
- 我的资源 快来上传第一个资源
- 我的收益 登录查看自己的收益
- 我的积分 登录查看自己的积分
- 我的C币 登录后查看C币余额
- 我的收藏
- 我的下载
- 下载帮助
安全验证
文档复制为VIP权益,开通VIP直接复制
信息提交成功