Fortinet Certified Professional - FortiAnalyzer 7.4 Administrator Free Sample Questions

Covers FortiAnalyzer initial configuration, high availability, and RAID, device management and troubleshooting, log and report management, and administrative domains and backups.

20 free sample questions194 in the full practice test Other version: NSE5-FAZ-7-2(217)

Try simulator

FCP-FAZ-AD-7-4 Sample Questions

  1. Question 1

    A financial institution is using a hardware-based FortiAnalyzer 2000F for log aggregation and compliance reporting. The primary requirements are maximizing log ingestion write performance and providing redundancy for a single disk failure. Which RAID configuration should the administrator choose to best meet these requirements?

    Answer and explanation

    Correct answer: D

    RAID 10 (a stripe of mirrors) provides the best write performance among the redundant RAID levels because it does not require parity calculations for writes. It also offers redundancy for a single disk failure within each mirrored pair. RAID 5 has a write penalty due to parity calculations. RAID 6 has an even higher write penalty. RAID 1 offers redundancy but not the performance benefits of striping found in RAID 10.

  2. Question 2

    An administrator is troubleshooting why a newly registered FortiGate is not sending logs to FortiAnalyzer. The administrator has verified L3 connectivity and firewall policies. Which CLI command on the FortiGate is the most effective next step to diagnose the log upload process specifically for FortiAnalyzer?

    Answer and explanation

    Correct answer: C

    The diagnose test application oftps 1 command specifically tests the connection and log upload status to the FortiAnalyzer. It provides detailed output about the OFTPS (Over Fortinet Transfer Protocol Secure) connection state, including connection status, encryption settings, and log upload statistics, which is ideal for this troubleshooting scenario. Other commands are less specific to the FortiAnalyzer logging process.

  3. Question 3

    A security analyst needs to create a daily report that shows the top 10 users by blocked web traffic volume, but only for users in the 'Sales' and 'Marketing' LDAP groups. The standard datasets do not provide this level of filtering. What is the correct sequence of actions to generate this specific report?

    Answer and explanation

    Correct answer: B

    Standard report charts have limited filtering capabilities. To achieve complex filtering, such as by specific LDAP user groups, the correct method is to first create a custom dataset. This involves writing a SQL query that selects the required log data and uses a WHERE clause to filter on the usergroup field. Once this dataset is created and tested, it can be used as the source for a custom chart within a new report.

  4. Question 4

    A managed service provider (MSP) uses FortiAnalyzer to provide services for multiple customers. They have configured a wildcard administrator account using a RADIUS server to allow their engineers to log in. However, they need to ensure that engineers can only access the ADOMs for the customers they are assigned to manage. How can this be achieved?

    Answer and explanation

    Correct answer: B

    When using a wildcard RADIUS administrator, FortiAnalyzer can dynamically assign ADOM access based on vendor-specific attributes (VSAs) returned by the RADIUS server during authentication. By configuring the RADIUS server to send the Fortinet-ADOM-Name VSA containing the specific ADOM(s) an engineer is authorized to access, the MSP can enforce granular, per-user ADOM restrictions without creating multiple accounts on the FortiAnalyzer itself.

  5. Question 5

    Multiple answers

    Which two statements are true regarding the difference between Normal and Advanced ADOM modes on FortiAnalyzer? (Select TWO)

    Answer and explanation

    Correct answers: A, E

    A key distinction is how VDOMs are handled. In Normal mode, the FortiGate device is the unit of assignment, so all of its VDOMs must belong to one ADOM. Advanced mode provides more flexibility, allowing an administrator to assign individual VDOMs from a single physical FortiGate to multiple different ADOMs, which is essential for complex multi-tenant environments.

  6. Question 6

    True or False: Once an ADOM's disk quota is set, it can only be increased and cannot be decreased without deleting and recreating the ADOM.

    Answer and explanation

    Correct answer: B

    An ADOM's disk quota can be both increased and decreased after it has been set. This can be done through the GUI or CLI, provided there is available disk space. However, you cannot decrease the quota to a value less than the current amount of data stored in that ADOM.

  7. Question 7

    An administrator is restoring a FortiAnalyzer configuration backup onto a new, identical hardware model. The backup file is encrypted. What information, in addition to the backup file itself, is absolutely required to successfully complete the restore operation?

    Answer and explanation

    Correct answer: B

    When a FortiAnalyzer configuration backup is encrypted, the password used for that encryption is mandatory for the restore process. Without the correct password, the FortiAnalyzer cannot decrypt the file and the restore operation will fail.

  8. Question 8

    A FortiAnalyzer HA cluster is configured in active-passive mode. During a maintenance window, the primary unit is rebooted. A failover occurs as expected. After the original primary unit comes back online, it immediately takes over the primary role again, causing a second network interruption. What setting needs to be adjusted to prevent the original primary from automatically reclaiming its role after a reboot?

    Answer and explanation

    Correct answer: C

    HA preemption is the feature that allows a device with a higher priority (the original primary) to automatically take over the primary role when it becomes available. By disabling preemption, the original primary unit will remain in a passive state after it reboots, allowing the current primary (the original secondary) to continue its role without interruption. This prevents the unwanted second failover.

  9. Question 9

    An administrator observes that FortiAnalyzer is frequently rebuilding its SQL database, causing high CPU utilization and slow report generation. Which of the following actions is the most likely cause of this behavior?

    Answer and explanation

    Correct answer: B

    FortiAnalyzer maintains a specific SQL database schema for each FortiOS major version within an ADOM. If logs from a device with a different major FortiOS version (e.g., FortiOS 7.2 logs being sent to an ADOM configured for 7.4) are received, FortiAnalyzer will trigger a database rebuild to accommodate the different log format. This is a resource-intensive process and a common cause of performance issues.

  10. Question 10

    What is the primary purpose of using log forwarding on FortiAnalyzer?

    Answer and explanation

    Correct answer: B

    Log forwarding allows FortiAnalyzer to act as a central aggregator and then forward received logs to other systems. This is commonly used to integrate with a central corporate SIEM (like Splunk or QRadar) or to create a tiered logging architecture with multiple FortiAnalyzers (e.g., regional collectors forwarding to a central analyzer).