Fortinet Certified Professional - FortiAnalyzer 7.4 Analyst Free Sample Questions

20 free sample questions219 in the full practice test

Try simulator

FCP-FAZ-AN-7-4 Sample Questions

  1. Question 1

    A SOC analyst at a manufacturing firm is investigating a performance degradation issue with their FortiAnalyzer 7.4. They suspect that a specific custom report, which runs hourly, is consuming excessive system resources. The report uses a complex custom dataset that queries logs from the past 24 hours across all 500 of their managed FortiGates. Which diagnostic command would provide the most direct insight into the resource consumption specifically related to report generation?

    Answer and explanation

    Correct answer: C

    The diagnose test application reportd 2 command is specifically designed to show the status of running reports, including their progress, duration, and the SQL queries being executed. This provides the most direct information to identify a long-running or resource-intensive report. diagnose sql status shows the status of the SQL database but isn't specific to the reporting daemon. diagnose fortilogd lograte shows log ingestion rates, and get system performance status provides general system metrics, not specific daemon performance.

  2. Question 2

    A security analyst needs to create a playbook that automatically responds to a 'Malware Detected' event. The response requires retrieving the affected user's manager from an external HR system via a REST API and then sending a notification email to both the user and their manager. Which playbook component is essential for storing and reusing the manager's email address obtained from the API call for the subsequent notification task?

    Answer and explanation

    Correct answer: B

    Variables are used within playbooks to store data that can be used by subsequent tasks. In this scenario, the manager's email address returned by the REST API call must be stored in a variable so that the 'Send Email' task can access it and use it as a recipient address. A trigger starts the playbook, a connector facilitates the API call, and a task is an action, but none of these inherently store and pass data between steps like a variable does.

  3. Question 3

    Multiple answers

    A junior analyst is tasked with creating a new incident in FortiAnalyzer based on a series of correlated, low-priority events that, when combined, indicate a potential slow-scan attack. When creating the incident manually, which two of the following fields are mandatory? (Choose two.)

    Answer and explanation

    Correct answers: A, C

  4. Question 4

    A university's IT department uses FortiAnalyzer in Collector mode on a campus-wide VM cluster, which forwards all logs to an Analyzer-mode appliance in their central data center. An analyst in the data center is unable to see logs from a newly deployed FortiGate in the engineering building. The collector is receiving logs from other devices on the same subnet. What is the most likely reason for this issue?

    Answer and explanation

    Correct answer: B

    In an Analyzer/Collector architecture, the Collector must be explicitly configured to forward logs for specific devices or ADOMs to the Analyzer. Even if the Collector is receiving logs from the FortiGate, if the log forwarding policy for that device/ADOM is not enabled, the logs will not reach the central Analyzer. The other options describe incorrect log flows or are less likely given the scenario.

  5. Question 5

    True or False: When a playbook is exported from one FortiAnalyzer and imported into another, any connectors referenced in the playbook tasks are automatically created on the destination FortiAnalyzer if they do not already exist.

    Answer and explanation

    Correct answer: B

    The import/export function for playbooks only includes the playbook's definition and logic. It does not include the configuration for external connectors. The administrator must manually configure any required connectors on the destination FortiAnalyzer before the imported playbook can function correctly.

  6. Question 6

    A SOC manager wants to create a weekly executive summary report that shows only the top 10 most active applications and the top 5 users by bandwidth across the entire organization. The default reports show too much detail. To achieve this, the analyst must create a custom chart. Which component must be created first before the custom chart can be configured to display this specific, aggregated data?

    Answer and explanation

    Correct answer: D

    Datasets are the foundation of custom charts in FortiAnalyzer reports. A dataset defines the SQL-like query that fetches, filters, and aggregates the raw log data. To show the 'top 10 applications' or 'top 5 users', a dataset must be created first to perform this specific grouping and limiting of the data. The custom chart is then built upon this pre-processed dataset.

  7. Question 7

    An analyst is building a playbook to automate the initial triage of a suspected phishing email. The playbook is triggered by a FortiMail event. A key step is to extract the sender's email address and the URL from the event log to perform reputation checks. Which syntax should be used within the playbook tasks to reference these dynamic values from the triggering event?

    Answer and explanation

    Correct answer: C

    FortiAnalyzer playbooks use a Jinja2 templating syntax to reference variables. Values from the triggering event are accessed through the FGT_event object. The correct syntax is {{ FGT_event.fieldname }}, where fieldname corresponds to the normalized log field from the event, such as sender or url.

  8. Question 8

    A financial institution has a strict 90-day log retention policy for all traffic logs for compliance reasons. An administrator has confirmed that the global log retention settings are configured correctly. However, a recent audit found that traffic logs for the 'Trading_Floor' ADOM are being purged after only 30 days. Logs for all other ADOMs are retained for the full 90 days. What is the most likely cause of this discrepancy?

    Answer and explanation

    Correct answer: B

    FortiAnalyzer allows for both global and per-ADOM log retention policies. A policy configured at the ADOM level will always take precedence over the global settings for that specific ADOM. This allows for granular control based on different compliance or operational needs for different sets of devices.

  9. Question 9

    An analyst is investigating an incident involving a compromised user account. To determine the blast radius, they need to find every IP address the user j.doe has logged in from over the past 7 days. Which of the following FortiAnalyzer log view queries would be the most efficient for this task?

    Answer and explanation

    Correct answer: D

    The correct syntax for an exact match filter in the FortiAnalyzer log view is fieldname = 'value'. Using single quotes ensures an exact match for the string 'j.doe'. Using double quotes or no quotes can lead to different interpretations of the search term, and 'contains' would perform a substring match, which is less precise and efficient for this specific requirement.

  10. Question 10

    What is the primary function of an 'Indicator' within the FortiAnalyzer SOC module?

    Answer and explanation

    Correct answer: B

    An Indicator, often called an Indicator of Compromise (IoC), represents a piece of data that signifies a potential threat. This could be a malicious IP, a known bad URL, a file hash of malware, etc. FortiAnalyzer uses these indicators to scan incoming logs and historical data to find matches, which can then be used to generate events or incidents.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 219 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon