Fortinet NSE 5 - FortiAnalyzer 7.2 Analyst Free Sample Questions

Covers FortiAnalyzer concepts, log analysis, SOC event handlers and incident management, report management and troubleshooting, and creating and managing automation playbooks.

20 free sample questions217 in the full practice test Other version: FCP-FAZ-AD-7-4(194)

Try simulator

NSE5-FAZ-7-2 Sample Questions

  1. Question 1

    A SOC analyst at a financial services company is investigating a high-severity event related to multiple failed login attempts from a suspicious IP address. The analyst needs to quickly gather all associated traffic logs, endpoint logs, and application control logs related to this IP for the last 24 hours. Which FortiAnalyzer feature provides the most efficient, integrated view for this type of cross-log-type investigation?

    Answer and explanation

    Correct answer: C

    The global search bar in the 'Log View' tab is the most efficient tool for this task. It allows an analyst to search for a specific value (like an IP address) across all indexed log types simultaneously within the selected time frame. This provides a quick, correlated view of all activities associated with the IP without the need to build reports or manually browse individual log files.

  2. Question 2

    Multiple answers

    A security analyst is building a custom event handler to detect potential data exfiltration. The goal is to trigger an event if any single user uploads more than 100MB of data to any cloud storage application within a 5-minute window. Which three settings are required in the event handler configuration to achieve this specific logic? (Choose three.)

    Answer and explanation

    Correct answers: A, B, D

    To meet the requirement, the event handler must: 1) Filter for logs related to cloud storage applications. 2) Group the logs by user to track individual activity. 3) Use an aggregated condition to sum the uploaded bytes ('sentbyte' from the perspective of the client) and trigger when it exceeds 100MB (104,857,600 bytes) within the specified 5-minute (300 seconds) window.

  3. Question 3

    A SOC manager wants to create a weekly 'Top 10 Riskiest Users' report. This report should be based on a custom risk score calculated from the number of high-severity security events (IPS, Antivirus, Web Filter) associated with each user. To implement this, an analyst must first create a custom dataset. Which SQL query function is essential for counting the events associated with each user?

    Answer and explanation

    Correct answer: D

    The COUNT() function is the standard SQL aggregate function used to count the number of rows that match a specified condition. In this scenario, the analyst would use COUNT() in conjunction with GROUP BY user to get the total number of high-severity events for each user.

  4. Question 4

    True or False: When a playbook is triggered by an event handler, it can only use log fields from the single log that initiated the event.

    Answer and explanation

    Correct answer: B

    This statement is false. When an event handler triggers a playbook, it passes a JSON object containing details of the event. If the event was generated from an aggregation of multiple logs (e.g., '5 failed logins in 1 minute'), the playbook trigger can access the fields from all the logs that contributed to that aggregated event, not just the first or last one.

  5. Question 5

    A SOC analyst has created a playbook to automatically create a ServiceNow ticket when a 'Compromised Host' event is generated. After deploying the playbook, new 'Compromised Host' events are visible in FortiAnalyzer, but no tickets are being created in ServiceNow. The Playbook Monitor shows the playbook is not being triggered. What is the most likely cause of this issue?

    Answer and explanation

    Correct answer: B

    A playbook does not automatically run when an event is generated. It must be explicitly linked to an event handler. The analyst must edit the 'Compromised Host' event handler and, in the notification settings, enable the 'Execute Playbook' option and select the correct playbook. Since the Playbook Monitor shows no trigger activity, it indicates the link between the event handler and the playbook is missing.

  6. Question 6

    When creating a new ADOM in FortiAnalyzer 7.2, an administrator notices the 'ADOM Mode' option. What is the primary purpose of setting the ADOM Mode to 'Advanced'?

    Answer and explanation

    Correct answer: B

    The 'Advanced' ADOM mode is specifically designed to support devices running different major firmware versions within a single ADOM. This is useful in environments with a mix of FortiOS versions, although it may limit the visibility of certain version-specific features. The 'Normal' mode restricts the ADOM to devices of the same major firmware version.

  7. Question 7

    An analyst is reviewing the 'Compromised Hosts' list in the FortiView dashboard. They notice a host with a high threat score and several Indicators of Compromise (IOCs) listed. What is the primary source of the IOC data used by FortiAnalyzer to identify these compromised hosts?

    Answer and explanation

    Correct answer: B

    The 'Compromised Hosts' feature primarily relies on the FortiGuard Outbreak Detection Service (previously known as the IOC service). FortiAnalyzer downloads a package of IOCs from FortiGuard and scans incoming logs for matches. When a log entry matches a known indicator of compromise, the source IP is flagged and added to the Compromised Hosts list.

  8. Question 8

    Multiple answers

    A new SOC analyst is tasked with creating a playbook that performs the following actions upon detecting a high-severity IPS event:

    1. Retrieve the source IP address from the event log.
    2. Query a third-party threat intelligence service (via API) to check the IP's reputation.
    3. If the reputation is 'malicious', add the IP to a specific address group on the edge FortiGate to block it.

    Which two playbook components are essential for this workflow? (Choose two.)

    Answer and explanation

    Correct answers: A, C

    This workflow requires two key integrations: 1) An HTTP connector is needed to make an API call to the external threat intelligence service. 2) A FortiGate connector is required to interact with the FortiGate device and add the malicious IP to the specified address group for blocking.

  9. Question 9

    An administrator is configuring log fetching for a remote FortiGate. They want to ensure that if the connection between the FortiGate and FortiAnalyzer is interrupted, logs are buffered on the FortiGate and sent later when the connection is restored. Which FortiGate setting is required to enable this behavior?

    Answer and explanation

    Correct answer: B

    On the FortiGate, under the config log fortianalyzer setting, the upload-option must be set to store-and-upload. This enables the reliable logging feature, where logs are stored locally on the FortiGate's disk if the FortiAnalyzer is unreachable. Once the connection is re-established, the buffered logs are uploaded.

  10. Question 10

    A SOC analyst is debugging a playbook that is failing at a specific task. The task is supposed to extract a username from a log field and use it in a subsequent API call. The Playbook Monitor shows an error at the API call task. How can the analyst verify the value of the username variable as it was extracted in the preceding task?

    Answer and explanation

    Correct answer: D

    The Playbook Monitor provides detailed execution logs for each playbook run. To debug variable values, an analyst can navigate to the specific failed run, find the task that was supposed to extract the username, and expand its details. The 'Output' section for that task will show the exact values that were produced and passed on as variables to subsequent tasks, allowing the analyst to confirm if the extraction was successful or if the value was malformed.