Fortinet Certified NSE5_FAZ-7.0 Dumps Questions Valid NSE5_FAZ-7.0 Materials [Q49-Q68]

Share

Fortinet Certified NSE5_FAZ-7.0  Dumps Questions Valid NSE5_FAZ-7.0 Materials

Current NSE5_FAZ-7.0 Exam Dumps [2023] Complete Fortinet Exam Smoothly

NEW QUESTION # 49
What are offline logs on FortiAnalyzer?

  • A. Logs that are indexed and stored in the SQL database.
  • B. When you restart FortiAnalyzer. all stored logs are considered to be offline logs.
  • C. Logs that are collected from offline devices after they boot up.
  • D. Compressed logs, which are also known as archive logs, are considered to be offline logs.

Answer: D

Explanation:
Reference:
Logs are received and saved in a log file on the FortiAnalyzer disks. Eventually, when the log file reaches a configured size, or at a set schedule, it is rolled over by being renamed. These files (rolled or otherwise) are known as archive logs and are considered offline so they don't offer immediate analytic support. Combined, they count toward the archive quota and retention limits, and they are deleted based on the ADOM data policy. FortiAnalyzer_7.0_Study_Guide-Online page 140


NEW QUESTION # 50
What is required to authorize a FortiGate on FortiAnalyzer using Fabric authorization?

  • A. A pre-shared key
  • B. The FortiGate serial number
  • C. A FortiGate ADOM
  • D. Valid FortiAnalyzer credentials

Answer: D

Explanation:
FortiAnalyzer_7.0_Study_Guide-Online.pdf page 93: The fourth method uses the Fortinet Security Fabric authorization process. This method requires that both FortiGate and FortiAnalyzer are running version 7.0.1 or higher. It is also required that the FortiGate administrator has valid credentials to log in on FortiAnalyzer and complete the registration.
https://docs.fortinet.com/document/fortianalyzer/7.2.1/administration-guide/13897/adding-a-fortigate-using-security-fabric-authorization


NEW QUESTION # 51
When working with FortiAnalyzer reports, what is the purpose of a dataset?

  • A. To define the chart type to be used
  • B. To provide the layout used for reports
  • C. To set the data included in templates
  • D. To retrieve data from the database

Answer: D

Explanation:
Reference:
Datasets: Structured Query Language (SQL) SELECT queries that extract specific data from the database


NEW QUESTION # 52
What must you configure on FortiAnalyzer to upload a FortiAnalyzer report to a supported external server?
(Choose two.)

  • A. Mail server
  • B. Output profile
  • C. Report scheduling
  • D. SFTP, FTP, or SCP server

Answer: A,B

Explanation:
https://docs.fortinet.com/document/fortianalyzer/6.0.2/administration-guide/598322/creating-output-profiles


NEW QUESTION # 53
Which statement is true when you are upgrading the firmware on an HA cluster made up of two FortiAnalyzer devices?

  • A. You can perform the firmware upgrade using only a console connection.
  • B. You can enable uninterruptible-upgrade so that the normal FortiAnalyzer operations are not interrupted while the cluster firmware upgrades.
  • C. First, upgrade the secondary device, and then upgrade the primary device.
  • D. Both FortiAnalyzer devices will be upgraded at the same time.

Answer: C

Explanation:
FortiAnalyzer_7.0_Study_Guide-Online.pdf page 64: To upgrade FortiAnalyzer HA cluster firmware:
1. Log in to each secondary device.
2. Upgrade the firmware of all secondary devices.
3. Wait for the upgrades to complete and verify that all secondary devices joined the cluster.
4. Verify that logs on all secondary devices are synchronized with the primary device.
5. Upgrade the primary device.
https://docs.fortinet.com/document/fortianalyzer/7.2.0/upgrade-guide/262607/upgrading-fortianalyzer-firmware


NEW QUESTION # 54
Which statements are true regarding securing communications between FortiAnalyzer and FortiGate with IPsec? (Choose two.)

  • A. Must establish an IPsec tunnel ID and pre-shared key.
  • B. Must configure the FortiAnalyzer end of the tunnel only--the FortiGate end is auto-negotiated.
  • C. IPsec cannot be enabled if SSL is enabled as well.
  • D. IPsec is only enabled through the CLI on FortiAnalyzer.

Answer: A,D

Explanation:
Option B is correct because you must establish an IPsec tunnel ID and pre-shared key to secure the communication between FortiAnalyzer and FortiGate with IPsec12. The tunnel ID is a unique identifier for each tunnel and the pre-shared key is a secret passphrase that authenticates the peers.
Option D is correct because IPsec is only enabled through the CLI on FortiAnalyzer1. You cannot configure IPsec settings through the GUI on FortiAnalyzer.


NEW QUESTION # 55
If you upgrade your FortiAnalyzer firmware, what report elements can be affected?

  • A. Report settings
  • B. Report scheduling
  • C. Output profiles
  • D. Custom datasets

Answer: D


NEW QUESTION # 56
Refer to the exhibit.

Which two statements are true regarding enabling auto-cache on FortiAnalyzer? (Choose two.)

  • A. Enabling auto-cache reduces report generation time for reports that require a long time to assemble datasets.
  • B. Reports will be cached in the memory.
  • C. Report size will be optimized to conserve disk space on FortiAnalyzer.
  • D. This feature is automatically enabled for scheduled reports.

Answer: A,D


NEW QUESTION # 57
How do you restrict an administrator's access to a subset of your organization's ADOMs?

  • A. Assign the ADOMs to the administrator's account
  • B. Configure trusted hosts
  • C. Set the ADOM mode to Advanced
  • D. Assign the default Super_User administrator profile

Answer: A

Explanation:
https://docs.fortinet.com/document/fortianalyzer/6.2.5/administration-guide/717578/assigning-administrators-to-an-adom


NEW QUESTION # 58
Refer to the exhibit.

Which image corresponds to the packet capture shown in the exhibit?
A)

B)

C)

D)

  • A. Option D
  • B. Option C
  • C. Option B
  • D. Option A

Answer: A


NEW QUESTION # 59
If a hard disk fails on a FortiAnalyzer that supports software RAID, what should you do to bring the FortiAnalyzer back to functioning normally, without losing data?

  • A. Take no action if the RAID level supports a failed disk
  • B. Replace the disk and rebuild the RAID manually
  • C. Hot swap the disk
  • D. Shut down FortiAnalyzer and replace the disk

Answer: D

Explanation:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD46446#:~:text=On%20FortiAnalyzer%2FFortiManager%20devices%20that,to%20exchanging%20the%20hard%20disk.
If a hard disk on a FortiAnalyzer unit fails, it must be replaced. On FortiAnalyzer devices that support hardware RAID, the hard disk can be replaced while the unit is still running - known as hot swapping. On FortiAnalyzer units with software RAID, the device must be shutdown prior to exchanging the hard disk.


NEW QUESTION # 60
You are using RAID with a FortiAnalyzer that supports software RAID, and one of the hard disks on FortiAnalyzer has failed.
What is the recommended method to replace the disk?

  • A. Downgrade your RAID level, replace the disk, and then upgrade your RAID level
  • B. Shut down FortiAnalyzer and then replace the disk
  • C. Perform a hot swap
  • D. Clear all RAID alarms and replace the disk while FortiAnalyzer is still running

Answer: B

Explanation:
https://community.fortinet.com/t5/FortiAnalyzer/Technical-Note-How-to-swap-Hard-Disk-on-FortiAnalyzer/ta-p/194997?externalID=FD41397#:~:text=If%20a%20hard%20disk%20on,process%20known%20as%20hot%20swapping


NEW QUESTION # 61
Which statement is true when you are upgrading the firmware on an HA cluster made up of two FortiAnalyzer devices?

  • A. You can enable uninterruptible-upgrade so that the normal FortiAnalyzer operations are not interrupted while the cluster firmware upgrades.
  • B. First, upgrade the secondary device, and then upgrade the primary device.
  • C. You can perform the firmware upgrade using only a console connection.
  • D. Both FortiAnalyzer devices will be upgraded at the same time.

Answer: C


NEW QUESTION # 62
What statements are true regarding the "store and upload" log transfer option between FortiAnalyzer and FortiGate? (Choose three.)

  • A. Disk logging is enabled on the FortiGate through the CLI only.
  • B. Only FortiGate models with hard disks can send logs to FortiAnalyzer using the store and upload option.
  • C. Disk logging is enabled by default on the FortiGate.
  • D. Both secure communications methods (SSL and IPsec) allow the store and upload option.
  • E. All FortiGates can send logs to FortiAnalyzer using the store and upload option.

Answer: A,B,D


NEW QUESTION # 63
What is the purpose of the following CLI command?

  • A. To add a log file checksum
  • B. To add a unique tag to each log to prove that it came from this FortiAnalyzer
  • C. To encrypt log communications
  • D. To add the MD's hash value and authentication code

Answer: A

Explanation:
https://docs2.fortinet.com/document/fortianalyzer/6.0.3/cli-reference/849211/global


NEW QUESTION # 64
Which two statements are correct regarding the export and import of playbooks? (Choose two.)

  • A. A playbook that was disabled when it was exported, will be disabled when it is imported.
  • B. You can export only one playbook at a time.
  • C. Playbooks can be exported and imported only within the same FortiAnaryzer.
  • D. You can import a playbook even if there is another one with the same name in the destination.

Answer: A,D

Explanation:
If the imported playbook has the same name as an existing one, FortiAnalyzer will create a new name that includes a timestamp to avoid conflicts.
Playbooks are imported with the same status they had (enabled or disabled) when they were exported.
Playbooks set to run automatically should be exported while they are disabled to avoid unintended runs on the destination.


NEW QUESTION # 65
Refer to the exhibit.

What does the data point at 14:55 tell you?

  • A. The sqlplugind daemon is behind in log indexing by two logs
  • B. Raw logs are reaching FortiAnalyzer faster than they can be indexed
  • C. The received rate is almost at its maximum for this device
  • D. Logs are being dropped

Answer: B


NEW QUESTION # 66
An administrator fortinet, is able to view logs and perform device management tasks, such as adding and removing registered devices. However, administrator fortinet is not able to create a mall server that can be used to send email.
What could be the problem?

  • A. Fortinet is assigned the Restricted_ User administrator profile.
  • B. Fortinet is assigned the Standard_ User administrator profile.
  • C. ADOM mode is configured with Advanced mode.
  • D. A trusted host is configured.

Answer: B

Explanation:
* Super_User, which, like in FortiGate, provides access to all device and system privileges.
* Standard_User, which provides read and write access to device privileges, but not system privileges.
* Restricted_User, which provides read access only to device privileges, but not system privileges. Access to the Management extensions is also removed.
* No_Permissions_User, which provides no system or device privileges. Can be used, for example, to temporarily remove access granted to existing admins.
FortiAnalyzer_7.0_Study_Guide-Online page 42


NEW QUESTION # 67
Which two statements are true regarding FortiAnalyzer log forwarding? (Choose two.)

  • A. Aggregation mode stores logs and content files and uploads them to another FortiAnalyzer device at a scheduled time.
  • B. Forwarding mode forwards logs in real time only to other FortiAnalyzer devices.
  • C. Both modes, forwarding and aggregation, support encryption of logs between devices.
  • D. In aggregation mode, you can forward logs to syslog and CEF servers as well.

Answer: A,C

Explanation:
A) FortiAnalyzer_7.0_Study_Guide-Online.pdf page 148: The log communication between devices can be protected by encryption, with the desired encryption level, using the commands shown on the slide. (You need to interpret this. "Real time" and "aggregation" is about the "moment" when Fortigate sends the logs. However, no matter the moment, Fortigate will upload logs encrypted or unencrypted based on previous / differente config).
C) FortiAnalyzer_7.0_Study_Guide-Online.pdf page 147: Aggregation: Logs and content files stored and uploaded at scheduled time.


NEW QUESTION # 68
......

NSE5_FAZ-7.0 Premium PDF & Test Engine Files with 116 Questions & Answers: https://www.freepdfdump.top/NSE5_FAZ-7.0-valid-torrent.html

Get 100% Real NSE5_FAZ-7.0 Accurate & Verified Answers As Seen in the Real Exam!: https://drive.google.com/open?id=124W3HrZB7y9eLHXpgOoqkn5bbvdCZeej