Download Fortinet NSE 5 - FortiAnalyzer 6.2.NSE5_FAZ-6.2.VCEplus.2020-11-23.25q.vcex

Vendor: Fortinet
Exam Code: NSE5_FAZ-6.2
Exam Name: Fortinet NSE 5 - FortiAnalyzer 6.2
Date: Nov 23, 2020
File Size: 224 KB

How to open VCEX files?

Files with VCEX extension can be opened by ProfExam Simulator.

Purchase
Coupon: EXAM_HUB

Discount: 20%

Demo Questions

Question 1
Which two of the following must you configure on FortiAnalyzer to email a FortiAnalyzer report externally? (Choose two.)
  1. Mail server
  2. Output profile
  3. SFTP server
  4. Report scheduling
Correct answer: BC
Explanation:
Reference: https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/6d9f8fb5-6cf4-11e9-81a4-00505692583a/FortiAnalyzer-6.0.5-Administration-Guide.pdf (119)
Reference: https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/6d9f8fb5-6cf4-11e9-81a4-00505692583a/FortiAnalyzer-6.0.5-Administration-Guide.pdf (119)
Question 2
Refer to the exhibit.
 
Why is the total quota less than the total system storage?
  1. Some space is reserved for system use
  2. 3.6% of the system storage is already being used
  3. The logfiled process is just estimating the total quota
  4. The oftpd process has not archived the logs yet
Correct answer: B
Question 3
For which two purposes would you use the command set log checksum? (Choose two.)
  1. To help protect against man-in-the-middle attacks during log upload from FortiAnalyzer to an SFTP server 
  2. To prevent log modification or tampering
  3. To encrypt log communications
  4. To send an identical set of logs to a second logging server
Correct answer: AB
Explanation:
To prevent the log in the store from being modified, you can add a log checksum by using the config system global command. When the log is split, archived, and the log is uploaded (if the feature is enabled), you can configure the FortiAnalyzer to log the log file hash value, timestamp, and authentication code. This can help defend against man-in-the-middle attacks when uploading log transmission data from the FortiAnalyzer to the SFTP server.
To prevent the log in the store from being modified, you can add a log checksum by using the config system global command. When the log is split, archived, and the log is uploaded (if the feature is enabled), you can configure the FortiAnalyzer to log the log file hash value, timestamp, and authentication code. This can help defend against man-in-the-middle attacks when uploading log transmission data from the FortiAnalyzer to the SFTP server.
Question 4
Refer to the exhibit.
 
What does the data point at 14:55 tell you?
  1. The received rate is almost at its maximum for this device
  2. The sqlplugind daemon is behind in log indexing by two logs
  3. Logs are being dropped
  4. Raw logs are reaching FortiAnalyzer faster than they can be indexed
Correct answer: C
Question 5
You are using RAID with a FortiAnalyzer that supports software RAID, and one of the hard disks on FortiAnalyzer has failed. What is the recommended method to replace the disk?
  1. Shut down FortiAnalyzer and then replace the disk
  2. Downgrade your RAID level, replace the disk, and then upgrade your RAID level
  3. Clear all RAID alarms and replace the disk while FortiAnalyzer is still running
  4. Perform a hot swap
Correct answer: D
Explanation:
Reference: https://www.fortinetguru.com/2016/04/system-settings/6/
Reference: https://www.fortinetguru.com/2016/04/system-settings/6/
Question 6
On the RAID management page, the disk status is listed as Initializing.
What does the status Initializing indicate about what the FortiAnalyzer is currently doing? 
  1. FortiAnalyzer is ensuring that the parity data of a redundant drive is valid
  2. FortiAnalyzer is writing data to a newly added hard drive to restore it to an optimal state
  3. FortiAnalyzer is writing to all of its hard drives to make the array fault tolerant
  4. FortiAnalyzer is functioning normally
Correct answer: C
Explanation:
Reference: https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/4cb0dce6-dbef-11e9-8977-00505692583a/FortiAnalyzer-5.6.10-Administration-Guide.pdf (40)
Reference: https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/4cb0dce6-dbef-11e9-8977-00505692583a/FortiAnalyzer-5.6.10-Administration-Guide.pdf (40)
Question 7
In the FortiAnalyzer FortiView, source and destination IP addresses from FortiGate devices are not resolving to a hostname.
How can you resolve the source and destination IP addresses, without introducing any additional performance impact to FortiAnalyzer?
  1. Resolve IP addresses on a per-ADOM basis to reduce delay on FortiView while IPs resolve
  2. Configure # set resolve-ip enable in the system FortiView settings
  3. Configure local DNS servers on FortiAnalyzer
  4. Resolve IP addresses on FortiGate
Correct answer: B
Explanation:
Reference: https://forum.fortinet.com/tm.aspx?m=156950
Reference: https://forum.fortinet.com/tm.aspx?m=156950
Question 8
You have recently grouped multiple FortiGate devices into a single ADOM. System Settings > Storage Info shows the quota used. What does the disk quota refer to?
  1. The maximum disk utilization for each device in the ADOM
  2. The maximum disk utilization for the FortiAnalyzer model
  3. The maximum disk utilization for the ADOM type
  4. The maximum disk utilization for all devices in the ADOM
Correct answer: B
Question 9
Why should you use an NTP server on FortiAnalyzer and all registered devices that log into FortiAnalyzer?
  1. To properly correlate logs
  2. To use real-time forwarding
  3. To resolve host names
  4. To improve DNS response times
Correct answer: A
Question 10
You need to upgrade your FortiAnalyzer firmware.
What happens to the logs being sent to FortiAnalyzer from FortiGate during the time FortiAnalyzer is temporarily unavailable?
  1. FortiAnalyzer uses log fetching to retrieve the logs when back online
  2. FortiGate uses the miglogd process to cache the logs
  3. The logfiled process stores logs in offline mode
  4. Logs are dropped
Correct answer: B
HOW TO OPEN VCE FILES

Use VCE Exam Simulator to open VCE files
Avanaset

HOW TO OPEN VCEX AND EXAM FILES

Use ProfExam Simulator to open VCEX and EXAM files
ProfExam Screen

ProfExam
ProfExam at a 20% markdown

You have the opportunity to purchase ProfExam at a 20% reduced price

Get Now!