Which two parameters impact the amount of reserved disk space required by FortiAnalyzer? (Choose two.)
On FortiAnalyzer, what is a wildcard administrator account?
What statements are true regarding disk log quota? (Choose two)
NO: 5
Which FortiAnalyzer feature allows you to retrieve the archived logs matching a specific timeframe from
another FortiAnalyzer device?
Which process is responsible for enforcing the log file size?
In order for FortiAnalyzer to collect logs from a FortiGate device, what configuration is required? (Choose two.)
FortiAnalyzer centralizes which functions? (Choose three)
Which statement is true about ADOMs?
Refer to the exhibit.
Laptop1 is used by several administrators to manage FortiAnalyzer. You want to configure a generic text filter that matches all login attempts to the web interface generated by any user other than "admin", and coming from Laptop1.
Which filter will achieve the desired result?
Refer to the exhibit.
What does the data point at 12:20 indicate?
Which daemon is responsible for enforcing raw log file size?
Which three RAID configurations provide fault tolerance on FortiAnalyzer? (Choose three.)
What is the purpose of the FortiAnalyzer command execute format disk?
You need to upgrade your FortiAnalyzer firmware.
What happens to the logs being sent to FortiAnalyzer from FortiGate during the time FortiAnalyzer is
temporarily unavailable?
An administrator has configured the following settings:
config system fortiview settings
set resolve-ip enable
end
What is the significance of executing this command?
Refer to the exhibit.
Which statement is correct regarding the event displayed?
How are logs forwarded when FortiAnalyzer is using aggregation mode?
What are the operating modes of FortiAnalyzer? (Choose two)
Why should you use an NTP server on FortiAnalyzer and all registered devices that log into FortiAnalyzer?
Which statement correctly describes RAID 10 (1+0) on FortiAnalyzer?
Which two statements are true about FortiAnalyzer log forwarding modes? (Choose two.)
A play book contains five tasks in total. An administrator executed the playbook and four out of five tasks finished successfully, but one task failed. What will be the status of the playbook after its execution?
Refer to the exhibit.
The capture displayed was taken on a FortiAnalyzer.
Why is a single IP address shown as the source for all logs received?
How can you attach a report to an incident?
Which two of the following must you configure on FortiAnalyzer to email a FortiAnalyzer report externally?
(Choose two.)
Which two statements are true regarding fabric connectors? (Choose two.)
What can you do on FortiAnalyzer to restrict administrative access from specific locations?
What are offline logs on FortiAnalyzer?
Which statement is true when you are upgrading the firmware on an HA cluster made up of two FortiAnalyzer devices?
Refer to the exhibit.
The exhibit shows the creation of a new administrator on FortiAnalyzer. The new account uses the credentials stored on an LDAP server.
Why would an administrator configure a password for this account?
FortiAnalyzer uses the Optimized Fabric Transfer Protocok (OFTP) over SSL for what purpose?
NO: 14
View the exhibit.
Why is the total quota less than the total system storage?
What are offline logs on FortiAnalyzer?
Which two statements regarding the log synchronization states for HA on FortiAnalyzer are true? (Choose two.)
Which log will generate an event with the status Contained?
How can you configure FortiAnalyzer to permit administrator logins from only specific locations?
What is the purpose of using prefilters when configuring event handlers?
You crested a playbook on FortiAnalyzer that uses a FortiOS connector
When configuring the FortiGate side, which type of trigger must be used so that the actions in an automation stitch are available in the FortiOS connector?
In a Fortinet Security Fabric, what can make an upstream FortiGate create traffic logs associated with sessions initiated on downstream FortiGate devices?
Refer to the exhibit.
Based on the output, what can you conclude about the FortiAnalyzer logging status?
An administrator has configured the following settings:
What is the purpose of executing these commands?
If a hard disk fails on a FortiAnalyzer that supports software RAID, what should you do to bring the
FortiAnalyzer back to functioning normally, without losing data?
Which clause is considered mandatory in SELECT statements used by the FortiAnalyzer to generate reports?
View the exhibit:
What does the 1000MB maximum for disk utilization refer to?
After you have moved a registered logging device out of one ADOM and into a new ADOM, what is the
purpose of running the following CLI command?
execute sql-local rebuild-adom
When you perform a system backup, what does the backup configuration contain? (Choose two.)
What is the main purpose of using an NTP server on FortiAnalyzer and all of its registered devices?
The connection status of a new device on FortiAnalyzer is listed as Unauthorized.
What does that status mean?
What are two advantages of setting up fabric ADOM? (Choose two.)
Which two constraints can impact the amount of reserved disk space required by FortiAnalyzer? (Choose
two.)
If you upgrade your FortiAnalyzer firmware, what report elements can be affected?
For proper log correlation between the logging devices and FortiAnalyzer, FortiAnalyzer and all registered
devices should:
What purposes does the auto-cache setting on reports serve? (Choose two.)
Refer to the exhibits.
How many events will be added to the incident created after running this playbook?