Fortinet NSE5_FAZ-6.2 Dumps Updated [Sep-2021] Get 100% Real Exam Questions! [Q14-Q37]

Share

[Sep-2021] Pass Fortinet NSE5_FAZ-6.2 Exam in First Attempt Guaranteed!

Full NSE5_FAZ-6.2 Practice Test and 65 unique questions with explanations waiting just for you, get it now!

NEW QUESTION 14
Which two methods can you use to send event notifications when an event occurs that matches a configured event handler? (Choose two.)

  • A. IM
  • B. SNMP
  • C. Email
  • D. SMS

Answer: B,C

 

NEW QUESTION 15
Logs are being deleted from one of your ADOMs earlier that the configured setting for archiving in your data policy. What is the most likely problem?

  • A. The ADOM disk quota is set too low based on log rates.
  • B. CPU resources are too high.
  • C. Logs in that ADOM are being forwarded in real-time to another FortiAnalyzer device.
  • D. The total disk space is insufficient and you need to add other disk.

Answer: A

 

NEW QUESTION 16
By default, what happens when a log file reaches its maximum file size?

  • A. FortiAnalyzer overwrites the log files.
  • B. FortiAnalyzer stops logging.
  • C. FortiAnalyzer rolls the active log by renaming the file.
  • D. FortiAnalyzer forwards logs to syslog.

Answer: C

 

NEW QUESTION 17
What are two of the key features of FortiAnalyzer? (Choose two.)

  • A. Reports
  • B. Cloud-based management
  • C. Centralized log repository
  • D. Virtual domains (VDOMs)

Answer: A,C

 

NEW QUESTION 18
View the exhibit.

What does the data point at 14:35 tell you?

  • A. The sqlplugind daemon is ahead in indexing by one log.
  • B. FortiAnalyzer is dropping logs.
  • C. FortiAnalyzer is indexing logs faster than logs are being received.
  • D. FortiAnalyzer has temporarily stopped receiving logs so older logs' can be indexed.

Answer: A

Explanation:
Explanation
Logs are received then they are indexed, no logging server in the world can index logs faster than they are received. When FAZ receives raw logs, they are inserted (indexed) by the SQL database and the sqlplugind daemon, this graph shows that FAZ received 3 logs and sqlplugind indexed 4.

 

NEW QUESTION 19
Logs are being deleted from one of the ADOMs earlier than the configured setting for archiving in the data policy.
What is the most likely problem?

  • A. The ADOM disk quota is set too low, based on log rates
  • B. Logs in that ADOM are being forwarded, in real-time, to another FortiAnalyzer device
  • C. The total disk space is insufficient and you need to add other disk
  • D. CPU resources are too high

Answer: A

Explanation:
Explanation
Explanation/Reference: https://help.fortinet.com/fmgr/50hlp/56/5-6-1/FMG-FAZ/1100_Storage/0017_Deleted%20device
%20logs.htm

 

NEW QUESTION 20
How do you restrict an administrator's access to a subset of your organization's ADOMs?

  • A. Assign the ADOMs to the administrator's account
  • B. Configure trusted hosts
  • C. Assign the default Super_User administrator profile
  • D. Set the ADOM mode to Advanced

Answer: A

 

NEW QUESTION 21
View the Exhibit:

Why is the total quota less than the total system storage?

  • A. The oftpd process has not archived the logs yet
  • B. The logfiled process is just estimating the total quota
  • C. Some space is reserved for system use, such as storage of compression files, upload files, and temporary report files
  • D. 3.6% of the system storage is already being used.

Answer: C

 

NEW QUESTION 22
What is the purpose of a dataset query in FortiAnalyzer?

  • A. It extracts the database schema
  • B. It retrieves log data from the database
  • C. It injects log data into the database
  • D. It sorts log data into tables

Answer: B

 

NEW QUESTION 23
If a hard disk fails on a FortiAnalyzer that supports software RAID, what should you do to bring the FortiAnalyzer back to functioning normally, without losing data?

  • A. Hot swap the disk
  • B. Shut down FortiAnalyzer and replace the disk
  • C. Replace the disk and rebuild the RAID manually
  • D. Take no action if the RAID level supports a failed disk

Answer: C

 

NEW QUESTION 24
Consider the CLI command:

What is the purpose of the command?

  • A. To encrypt log communications
  • B. To add a log file checksum
  • C. To add a unique tag to each log to prove that it came from this FortiAnalyzer
  • D. To add the MD5 hash value and authentication code

Answer: D

 

NEW QUESTION 25
View the exhibit.

What does the data point at 14:35 tell you?

  • A. The sqlplugind daemon is ahead in indexing by one log.
    Logs are received then they are indexed, no logging server in the world can index logs faster than they are received. When FAZ receives raw logs, they are inserted (indexed) by the SQL database and the sqlplugind daemon, this graph shows that FAZ received 3 logs and sqlplugind indexed 4.
  • B. FortiAnalyzer is dropping logs.
  • C. FortiAnalyzer is indexing logs faster than logs are being received.
  • D. FortiAnalyzer has temporarily stopped receiving logs so older logs' can be indexed.

Answer: A

 

NEW QUESTION 26
Why should you use an NTP server on FortiAnalyzer and all registered devices that log into FortiAnalyzer?

  • A. To use real-time forwarding
  • B. To properly correlate logs
  • C. To resolve host names
  • D. To improve DNS response times

Answer: B

 

NEW QUESTION 27
Which two constraints can impact the amount of reserved disk space required by FortiAnalyzer? (Choose two.)

  • A. Total quota
  • B. Disk size
  • C. RAID level
  • D. License type

Answer: B,C

 

NEW QUESTION 28
What are the operating modes of FortiAnalyzer? (Choose two)

  • A. Collector
  • B. Standalone
  • C. Manager
  • D. Analyzer

Answer: A,D

 

NEW QUESTION 29
What is the purpose of a predefined template on the FortiAnalyzer?

  • A. It specifies report settings which contains time period, device selection, and schedule
  • B. It contains predefined data to generate mock reports
  • C. It specifies the report layout which contains predefined texts, charts, and macros
  • D. It can be edited and modified as required

Answer: C

 

NEW QUESTION 30
You've moved a registered logging device out of one ADOM and into a new ADOM. What happens when you rebuild the new ADOM database?

  • A. FortiAnalyzer migrates analytics logs to the new ADOM.
  • B. FortiAnalyzer migrates archive logs to the new ADOM.
  • C. FortiAnalyzer removes logs from the old ADOM.
  • D. FortiAnalyzer resets the disk quota of the new ADOM to default.

Answer: A

 

NEW QUESTION 31
What remote authentication servers can you configure to validate your FortiAnalyzer administrator logons?
(Choose three)

  • A. TACACS+
  • B. Local
  • C. PKI
  • D. LDAP
  • E. RADIUS

Answer: A,D,E

 

NEW QUESTION 32
For proper log correlation between the logging devices and FortiAnalyzer, FortiAnalyzer and all registered devices should:

  • A. Use real-time forwarding
  • B. Use host name resolution
  • C. Use DNS
  • D. Use an NTP server

Answer: D

 

NEW QUESTION 33
Refer to the exhibit.

What does the 1000MB maximum for disk utilization refer to?

  • A. The disk quota for all devices in the ADOM
  • B. The disk quota for the FortiAnalyzer model
  • C. The disk quota for each device in the ADOM
  • D. The disk quota for the ADOM type

Answer: A

Explanation:
Explanation/Reference:

 

NEW QUESTION 34
Which FortiAnalyzer feature allows you to retrieve the archived logs matching a specific timeframe, from another FortiAnalyzer device?

  • A. Log fetching
  • B. Indicators of compromise
  • C. Log upload
  • D. Log forwarding in aggregation mode

Answer: A

 

NEW QUESTION 35
On the RAID management page, the disk status is listed as Initializing.
What does the status Initializing indicate about what the FortiAnalyzer is currently doing?

  • A. FortiAnalyzer is functioning normally
  • B. FortiAnalyzer is writing to all of its hard drives to make the array fault tolerant
  • C. FortiAnalyzer is ensuring that the parity data of a redundant drive is valid
  • D. FortiAnalyzer is writing data to a newly added hard drive to restore it to an optimal state

Answer: B

 

NEW QUESTION 36
Logs are being deleted from one of the ADOMs earlier than the configured setting for archiving in the data policy.
What is the most likely problem?

  • A. The ADOM disk quota is set too low, based on log rates
  • B. Logs in that ADOM are being forwarded, in real-time, to another FortiAnalyzer device
  • C. The total disk space is insufficient and you need to add other disk
  • D. CPU resources are too high

Answer: A

 

NEW QUESTION 37
......

Get Latest NSE5_FAZ-6.2 Dumps Exam Questions in here: https://www.dumpstillvalid.com/NSE5_FAZ-6.2-prep4sure-review.html