Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

FCP_FAZ_AN-7.6 Fortinet NSE 5 - FortiAnalyzer 7.6 Analyst Questions and Answers

Questions 4

After generating a report, you notice the information you were expecting to see is not included in it. However, you confirm that the logs are there:

Which two actions should you perform? (Choose two.)

Options:

A.

Check the time frame covered by the report.

B.

Disable auto-cache.

C.

Increase the report utilization quota.

D.

Test the dataset.

Buy Now
Questions 5

Which two modules can be imported and exported between ADOMs on FortiAnalyzer? (Choose two.)

Options:

A.

Templates

B.

Reports

C.

Charts

D.

Datasets

Buy Now
Questions 6

Refer to the exhibit.

FCP_FAZ_AN-7.6 Question 6

An analyst is using FortiView to look at the top threats recorded by FortiAnalyzer in the last 2 hours. What can the analyst conclude from the exhibit? (Choose one answer)

Options:

A.

There are cross-site scripting (XSS) attacks on an Apache web server.

B.

The attacks that have CVE IDs attached require priority attention.

C.

Only IPS threats constitute genuine threats.

D.

There are no critical level threats.

Buy Now
Questions 7

What is the purpose of playbook trigger variables?

Options:

A.

To display statistics about the playbook runtime

B.

To use information from the trigger to filter the action in a task

C.

To provide the trigger information to make the playbook start running

D.

To store the start the times of playbooks with On_Schedule triggers

Buy Now
Questions 8

Refer to Exhibit:

FCP_FAZ_AN-7.6 Question 8

What does the data point at 21:20 indicate?

Options:

A.

FortiAnalyzer is indexing logs faster than logs are being received.

B.

The fortilogd daemon is ahead in indexing by one log.

C.

The SQL database requires a rebuild because of high receive lag.

D.

FortiAnalyzer is temporarily buffering received logs so older logs can be indexed first.

Buy Now
Questions 9

What happens when the indicator of compromise (IOC) engine on FortiAnalyzer finds web logs that match blacklisted IP addresses?

Options:

A.

FortiAnalyzer flags the associated host for further analysis.

B.

A new infected entry is added for the corresponding endpoint under Compromised Hosts.

C.

The detection engine classifies those logs as Suspicious.

D.

The endpoint is marked as Compromised and, optionally, can be put in quarantine.

Buy Now
Questions 10

Which statement correctly describes one Difference between templates and reports?

Options:

A.

Reports provide more configuration options than templates

B.

Templates can be cloned, but reports cannot be cloned.

C.

Reports support macros, but templates do not.

D.

Template are mapped to device groups. while reports are mapped to ADOMs

Buy Now
Questions 11

As part of your analysis, you discover that an incident is a false positive.

You change the incident status to Closed: False Positive.

Which statement about your update is true?

Options:

A.

The audit history log will be updated.

B.

The corresponding event will be marked as mitigated.

C.

The incident will be deleted.

D.

The incident number will be changed

Buy Now
Questions 12

Which two statements about local logs on FortiAnalyzer are true? (Choose two.)

Options:

A.

They are not supported in FortiView.

B.

You can view playbook logs for all ADOMs in the root ADOM.

C.

Event logs show system-wide information, whereas application logs are ADOM-specific.

D.

Event logs are available only in the root ADOM.

Buy Now
Questions 13

Which three tasks can be performed on FortiAnalyzer using FortiAI? (Choose three.)

Options:

A.

Configure site-to-site VPN using FortiAI.

B.

Perform Incident investigation and response.

C.

Identify potential impacts and recommend remediation.

D.

Configure SD-WAN overlay using FortiAI.

E.

Perform threat hunting.

Buy Now
Questions 14

Which statement about the FortiSIEM management extension is correct?

Options:

A.

It allows you to manage the entire life cycle of a threat or breach.

B.

It can be installed as a dedicated VM.

C.

Its use of the available disk space is capped at 50%.

D.

It requires a licensed FortiSIEM supervisor.

Buy Now
Questions 15

Which FortiAnalyzer feature allows you to use a proactive approach when managing your network security?

Options:

A.

FortiView Monitor

B.

Outbreak alert services

C.

Incidents dashboard

D.

Threat hunting

Buy Now
Questions 16

Which log will generate an event with the status Unhandled?

Options:

A.

An AV log with action=quarantine.

B.

An IPS log with action=pass.

C.

A WebFilter log with action=dropped.

D.

An AppControl log with action=blocked.

Buy Now
Questions 17

Which two actions should an administrator take to view Compromised Hosts on FortiAnalyzer? (Choose two.)

Options:

A.

Enable device detection on the FortiGate devices that are sending logs to FortiAnalyzer.

B.

Enable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent to FortiAnalyzer.

C.

Make sure all endpoints are reachable by FortiAnalyzer.

D.

Subscribe FortiAnalyzer to FortiGuard to keep its local threat database up to date.

Buy Now
Questions 18

Exhibit.

FCP_FAZ_AN-7.6 Question 18

What is the analyst trying to create?

Options:

A.

The analyst is trying to create a trigger variable to the used in the playbook.

B.

The analyst is trying to create an output variable to be used in the playbook.

C.

The analyst is trying to create a report in the playbook.

D.

The analyst is trying to create a SOC report in the playbook.

Buy Now
Questions 19

(Refer to the exhibit.

FCP_FAZ_AN-7.6 Question 19

Which statement about the displayed event is correct? (Choose one answer)

Options:

A.

The security risk was dropped.

B.

The risk source is isolated.

C.

The security risk was blocked.

D.

The security event risk is from an application control log.

Buy Now
Questions 20

Refer to the exhibits.

FCP_FAZ_AN-7.6 Question 20

The event shown in the exhibit has been escalated to an incident.

Which SOC role is responsible for handling the escalated incident?

Options:

A.

Threat hunter

B.

Security analyst

C.

SOC engineer

D.

Incident responder

Buy Now
Questions 21

Refer to the exhibit.

FCP_FAZ_AN-7.6 Question 21

What can you conclude from this output? (Choose one answer)

Options:

A.

ADOM1 has 300 MB of disk space remaining.

B.

The allocated disk quota to ADOM1 is 3 GB.

C.

Archive logs are using more space than analytic logs.

D.

There is no disk quota allocated to quarantining files.

Buy Now
Questions 22

Exhibit.

FCP_FAZ_AN-7.6 Question 22

A FortiAnalyzer analyst is customizing a SQL query to use in a report.

Which SQL query should the analyst run to get the expected results?

A)

FCP_FAZ_AN-7.6 Question 22

B)

FCP_FAZ_AN-7.6 Question 22

C)

FCP_FAZ_AN-7.6 Question 22

D)

FCP_FAZ_AN-7.6 Question 22

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 23

(Refer to the exhibit.

FCP_FAZ_AN-7.6 Question 23

Which statement about the displayed event is correct? (Choose one answer)

Options:

A.

An incident was created from this event.

B.

The risk source is isolated.

C.

The security risk was escalated.

D.

The security event risk is considered open.

Buy Now
Exam Code: FCP_FAZ_AN-7.6
Exam Name: Fortinet NSE 5 - FortiAnalyzer 7.6 Analyst
Last Update: May 23, 2026
Questions: 79

PDF + Testing Engine

$64.99   $185.69

Testing Engine

$49.99   $142.83

PDF (Q&A)

$54.99   $157.11