لا تريد أن تفوت شيئا؟

نصائح اجتياز امتحان الشهادة

آخر أخبار الامتحانات ومعلومات الخصم

برعاية وحديثة من قبل خبرائنا

نعم، أرسل لي النشرة الإخبارية

خذ اختبارات أخرى عبر الإنترنت

السؤال #1
Which statement about sending notifications with incident update is true?
A. You can send notifications to multiple external platforms
B. Notifications can be sent only by email
C. If you use multiple fabric connectors, all connectors must have the same settings
D. Notifications can be sent only when an incident is updated or deleted
عرض الإجابة
اجابة صحيحة: A
السؤال #2
Exhibit.Laptop1 is used by several administrators to manage FortiAnalyzer. You want to configure a generic text filter that matches all login attempts to the web interface generated by any user other than admin'', and coming from Laptop1.Which filter will achieve the desired result?
A. peration-login and performed_on==''GUI(10
B. peration-login and performed_on==''GU (10
C. peration-login and srcip== 10
D. peration-login and dstip==10
عرض الإجابة
اجابة صحيحة: A
السؤال #3
Which statement describes archive logs on FortiAnalyzer?
A. Logs that are indexed and stored in the SQL database
B. Logs a FortiAnalyzer administrator can access in FortiView
C. Logs compressed and saved in files with the
D. Logs previously collected from devices that are offline
عرض الإجابة
اجابة صحيحة: C
السؤال #4
Refer to the exhibit.Laptop1 is used by several administrators to manage FortiAnalyzer. You want to configure a generic text filter that matches all login attempts to the web interface generated by any user other than "admin", and coming from Laptop1.Which filter will achieve the desired result?
A. operation-login & dstip==10
B. operation-login & srcip==10
C. operation-login & performed_on=="GUI(10
D. operation-login & performed_on=="GUI(10
عرض الإجابة
اجابة صحيحة: D
السؤال #5
Refer to the exhibit.What can you conclude about the output?
A. he output is not ADOM specific
B. he log rate higher than the message rate is not normal
C. here are more event logs than traffic logs
D. he low indexing values require investigation
عرض الإجابة
اجابة صحيحة: B
السؤال #6
What is the purpose of playbook trigger variables?
A. To display statistics about the playbook runtime
B. To provide the trigger information to make the playbook start running
C. To use information from the trigger to filter the action in a task
D. To store the start times of playbooks with On_Schedule triggers
عرض الإجابة
اجابة صحيحة: C
السؤال #7
Which SQL query is in the correct order to query to database in the FortiAnalyzer?
A. SELECT devid FROM $log GROUP BY devid WHERE `user',,' users1'
B. SELECT FROM $log WHERE devid `user',, USER1' GROUP BY devid
C. SELCT devid WHERE 'user'-` USER1' FROM $log GROUP By devid
D. SELECT devid FROM $log WHERE `user'=' GROUP BY devid
عرض الإجابة
اجابة صحيحة: D
السؤال #8
Which two actions should an administrator take to vide Compromised Hosts on FortiAnalyzer? (Choose two.)
A. Enable device detection on the FotiGate device that are sending logs to FortiAnalyzer
B. Enable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent to fortiAnalyzer
C. Make sure all endpoints are reachable by FortiAnalyzer
D. Subscribe FortiAnalyzer to FortiGuard to keep its local threat database up to date
عرض الإجابة
اجابة صحيحة: AB
السؤال #9
Which statement about the FortiSOAR management extension is correct?
A. It requires a FortiManager configured to manage FortiGate
B. It runs as a docker container on FortiAnalyzer
C. It requires a dedicated FortiSOAR device or VM
D. It does not include a limited trial by default
عرض الإجابة
اجابة صحيحة: C
السؤال #10
Refer to Exhibit:Client-1 is trying to access the internet for web browsing.All FortiGate devices in the topology are part of a Security Fabric with logging to FortiAnalyzer configured. All firewall policies have logging enabled. All web filter profiles are configured to log only violations.Which statement about the logging behavior for this specific traffic flow is true?
A. Only FGT-B will create traffic logs
B. FGT-B will see the MAC address of FGT-A as the destination and notifies FGT-A to log this flow
C. FGT B will create traffic logs and will create web filter logs if it detects a violation
D. Only FGT-A will create web filter logs if it detects a violation
عرض الإجابة
اجابة صحيحة: D
السؤال #11
Which statement about the FortiSOAR management extension is correct?
A. It requires a FortiManager configured to manage FortiGate
B. It runs as a docker container on FortiAnalyzer
C. It requires a dedicated FortiSOAR device or VM
D. It does not include a limited trial by default
عرض الإجابة
اجابة صحيحة: C
السؤال #12
Refer to the exhibit.What can you conclude about the output?
A. The output is not ADOM specific
B. There are more event logs than traffic logs
C. The low indexing values require investigation
D. The log rate being higher than the message rate is not normal
عرض الإجابة
اجابة صحيحة: A
السؤال #13
Which statement about the FortiSOAR management extension is correct?
A. It requires a FortiManager configured to manage FortiGate
B. It runs as a docker container on FortiAnalyzer
C. It requires a dedicated FortiSOAR device or VM
D. It does not include a limited trial by default
عرض الإجابة
اجابة صحيحة: C
السؤال #14
Which log will generate an event with the status Unhandled?
A. An AV log with action=quarantine
B. An IPS log with action=pass
C. A WebFilter log will action=dropped
D. An AppControl log with action=blocked
عرض الإجابة
اجابة صحيحة: B
السؤال #15
Refer to the exhibits.Assume these are all the events that exist on the FortiAnalyzer device.How many events will be added to the incident created after running this playbook?
A. No events will be added
B. Eleven events will be added
C. Four events will be added
D. Seven events will be added
عرض الإجابة
اجابة صحيحة: C
السؤال #16
You created a playbook on FortiAnalyzer that uses a FortiOS connector.When configuring the FortiGate side, which type of trigger must be used so that the actions in an automation stich are available in the FortiOS connector?
A. FortiAnalyzer Event Handler
B. Fabric Connector event
C. FortiOS Event Log
D. Incoming webhook
عرض الإجابة
اجابة صحيحة: D
السؤال #17
Which log will generate an event with the status Unhandled?
A. An AV log with action=quarantine
B. An IPS log with action=pass
C. A WebFilter log will action=dropped
D. An AppControl log with action=blocked
عرض الإجابة
اجابة صحيحة: B
السؤال #18
When managing incidents on FortiAnlyzer, what must an analyst be aware of?
A. You can manually attach generated reports to incidents
B. The status of the incident is always linked to the status of the attach event
C. Severity incidents rated with the level High have an initial service-level agreement (SLA) response time of 1 hour
D. Incidents must be acknowledged before they can be analyzed
عرض الإجابة
اجابة صحيحة: A
السؤال #19
Exhibit.Which statement about the event displayed is correct?
A. The risk source is isolated
B. The security risk was blocked or dropped
C. The security event risk is considered open
D. An incident was created from this event
عرض الإجابة
اجابة صحيحة: B
السؤال #20
Which log will generate an event with the status Unhandled?
A. An AV log with action=quarantine
B. An IPS log with action=pass
C. A WebFilter log will action=dropped
D. An AppControl log with action=blocked
عرض الإجابة
اجابة صحيحة: B
السؤال #21
Exhibit.Based on the partial outputs displayed, which devices can be members of a FotiAnalyzer Fabric?
A. ortiAnalayzer1 and FortiAnalyzer3
B. ll devices listed can be members
C. ortiAnalyzer2 and FortiAnalyzer3
D. ortiAnalyzer1 and FortiAnalyzer2
عرض الإجابة
اجابة صحيحة: B
السؤال #22
Which statement regarding macros on FortiAnalyzer is true?
A. acros are ADOM-specific and each ADOM type have unique macros relevant to that ADOM
B. acros are useful in generating excel log files automatically based on the report settings
C. acros are predefined templates for reports and cannot be customized
D. acros are supported only on the FortiGate ADOMs
عرض الإجابة
اجابة صحيحة: A
السؤال #23
Exhibit.Which statement about the event displayed is correct?
A. The risk source is isolated
B. The security risk was blocked or dropped
C. The security event risk is considered open
D. An incident was created from this event
عرض الإجابة
اجابة صحيحة: B
السؤال #24
Which SQL query is in the correct order to query the database in the FortiAnalyzer?
A. SELECT devid FROM $log WHERE 'user'='USER1' GROUP BY devid
B. SELECT devid WHERE 'user'='USER1' FROM $log GROUP BY devid
C. SELECT devid FROM $log GROUP BY devid WHERE 'user'='USER1'
D. SELECT FROM $log WHERE devid 'user'='USER1' GROUP BY devid
عرض الإجابة
اجابة صحيحة: A
السؤال #25
Which statement about the FortiSOAR management extension is correct?
A. It requires a FortiManager configured to manage FortiGate
B. It runs as a docker container on FortiAnalyzer
C. It requires a dedicated FortiSOAR device or VM
D. It does not include a limited trial by default
عرض الإجابة
اجابة صحيحة: C
السؤال #26
In firmware version 7.6, how does on-premises FortiAnalyzer store logs? (Choose one answer)
A. Uses ClickHouse database
B. Uses MySQL database
C. Uses Postgres SQL database
D. Uses ElasticSeach database
عرض الإجابة
اجابة صحيحة: A
السؤال #27
Which log will generate an event with the status Unhandled?
A. An AV log with action=quarantine
B. An IPS log with action=pass
C. A WebFilter log will action=dropped
D. An AppControl log with action=blocked
عرض الإجابة
اجابة صحيحة: B
السؤال #28
Refer to the exhibit.What does the data point at 21:20 indicate?
A. FortiAnalyzer is indexing logs faster than logs are being received
B. The sqlpugind daemon is behind in receiving logs by one log
C. The fortilogd daemon is ahead in indexing by one log
D. The log insert lag time is high
عرض الإجابة
اجابة صحيحة: B
السؤال #29
Which two actions should an administrator take to vide Compromised Hosts on FortiAnalyzer? (Choose two.)
A. Enable device detection on the FotiGate device that are sending logs to FortiAnalyzer
B. Enable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent to fortiAnalyzer
C. Make sure all endpoints are reachable by FortiAnalyzer
D. Subscribe FortiAnalyzer to FortiGuard to keep its local threat database up to date
عرض الإجابة
اجابة صحيحة: AB
السؤال #30
Which log will generate an event with the status Contained?
A. An AV log with action=quarantine
B. An IPS log with action=pass
C. A WebFilter log will action=dropped
D. An AppControl log with action=blocked
عرض الإجابة
اجابة صحيحة: A
السؤال #31
You created a playbook on FortiAnalyzer that uses a FortiOS connector.When configuring the FortiGate side, which type of trigger must be used so that the actions in an automation stich are available in the FortiOS connector?
A. FortiAnalyzer Event Handler
B. Fabric Connector event
C. FortiOS Event Log
D. Incoming webhook
عرض الإجابة
اجابة صحيحة: D
السؤال #32
Which statement about automation connectors on FortiAnalyzer is true?
A. An ADOM with the Fabric type comes with multiple connectors configured
B. The local connector comes online once you have a playbook task referencing it
C. The actions available with FortiOS connectors are determined by automation rules configured on FortiGate
D. The playbook module must be enabled before external connectors are displayed
عرض الإجابة
اجابة صحيحة: A

View The Updated Fortinet Exam Questions

SPOTO Provides 100% Real Fortinet Exam Questions for You to Pass Your Fortinet Exam!

عرض الإجابات بعد التقديم

يرجى إرسال البريد الإلكتروني الخاص بك والواتس اب للحصول على إجابات الأسئلة.

ملحوظة: يرجى التأكد من صلاحية معرف البريد الإلكتروني وWhatsApp حتى تتمكن من الحصول على نتائج الاختبار الصحيحة.

بريد إلكتروني:
رقم الواتس اب/الهاتف:
Contact Us