Get 2021 Updated Free Fortinet NSE5_FAZ-6.2 Exam Questions & Answer
NSE5_FAZ-6.2 Dumps PDF and Test Engine Exam Questions
How much Fortinet NSE 5 - FortiAnalyzer (NSE5 FAZ-6.2) Exam Cost
The Fortinet NSE 5 - FortiAnalyzer (NSE5 FAZ-6.2) Exam Costs USD 400. As the exam costs may vary country or region vise, it is always recommended to check the official website to see what’s the cost of the exam for your country. Total cost for preparing for the exam will include study materials as well like NSE5 FAZ-6.2 dumps and NSE5 FAZ-6.2 practice exams. Refer to the official website by clicking here for more info on pricing.
NEW QUESTION 25
View the exhibit.
What does the data point at 14:35 tell you?
- A. FortiAnalyzer has temporarily stopped receiving logs so older logs' can be indexed.
- B. FortiAnalyzer is dropping logs.
- C. FortiAnalyzer is indexing logs faster than logs are being received.
- D. The sqlplugind daemon is ahead in indexing by one log.
Logs are received then they are indexed, no logging server in the world can index logs faster than they are received. When FAZ receives raw logs, they are inserted (indexed) by the SQL database and the sqlplugind daemon, this graph shows that FAZ received 3 logs and sqlplugind indexed 4.
Answer: D
NEW QUESTION 26
You have moved a registered logging device out of one ADOM and into a new ADOM.
What happens when you rebuild the new ADOM database?
- A. FortiAnalyzer migrates archive logs to the new ADOM.
- B. FortiAnalyzer resets the disk quota of the new ADOM to default.
- C. FortiAnalyzer removes analytics logs from the old ADOM.
- D. FortiAnalyzer migrates analytics logs to the new ADOM.
Answer: D
NEW QUESTION 27
Refer to the exhibit.
What does the 1000MB maximum for disk utilization refer to?
- A. The disk quota for all devices in the ADOM
- B. The disk quota for the ADOM type
- C. The disk quota for the FortiAnalyzer model
- D. The disk quota for each device in the ADOM
Answer: A
Explanation:
Explanation/Reference:
NEW QUESTION 28
What is the purpose of a predefined template on the FortiAnalyzer?
- A. It specifies the report layout which contains predefined texts, charts, and macros
- B. It contains predefined data to generate mock reports
- C. It can be edited and modified as required
- D. It specifies report settings which contains time period, device selection, and schedule
Answer: A
NEW QUESTION 29
Which FortiAnalyzer feature allows you to retrieve the archived logs matching a specific timeframe from another FortiAnalyzer device?
- A. Log fetching
- B. Log upload
- C. Log forwarding an aggregation mode
- D. Indicators of Compromise
Answer: A
NEW QUESTION 30
Which two purposes does the auto cache setting on reports serve? (Choose two.)
- A. It provides diagnostics on report generation time.
- B. It reduces report generation time.
- C. It automatically updates the hcache when new logs arrive.
- D. It reduces the log insert lag rate.
Answer: B,C
Explanation:
Reference:
https://docs.fortinet.com/document/fortianalyzer/6.2.5/administration-guide/384416/how-auto-cache-works
https://docs.fortinet.com/document/fortianalyzer/6.2.5/administration-guide/86926/enabling-auto-cache
NEW QUESTION 31
After you have moved a registered logging device out of one ADOM and into a new ADOM, what is the purpose of running the following CLI command?
execute sql-local rebuild-adom <new-ADOM-name>
- A. To reset the disk quota enforcement to default
- B. To migrate the archive logs to the new ADOM
- C. To populate the new ADOM with analytical logs for the moved device, so you can run reports
- D. To remove the analytics logs of the device from the old database
Answer: D
Explanation:
Explanation/Reference: https://docs.fortinet.com/document/fortianalyzer/6.0.2/cli-reference/551596/sql-local
NEW QUESTION 32
What can the CLI command # diagnose test application oftpd 3 help you to determine?
- A. What ADOMs are enabled and configured
- B. What devices are registered and unregistered
- C. What logs, if any, are reaching FortiAnalyzer
- D. What devices and IP addresses are connecting to FortiAnalyzer
Answer: D
NEW QUESTION 33
For proper log correlation between the logging devices and FortiAnalyzer, FortiAnalyzer and all registered devices should:
- A. Use DNS
- B. Use an NTP server
- C. Use real-time forwarding
- D. Use host name resolution
Answer: B
NEW QUESTION 34
In order for FortiAnalyzer to collect logs from a FortiGate device, what configuration is required? (Choose two.)
- A. Log encryption must be enabled
- B. FortiGate must be registered with FortiAnalyzer
- C. Remote logging must be enabled on FortiGate
- D. ADOMs must be enabled
Answer: B,C
Explanation:
Pg 70: "after you add and register a FortiGate device with the FortiAnalyzer unit, you must also ensure that the FortiGate device is configured to send logs to the FortiAnalyzer unit."
https://docs.fortinet.com/uploaded/files/4614/FortiAnalyzer-5.4.6-Administration%20Guide.pdf Pg 45: "ADOMs must be enabled to support the logging and reporting of NON-FORTIGATE devices, such as FortiCarrier, FortiClientEMS, FortiMail, FortiWeb, FortiCache, and FortiSandbox."
NEW QUESTION 35
View the exhibit.
Why is the total quota less than the total system storage?
- A. The oftpd process has not archived the logs yet
- B. Some space is reserved for system use, such as storage of compression files, upload files, and temporary report files
- C. 3.6% of the system storage is already being used.
- D. The logfiled process is just estimating the total quota
Answer: B
NEW QUESTION 36
View the exhibit:
What does the 1000MB maximum for disk utilization refer to?
- A. The disk quota for all devices in the ADOM
- B. The disk quota for the ADOM type
- C. The disk quota for the FortiAnalyzer model
- D. The disk quota for each device in the ADOM
Answer: A
NEW QUESTION 37
After you have moved a registered logging device out of one ADOM and into a new ADOM, what is the purpose of running the following CLI command?
execute sql-local rebuild-adom <new-ADOM-name>
- A. To reset the disk quota enforcement to default
- B. To migrate the archive logs to the new ADOM
- C. To populate the new ADOM with analytical logs for the moved device, so you can run reports
- D. To remove the analytics logs of the device from the old database
Answer: D
NEW QUESTION 38
You are using RAID with a FortiAnalyzer that supports software RAID, and one of the hard disks on FortiAnalyzer has failed.
What is the recommended method to replace the disk?
- A. Perform a hot swap
- B. Clear all RAID alarms and replace the disk while FortiAnalyzer is still running
- C. Downgrade your RAID level, replace the disk, and then upgrade your RAID level
- D. Shut down FortiAnalyzer and then replace the disk
Answer: D
Explanation:
NEW QUESTION 39
View the exhibit.
What does the data point at 14:35 tell you?
- A. The sqlplugind daemon is ahead in indexing by one log.
- B. FortiAnalyzer has temporarily stopped receiving logs so older logs' can be indexed.
- C. FortiAnalyzer is dropping logs.
- D. FortiAnalyzer is indexing logs faster than logs are being received.
Answer: D
Explanation:
https://docs.fortinet.com/document/fortianalyzer/6.2.5/administration-guide/47690/insert-rate-vs-receive-rate-widget
NEW QUESTION 40
View the exhibit.
Why is the total quota less than the total system storage?
- A. The oftpd process has not archived the logs yet
- B. Some space is reserved for system use, such as storage of compression files, upload files, and temporary report files
- C. 3.6% of the system storage is already being used.
- D. The logfiled process is just estimating the total quota
Answer: B
Explanation:
https://docs.fortinet.com/document/fortianalyzer/6.2.5/administration-guide/368682/disk-space-allocation
NEW QUESTION 41
FortiAnalyzer reports are dropping analytical data from 15 days ago, even though the data policy setting for analytics logs is 60 days.
What is the most likely problem?
- A. Quota enforcement is acting on analytical data before a report is complete
- B. CPU resources are too high
- C. Disk utilization for archive logs is set for 15 days
- D. Logs are rolling before the report is run
Answer: A
NEW QUESTION 42
What is the purpose of employing RAID with FortiAnalyzer?
- A. To introduce redundancy to your log data
- B. To back up your logs
- C. To provide data separation between ADOMs
- D. To separate analytical and archive data
Answer: A
Explanation:
https://en.wikipedia.org/wiki/RAID#:~:text=RAID%20(%22Redundant%20Array%20of%20Inexpensive,%2C%20performance%20improvement%2C%20or%20both.
NEW QUESTION 43
For which two purposes would you use the command set log checksum? (Choose two.)
- A. To prevent log modification or tampering
- B. To encrypt log communications
- C. To send an identical set of logs to a second logging server
- D. To help protect against man-in-the-middle attacks during log upload from FortiAnalyzer to an SFTP server
Answer: A,D
Explanation:
Explanation
To prevent the log in the store from being modified, you can add a log checksum by using the config system global command. When the log is split, archived, and the log is uploaded (if the feature is enabled), you can configure the FortiAnalyzer to log the log file hash value, timestamp, and authentication code. This can help defend against man-in-the-middle attacks when uploading log transmission data from the FortiAnalyzer to the SFTP server.
NEW QUESTION 44
In FortiAnalyzer's FormView, source and destination IP addresses from FortiGate devices are not resolving to a hostname. How can you resolve the source and destination IPs, without introducing any additional performance impact to FortiAnalyzer?
- A. Configure local DNS servers on FortiAnalyzer
- B. Resolve IPs on FortiGate
- C. Resolve IPs on a per-ADOM basis to reduce delay on FortiView while IPs resolve
- D. Configure # set resolve-ip enable in the system FortiView settings
Answer: B
NEW QUESTION 45
When you perform a system backup, what does the backup configuration contain? (Choose two.)
- A. System information
- B. Authorized devices logs
- C. Generated reports
- D. Device list
Answer: A,D
NEW QUESTION 46
......
Verified NSE5_FAZ-6.2 exam dumps Q&As with Correct 68 Questions and Answers: https://www.testkingpdf.com/NSE5_FAZ-6.2-testking-pdf-torrent.html

