Fortinet
FCP_FAZ_AN-7.4
Q1:
Exhibit.

What can you conclude about these search results? (Choose two.)
☐
A
They can be downloaded to a file.☐
B
They are sortable by columns and customizable.☐
C
They are not available for analysis in FortiView.☐
D
They were searched by using text mode.
Fortinet
FCP_FAZ_AN-7.4
Q2:
Exhibit.

A fortiAnalyzer analyst is customizing a SQL query to use in a report.
Which SQL query should the analyst run to get the expected results?
A)

B)

C)

D)

○
A
Option A○
B
Option B○
C
Option C○
D
Option D
Fortinet
FCP_FAZ_AN-7.4
Q3:
Exhibit.

What can you conclude about the output?
○
A
The message rate being lower that the log rate is normal.○
B
Both messages and logs are almost finished indexing.○
C
There are more traffic logs than event logs.○
D
The output is ADOM specific
Fortinet
FCP_FAZ_AN-7.4
Q4:
Why must you wait for several minutes before you run a playbook that you just created?
○
A
FortiAnalyzer needs that time to parse the new playbook.○
B
FortiAnalyzer needs that time to debug the new playbook.○
C
FortiAnalyzer needs that time to back up the current playbooks.○
D
FortiAnalyzer needs that time to ensure there are no other playbooks running.
Fortinet
FCP_FAZ_AN-7.4
Q5:
When managing incidents on FortiAnlyzer, what must an analyst be aware of?
○
A
You can manually attach generated reports to incidents.○
B
The status of the incident is always linked to the status of the attach event.○
C
Severity incidents rated with the level High have an initial service-level agreement (SLA) response time of 1 hour.○
D
Incidents must be acknowledged before they can be analyzed.