Summer Sale Limited Time 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = simple75

Pass the Fortinet Certified Professional Security Operations FCP_FAZ_AN-7.6 Questions and answers with Dumpstech

Exam FCP_FAZ_AN-7.6 Premium Access

View all detail and faqs for the FCP_FAZ_AN-7.6 exam

Practice at least 50% of the questions to maximize your chances of passing.
Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions
Questions # 21:

What is the purpose of using data selectors when configuring event handlers?

Options:

A.

They filter the types of logs that FortiAnalyzer can accept from registered devices.

B.

They download new filters can be used in event handlers.

C.

They apply their filter criteria to the entire event handler so that you don’t have to configure the same criteria in the individual rules.

D.

They are common filters that can be applied simultaneously to all event handlers.

Questions # 22:

Which log will generate an event with the status Unhandled?

Options:

A.

An AV log with action=quarantine.

B.

An IPS log with action=pass.

C.

A WebFilter log with action=dropped.

D.

An AppControl log with action=blocked.

Questions # 23:

You created a playbook on FortiAnalyzer that uses a FortiOS connector.

When configuring the FortiGate side, which type of trigger must be used so that the actions in an automation stitch are available in the FortiOS connector?

Options:

A.

FortiAnalyzer Event Handler

B.

Fabric Connector event

C.

FortiOS Event Log

D.

Incoming webhook

Questions # 24:

Which statement about exporting items in Report Definitions is true?

Options:

A.

Templates can be exported.

B.

Template exports contain associated charts and datasets.

C.

Chart exports contain associated datasets.

D.

Datasets can be exported.

Questions # 25:

As part of your analysis, you discover that an incident is a false positive.

You change the incident status to Closed: False Positive.

Which statement about your update is true?

Options:

A.

The audit history log will be updated.

B.

The corresponding event will be marked as mitigated.

C.

The incident will be deleted.

D.

The incident number will be changed

Questions # 26:

(Refer to the exhibit.

Question # 26

Which statement about the displayed event is correct? (Choose one answer)

Options:

A.

The security risk was dropped.

B.

The risk source is isolated.

C.

The security risk was blocked.

D.

The security event risk is from an application control log.

Questions # 27:

(When there are no matching parsers for a device log, what does FortiAnalyzer do? (Choose one answer)

Options:

A.

Drops the log

B.

Applies the generic SYSLOG parser

C.

Stores the log but doesn’t normalize it

D.

Archives the log for future analysis

Questions # 28:

Exhibit.

Question # 28

Which statement about the event displayed is correct?

Options:

A.

The risk source is isolated.

B.

The security risk was blocked or dropped.

C.

The security event risk is considered open.

D.

An incident was created from this event.

Questions # 29:

(In a FortiAnalyzer Fabric deployment, which three modules from Fabric members are available for analysis on the supervisor? (Choose three answers))

Options:

A.

Playbooks

B.

Indicators

C.

Logs

D.

Events

E.

Reports

Questions # 30:

After generating a report, you notice the information you were expecting to see is not included in it. However, you confirm that the logs are there:

Which two actions should you perform? (Choose two.)

Options:

A.

Check the time frame covered by the report.

B.

Disable auto-cache.

C.

Increase the report utilization quota.

D.

Test the dataset.

Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions