Fortinet NSE5_FAZ-5.4 - FortiAnalyzer 5.4 Specialist Exam

Question #11 (Topic: Topic 1)
In FortiAnalyzer’s FortiView, source and destination IP addresses from FortiGate devices are not resolving to a hostname. How can you resolve the source and
destination IPs, without introducing any additional performance impact to FortiAnalyzer?
A. Configure # set resolve-ip enable in the system FortiView settings B. Resolve IPs on FortiGate C. Configure local DNS servers on FortiAnalyzer D. Resolve IPs on a per-ADOM basis to reduce delay on FortiView while IPs resolve
Answer: A
Question #12 (Topic: Topic 1)
What is the purpose of employing RAID with FortiAnalyzer?
A. To provide data separation between ADOMs B. To separate analytical and archive data C. To back up your logs D. To introduce redundancy to your log data
Answer: D
Question #13 (Topic: Topic 1)
What happens when a log file saved on FortiAnalyzer disks reaches the size specified in the device log settings?
A. The log file is stored as a raw log and is available for analytic support B. The log file rolls over and is archived C. The log file is purged from the database D. The log file is overwritten
Answer: B
Question #14 (Topic: Topic 1)
View the exhibit.
[Fortinet-NSE5-FAZ-5.4-1.0/xmlfile-7_1.png]
Why is the total quota less than the total system storage?
A. The oftpd process has not archived the logs yet B. The logfiled process is just estimating the total quota C. Some space is reserved for system use, such as storage of compression files, upload files, and temporary report files D. 3.6% of the system storage is already being used
Answer: C
Question #15 (Topic: Topic 1)
In order for FortiAnalyzer to collect logs from a FortiGate device, what configuration is required? (Choose two.)
A. ADOMs must be enabled B. Log encryption must be enabled C. FortiGate must be registered with FortiAnalyzer D. Remote logging must be enabled on FortiGate
Answer: AC
Download Exam
Page: 3 / 5
Total 25 questions