FCP FCP FortiAnalyzer & Log Management 1 — Questions and Answers
Question 1: What is the primary role of FortiAnalyzer in the Fortinet Security Fabric?
- Centralized log collection, analysis, and reporting (Correct answer)
- Firewall policy enforcement
- Endpoint detection and response
- Network traffic shaping
Correct answer: Centralized log collection, analysis, and reporting
FortiAnalyzer serves as the centralized log management and analytics platform for collecting, correlating, and reporting on data from Fortinet devices.
Question 2: Which FortiAnalyzer feature allows administrators to create automated responses based on log data thresholds?
- Event handlers (Correct answer)
- Log forwarding
- ADOM segmentation
- Report templates
Correct answer: Event handlers
Event handlers in FortiAnalyzer let administrators define conditions and trigger automated actions or alerts when log data meets specified thresholds.
Question 3: What does ADOM stand for in FortiAnalyzer?
- Administrative Domain (Correct answer)
- Advanced Detection Operations Module
- Automated Data Operations Management
- Alert-Driven Operations Monitor
Correct answer: Administrative Domain
ADOM stands for Administrative Domain, which is used in FortiAnalyzer to segment management and log data by organization or department.
Question 4: In FortiAnalyzer, which log type records traffic allowed or denied by FortiGate firewall policies?
- Traffic logs (Correct answer)
- Event logs
- Antivirus logs
- IPS logs
Correct answer: Traffic logs
Traffic logs capture sessions that are permitted or blocked by FortiGate firewall policies, recording source, destination, and action taken.
Question 5: What FortiAnalyzer feature enables long-term storage of raw logs in a compressed archive format?
- Log archiving (Correct answer)
- Real-time monitoring
- ADOM replication
- Dataset queries
Correct answer: Log archiving
FortiAnalyzer's log archiving feature compresses and stores raw logs for extended periods to meet compliance and forensic investigation needs.
Question 6: Which FortiAnalyzer component allows administrators to build custom queries against the log database?
- Datasets (Correct answer)
- Event handlers
- ADOM backups
- Log forwarding profiles
Correct answer: Datasets
Datasets in FortiAnalyzer are SQL-like queries that extract specific data from the log database, forming the basis for custom reports and charts.
What is the primary role of FortiAnalyzer in the Fortinet Security Fabric?