Skip to content

FCP-FAZ-AD-7-4 FCP - FortiAnalyzer 7.4 Administrator Practice Questions

Prepare for FCP-FAZ-AD-7-4 with more than an answer.

194 questions in the full set20 sample questionsUpdated Jan 25, 2026

Unlock the full exam and previous versions

  • v1Version 1 194 questions Current
  • NSE5-FAZ-7-2Legacy Fortinet NSE 5 - FortiAnalyzer 7.2 Analyst 217 questions Locked
Exam fee
$200 USD
Level
Professional
Valid for
2 years from exam date
Domains covered on the exam 4
  1. System Configuration25%
  2. Device Management25%
  3. Logs and Reports Management30%
  4. Administration20%
  1. 1

    Which three of the following are valid log storage locations for FortiAnalyzer log archiving? (Select THREE)

    Show answer details

    Correct answer: A, B, D

  2. 2

    Case Study:

    A retail company with 50 stores is deploying a central FortiAnalyzer at its headquarters (HQ) to collect logs from a FortiGate at each store. The WAN links to the stores are unstable and have limited bandwidth. The company's primary goal is to ensure no logs are lost during network outages. They also need to perform centralized reporting at HQ.

    The network team has proposed a solution, but wants to ensure it follows best practices. The key requirements are:

    • Guaranteed log delivery from all 50 stores, even during intermittent connectivity loss.
    • Minimized WAN bandwidth consumption for log traffic.
    • Centralized analysis and reporting capabilities at the HQ FortiAnalyzer.

    Which configuration on the store FortiGates best satisfies all these requirements?

    Show answer details

    Correct answer: B

    This combination directly addresses all requirements. Reliable logging (OFTPS) uses TCP to ensure guaranteed delivery. The store-and-upload option allows the FortiGate to cache logs locally if the FortiAnalyzer is unreachable and upload them once connectivity is restored, preventing log loss. Enabling compression minimizes the amount of data sent over the limited bandwidth WAN links.

  3. 3

    An administrator is using the diagram below to explain the FortiAnalyzer HA synchronization process to a colleague. Which statement accurately describes what happens during this process?

    sequenceDiagram participant Primary participant Secondary Primary->>Secondary: Heartbeat Check Secondary-->>Primary: Heartbeat ACK loop Sync Process Primary->>Secondary: Send Config/Data Deltas Secondary-->>Primary: Acknowledge Receipt end

    Show answer details

    Correct answer: B

    The FortiAnalyzer HA synchronization process is efficient. After an initial full sync, the primary unit does not send the entire dataset repeatedly. Instead, it tracks changes to its configuration and new logs it receives, and it synchronizes only these deltas to the secondary unit. This minimizes the traffic over the HA heartbeat/sync link.

  4. 4

    True or False: Using macros in a FortiAnalyzer report allows you to include dynamic data, such as the report generation time or the current device's name, directly into the report's text fields.

    Show answer details

    Correct answer: A

    Macros are placeholder variables that can be used in report layouts to insert dynamic information. This is useful for creating reusable report templates. Examples include %%datetime%% to insert the report generation timestamp, %%adom%% for the ADOM name, or %%device%% for the device serial number.

  5. 5

    An administrator is running a SQL query directly on the FortiAnalyzer CLI to find all traffic logs from the source IP 10.10.10.5 that were denied by a firewall policy. Which WHERE clause is correctly formatted to achieve this?

    Show answer details

    Correct answer: B

    The SQL schema for FortiAnalyzer logs uses specific, often abbreviated, column names. The correct column name for source IP is srcip and for the firewall action is action. Therefore, the correct syntax is WHERE srcip='10.10.10.5' AND action='deny'. Using incorrect column names like source_ip will result in a query error.

  6. 6

    A financial institution is using a hardware-based FortiAnalyzer 2000F for log aggregation and compliance reporting. The primary requirements are maximizing log ingestion write performance and providing redundancy for a single disk failure. Which RAID configuration should the administrator choose to best meet these requirements?

    Show answer details

    Correct answer: D

    RAID 10 (a stripe of mirrors) provides the best write performance among the redundant RAID levels because it does not require parity calculations for writes. It also offers redundancy for a single disk failure within each mirrored pair. RAID 5 has a write penalty due to parity calculations. RAID 6 has an even higher write penalty. RAID 1 offers redundancy but not the performance benefits of striping found in RAID 10.

  7. 7

    An administrator is troubleshooting why a newly registered FortiGate is not sending logs to FortiAnalyzer. The administrator has verified L3 connectivity and firewall policies. Which CLI command on the FortiGate is the most effective next step to diagnose the log upload process specifically for FortiAnalyzer?

    Show answer details

    Correct answer: C

    The diagnose test application oftps 1 command specifically tests the connection and log upload status to the FortiAnalyzer. It provides detailed output about the OFTPS (Over Fortinet Transfer Protocol Secure) connection state, including connection status, encryption settings, and log upload statistics, which is ideal for this troubleshooting scenario. Other commands are less specific to the FortiAnalyzer logging process.

  8. 8

    A security analyst needs to create a daily report that shows the top 10 users by blocked web traffic volume, but only for users in the 'Sales' and 'Marketing' LDAP groups. The standard datasets do not provide this level of filtering. What is the correct sequence of actions to generate this specific report?

    Show answer details

    Correct answer: B

    Standard report charts have limited filtering capabilities. To achieve complex filtering, such as by specific LDAP user groups, the correct method is to first create a custom dataset. This involves writing a SQL query that selects the required log data and uses a WHERE clause to filter on the usergroup field. Once this dataset is created and tested, it can be used as the source for a custom chart within a new report.

  9. 9

    A managed service provider (MSP) uses FortiAnalyzer to provide services for multiple customers. They have configured a wildcard administrator account using a RADIUS server to allow their engineers to log in. However, they need to ensure that engineers can only access the ADOMs for the customers they are assigned to manage. How can this be achieved?

    Show answer details

    Correct answer: B

    When using a wildcard RADIUS administrator, FortiAnalyzer can dynamically assign ADOM access based on vendor-specific attributes (VSAs) returned by the RADIUS server during authentication. By configuring the RADIUS server to send the Fortinet-ADOM-Name VSA containing the specific ADOM(s) an engineer is authorized to access, the MSP can enforce granular, per-user ADOM restrictions without creating multiple accounts on the FortiAnalyzer itself.

  10. 10

    Which two statements are true regarding the difference between Normal and Advanced ADOM modes on FortiAnalyzer? (Select TWO)

    Show answer details

    Correct answer: A, E

    A key distinction is how VDOMs are handled. In Normal mode, the FortiGate device is the unit of assignment, so all of its VDOMs must belong to one ADOM. Advanced mode provides more flexibility, allowing an administrator to assign individual VDOMs from a single physical FortiGate to multiple different ADOMs, which is essential for complex multi-tenant environments.

Create an account to continue.