Skip to content

FCP-FAZ-AN-7-4 FCP - FortiAnalyzer 7.4 Analyst Practice Questions

Prepare for FCP-FAZ-AN-7-4 with more than an answer.

219 questions in the full set20 sample questionsUpdated Dec 7, 2025
Exam fee
$200 USD
Level
Professional
Valid for
2 years from the date of passing the second exam (NSE 4 + NSE 5)
Domains covered on the exam 5
  1. Features and Concepts20%
  2. Logging25%
  3. SOC Events and Incident Management25%
  4. Reports15%
  5. Playbooks15%
  1. 1

    A retail company needs to generate a PCI DSS compliance report. They are using a predefined FortiAnalyzer report template for this purpose. However, their internal auditor requires that the report includes a custom section detailing all firewall policy changes made by a specific administrator group (PCI_Admins) during the audit period. Which combination of actions must be performed to fulfill this requirement? (Select TWO)

    Show answer details

    Correct answer: A, C

  2. 2

    Which of the following best describes the function of log normalization in FortiAnalyzer?

    Show answer details

    Correct answer: C

    Log normalization is the process of taking logs from various sources (FortiGate, FortiMail, FortiWeb, etc.), which have different native formats, and mapping their fields to a standardized schema. This allows analysts to use consistent field names like srcip, dstip, and user in queries, reports, and event handlers, regardless of the original log source.

  3. 3

    A security analyst is reviewing an incident that was automatically generated by an event handler. The incident contains multiple events related to traffic from a known malicious IP address. The analyst wants to see the raw logs associated with these specific events to conduct a deeper investigation. What is the most direct way to access these logs from the incident details view?

    Show answer details

    Correct answer: B

    The FortiAnalyzer incident management interface provides direct drill-down capabilities. From within the incident details, an analyst can click on the attached events, which will pivot them directly to the Log View, automatically filtered to show the specific raw logs that triggered those events. This provides a seamless workflow for investigation.

  4. 4

    An administrator is attempting to import a playbook that was exported from a colleague's FortiAnalyzer. The import fails with an error. The administrator verifies that the file is not corrupted and that they have the correct permissions. The playbook contains a task that quarantines an endpoint using a FortiClient EMS connector. The destination FortiAnalyzer does not have a FortiClient EMS connector configured. Is this the reason for the import failure?

    Show answer details

    Correct answer: B

    False. The import process for a playbook does not validate the existence of its connectors. The playbook will import successfully, but it will fail at runtime when it attempts to execute the task that uses the missing connector. The import failure is likely due to another issue, such as a version incompatibility or a syntax error not related to the connector itself.

  5. 5

    An organization has a central FortiAnalyzer in Analyzer mode and several remote sites, each with a FortiAnalyzer in Collector mode. A new FortiGate is deployed at a remote site. Logs from the new FortiGate are visible on the local Collector but not on the central Analyzer. The Collector is configured to forward logs for all other devices in its ADOM to the Analyzer.

    What is the most likely cause of this issue?

    graph TD subgraph Central_SOC FAZ_Analyzer["FortiAnalyzer (Analyzer Mode)"] end subgraph Remote_Site FAZ_Collector["FortiAnalyzer (Collector Mode)"] FGT_Existing[FortiGate (Existing)] FGT_New["FortiGate (New)"] end FGT_Existing --> FAZ_Collector FGT_New --> FAZ_Collector FAZ_Collector -- "Forwards logs for FGT_Existing" --> FAZ_Analyzer FAZ_Collector -. "Logs NOT Forwarded for FGT_New" .-> FAZ_Analyzer

    Show answer details

    Correct answer: B

    In a Collector/Analyzer deployment, the Collector's log forwarding settings determine which logs are sent to the Analyzer. This configuration can be filtered by device, log type, or severity. The most probable reason for the issue is that the forwarding filter on the Collector was configured to include specific devices and has not been updated to include the newly added FortiGate.

  6. 6

    A SOC analyst at a manufacturing firm is investigating a performance degradation issue with their FortiAnalyzer 7.4. They suspect that a specific custom report, which runs hourly, is consuming excessive system resources. The report uses a complex custom dataset that queries logs from the past 24 hours across all 500 of their managed FortiGates. Which diagnostic command would provide the most direct insight into the resource consumption specifically related to report generation?

    Show answer details

    Correct answer: C

    The diagnose test application reportd 2 command is specifically designed to show the status of running reports, including their progress, duration, and the SQL queries being executed. This provides the most direct information to identify a long-running or resource-intensive report. diagnose sql status shows the status of the SQL database but isn't specific to the reporting daemon. diagnose fortilogd lograte shows log ingestion rates, and get system performance status provides general system metrics, not specific daemon performance.

  7. 7

    A security analyst needs to create a playbook that automatically responds to a 'Malware Detected' event. The response requires retrieving the affected user's manager from an external HR system via a REST API and then sending a notification email to both the user and their manager. Which playbook component is essential for storing and reusing the manager's email address obtained from the API call for the subsequent notification task?

    Show answer details

    Correct answer: B

    Variables are used within playbooks to store data that can be used by subsequent tasks. In this scenario, the manager's email address returned by the REST API call must be stored in a variable so that the 'Send Email' task can access it and use it as a recipient address. A trigger starts the playbook, a connector facilitates the API call, and a task is an action, but none of these inherently store and pass data between steps like a variable does.

  8. 8

    A junior analyst is tasked with creating a new incident in FortiAnalyzer based on a series of correlated, low-priority events that, when combined, indicate a potential slow-scan attack. When creating the incident manually, which two of the following fields are mandatory? (Choose two.)

    Show answer details

    Correct answer: A, C

  9. 9

    A university's IT department uses FortiAnalyzer in Collector mode on a campus-wide VM cluster, which forwards all logs to an Analyzer-mode appliance in their central data center. An analyst in the data center is unable to see logs from a newly deployed FortiGate in the engineering building. The collector is receiving logs from other devices on the same subnet. What is the most likely reason for this issue?

    Show answer details

    Correct answer: B

    In an Analyzer/Collector architecture, the Collector must be explicitly configured to forward logs for specific devices or ADOMs to the Analyzer. Even if the Collector is receiving logs from the FortiGate, if the log forwarding policy for that device/ADOM is not enabled, the logs will not reach the central Analyzer. The other options describe incorrect log flows or are less likely given the scenario.

  10. 10

    True or False: When a playbook is exported from one FortiAnalyzer and imported into another, any connectors referenced in the playbook tasks are automatically created on the destination FortiAnalyzer if they do not already exist.

    Show answer details

    Correct answer: B

    The import/export function for playbooks only includes the playbook's definition and logic. It does not include the configuration for external connectors. The administrator must manually configure any required connectors on the destination FortiAnalyzer before the imported playbook can function correctly.

Create an account to continue.