FCP_FAZ_AN-7.6 NSE 5 - FortiAnalyzer 7.6 Analyst Practice Questions
Prepare for FCP_FAZ_AN-7.6 with more than an answer.
- Exam fee
- $200 USD
- Time limit
- 65 minutes
- Questions on the exam
- 30-35
- Passing score
- Pass/Fail (no published numeric score) (scale Pass/Fail)
- Level
- FCP (Fortinet Certified Professional)
- Valid for
- 2 years from the date the FCP certification is achieved
Domains covered on the exam 4
- Features and Concepts20%
- Log Analysis25%
- SOC Operation and Automation30%
- Reports25%
- 1
In a FortiAnalyzer Playbook, what is the primary function of the 'Connector' element?
Show answer details
Correct answer: A
Connectors serve as the interface between the Playbook logic and external entities. They execute actions (like 'Ban IP', 'Send Email', 'Create Ticket') on connected devices (FortiGate) or third-party services.
- 2
A SOC Manager wants to see a real-time visualization of active threats mapped to their geographical origin. Which FortiView feature should be utilized?
Show answer details
Correct answer: C
The Threat Map widget in FortiView provides a geographical visualization of source and destination IPs involved in detected threats, allowing for immediate visual identification of regional attack patterns.
- 3
When configuring an Event Handler, what is the purpose of the 'Generic Text Filter' compared to specific field filters?
Show answer details
Correct answer: D
Specific field filters rely on the log parser identifying and extracting the field (e.g., 'user'). The Generic Text Filter searches the raw log content. This is essential for custom applications or unparsed log sections where the data exists but isn't normalized into a standard field.
- 4
An MSSP Administrator manages a FortiAnalyzer instance hosting multiple tenants in separate Administrative Domains (ADOMs). The administrator observes that a custom log parser configured in the 'root' ADOM is not parsing logs arriving from a FortiGate device assigned to 'Customer_A' ADOM. The FortiGate is sending logs correctly. What is the technical reason for this behavior?
Show answer details
Correct answer: C
In FortiAnalyzer, while some objects are global, custom log parsers are often ADOM-specific or need to be explicitly applied to the device/ADOM context. If the parser is defined in 'root' but the device is in 'Customer_A', the parser logic does not automatically descend unless configured globally and associated correctly. The administrator must configure or import the parser into 'Customer_A' or ensure the scope allows it.
- 5
A SOC analyst needs to search for all traffic logs where the destination port is NOT 443 and the user field contains the string 'admin'. Which search filter syntax should be used in the Log View?
Show answer details
Correct answer: B
In FortiAnalyzer search syntax: '!=' denotes 'not equal to', and '
' denotes 'contains' (partial match). Therefore, 'dstport!=443' filters out HTTPS traffic, and 'useradmin' looks for 'admin' anywhere in the user field. The 'and' operator combines them. - 6
A FortiAnalyzer administrator is designing a playbook to automatically quarantine a compromised host. The playbook fails to execute the quarantine action on the FortiGate. The administrator verifies that the 'Quarantine Host' connector is configured.
What is the most likely cause of this failure regarding the variable mapping?
Show answer details
Correct answer: A
Playbooks rely on variables passed from the trigger (Event or Incident). If the playbook is triggered by an event that lacks the specific 'srcip' field (or if the variable mapping points to a non-existent field in that log context), the connector action receives a null value and fails to execute the quarantine.
