NSE5-FAZ-7-2 Fortinet NSE 5 - FortiAnalyzer 7.2 Analyst Practice Questions
Prepare for NSE5-FAZ-7-2 with more than an answer.
Unlock the full exam and previous versions
- v1Version 1 194 questions Locked
- NSE5-FAZ-7-2Legacy Fortinet NSE 5 - FortiAnalyzer 7.2 Analyst 217 questions Current
- Level
- Professional (NSE 5)
- Valid for
- 2 years
Domains covered on the exam 5
- Features and Concepts
- Logging
- SOC (Security Operations Center)
- Reports
- Playbooks
- 1
An analyst uses Chart Builder from the Log View to visualize traffic to a specific country. After creating the chart, they want to reuse it in a custom weekly report. What is the correct procedure to make the chart available in the Report Editor?
Show answer details
Correct answer: D
Charts created on-the-fly using the Chart Builder in Log View are temporary. To make them permanent and reusable in reports, the analyst must explicitly save the chart to the Chart Library. Once saved, it becomes available in the Report Editor's chart list and can be dragged and dropped into any custom report.
- 2
Which two log types are stored in the Analytics (SQL) database and are available for FortiView, Reports, and event management? (Choose two.)
Show answer details
Correct answer: A, C
FortiAnalyzer primarily stores logs meant for analysis (Traffic, UTM/Security, Event, etc.) in its indexed SQL database. These are considered 'Analytics logs'. Raw archive logs are typically compressed and stored as flat files for long-term retention and compliance, and are not directly available for real-time analytics features like FortiView.
- 3
A FortiAnalyzer playbook needs to use the destination IP address from a triggering log in multiple subsequent tasks. What is the correct syntax to reference this value as a variable within a playbook task?
Show answer details
Correct answer: A
FortiAnalyzer playbooks use a double-percent sign syntax (%%...%%) to reference variables derived from log fields or the outputs of previous tasks. To reference the destination IP field (
dstip) from the trigger log, the correct syntax is%%dstip%%. - 4
An organization has deployed a FortiAnalyzer in Collector mode and another in Analyzer mode. What is the primary function of the FortiAnalyzer operating in Collector mode?
Show answer details
Correct answer: B
In an Analyzer-Collector architecture, the Collector's main role is to act as a centralized log aggregation point. It receives logs from various devices, archives them for long-term storage, and forwards them to the Analyzer. The resource-intensive tasks like indexing logs into the SQL database, running analytics, and generating reports are offloaded to the Analyzer.
- 5
A playbook is designed to enrich an incident by querying an internal asset database via an API. The playbook flow is shown below. The API query in Task 2 requires the
srcipfrom the trigger. The playbook fails. What is the most likely reason for the failure?flowchart TD A[Trigger: IPS Event] --> B{Task 1: Create Incident}; B --> C{Task 2: HTTP GET to Asset DB API}; C --> D[Task 3: Update Incident with Asset Info];Show answer details
Correct answer: C
In FortiAnalyzer playbooks, variables from the initial trigger (like
%%srcip%%) are directly available to the first level of tasks connected to that trigger. For a variable to be used in subsequent, downstream tasks (like Task 2, which follows Task 1), it must be explicitly passed through or returned as an output by the intermediate tasks. Since Task 1 ('Create Incident') does not pass thesrcipvariable along, Task 2 cannot access it, causing the API query to fail. - 6
A SOC analyst at a financial services company is investigating a high-severity event related to multiple failed login attempts from a suspicious IP address. The analyst needs to quickly gather all associated traffic logs, endpoint logs, and application control logs related to this IP for the last 24 hours. Which FortiAnalyzer feature provides the most efficient, integrated view for this type of cross-log-type investigation?
Show answer details
Correct answer: C
The global search bar in the 'Log View' tab is the most efficient tool for this task. It allows an analyst to search for a specific value (like an IP address) across all indexed log types simultaneously within the selected time frame. This provides a quick, correlated view of all activities associated with the IP without the need to build reports or manually browse individual log files.
- 7
A security analyst is building a custom event handler to detect potential data exfiltration. The goal is to trigger an event if any single user uploads more than 100MB of data to any cloud storage application within a 5-minute window. Which three settings are required in the event handler configuration to achieve this specific logic? (Choose three.)
Show answer details
Correct answer: A, B, D
To meet the requirement, the event handler must: 1) Filter for logs related to cloud storage applications. 2) Group the logs by user to track individual activity. 3) Use an aggregated condition to sum the uploaded bytes ('sentbyte' from the perspective of the client) and trigger when it exceeds 100MB (104,857,600 bytes) within the specified 5-minute (300 seconds) window.
- 8
A SOC manager wants to create a weekly 'Top 10 Riskiest Users' report. This report should be based on a custom risk score calculated from the number of high-severity security events (IPS, Antivirus, Web Filter) associated with each user. To implement this, an analyst must first create a custom dataset. Which SQL query function is essential for counting the events associated with each user?
Show answer details
Correct answer: D
The
COUNT()function is the standard SQL aggregate function used to count the number of rows that match a specified condition. In this scenario, the analyst would useCOUNT()in conjunction withGROUP BY userto get the total number of high-severity events for each user. - 9
True or False: When a playbook is triggered by an event handler, it can only use log fields from the single log that initiated the event.
Show answer details
Correct answer: B
This statement is false. When an event handler triggers a playbook, it passes a JSON object containing details of the event. If the event was generated from an aggregation of multiple logs (e.g., '5 failed logins in 1 minute'), the playbook trigger can access the fields from all the logs that contributed to that aggregated event, not just the first or last one.
- 10
A SOC analyst has created a playbook to automatically create a ServiceNow ticket when a 'Compromised Host' event is generated. After deploying the playbook, new 'Compromised Host' events are visible in FortiAnalyzer, but no tickets are being created in ServiceNow. The Playbook Monitor shows the playbook is not being triggered. What is the most likely cause of this issue?
Show answer details
Correct answer: B
A playbook does not automatically run when an event is generated. It must be explicitly linked to an event handler. The analyst must edit the 'Compromised Host' event handler and, in the notification settings, enable the 'Execute Playbook' option and select the correct playbook. Since the Playbook Monitor shows no trigger activity, it indicates the link between the event handler and the playbook is missing.
