更新された2025年02月20日検証済み!FCP_FAZ_AD-7.4問題集と解答で100%合格できる
2025年最新のの問題FCP_FAZ_AD-7.4問題集を試そう!更新されたFortinet試験合格させます
質問 # 50
Which statement is true when you are upgrading the firmware on an HA cluster made up of throe FortiAnalyzer devices?
- A. Enabling uninterruptible-upgrade prevents normal operations from being interrupted during the upgrade.
- B. First, upgrade the secondary devices, and then upgrade the primary device.
- C. All FortiAnalyzer devices will be upgraded at the same time.
- D. You can perform the firmware upgrade using only a console connection.
正解:B
解説:
In an HA cluster, the firmware upgrade process involves upgrading the secondary devices first. This approach ensures that the primary device can continue to handle traffic and maintain the operational stability of the network while the secondary devices are being upgraded. Once the secondary devices have successfully upgraded their firmware and are operational, the primary device can then be upgraded. This method minimizes downtime and maintains network integrity during the upgrade process.
When upgrading firmware in a High Availability (HA) cluster of FortiAnalyzer units, the recommended practice is to first upgrade the secondary devices before upgrading the primary device. This approach ensures that the primary device, which coordinates the cluster's operations, remains functional for as long as possible, minimizing the impact on log collection and analysis. Once the secondary devices are successfully upgraded and operational, the primary device can be upgraded, ensuring a smooth transition and maintaining continuous operation of the cluster.
Reference: FortiAnalyzer 7.2 Administrator Guide - "System Administration" and "High Availability" sections.
質問 # 51
Which two of the following must you configure on FortiAnalyzer to email a FortiAnalyzer report externally?
(Choose two.)
- A. SFTP server
- B. Mail server
- C. Report scheduling
- D. Output profile
正解:B、D
質問 # 52
Which two statements are true regarding log fetching on FortiAnalyzer? (Choose two.)
- A. Log fetching allows the administrator to fetch analytics logs from another FortiAnalyzer for redundancy.
- B. Log fetching allows the administrator to run queries and reports against historical data by retrieving archived logs from one FortiAnalyzer device and sending them to another FortiAnalyzer device.
- C. Log fetching can be done only on two FortiAnalyzer devices that are running the same firmware version.
- D. A FortiAnalyzer device can perform either the fetch server or client role, and it can perform two roles at the same time with the same FortiAnalyzer devices at the other end.
正解:B、C
解説:
Reference:
Using FortiAnalyzer, you can enable log fetching. This allows FortiAnalyzer to fetch the archived logs of specified devices from another FortiAnalyzer, which you can then run queries or reports on for forensic analysis.
The FortiAnalyzer device that fetches logs operates as the fetch client, and the other FortiAnalyzer device that sends logs operates as the fetch server. Log fetching can happen only between two FortiAnalyzer devices, and both of them must be running the same firmware version. A FortiAnalyzer device can perform either the fetch server or client role, and it can perform two roles at the same time with different FortiAnalyzer devices at the other end.
FortiAnalyzer_7.0_Study_Guide-Online pag. 168
質問 # 53
Which two parameters are used to calculate the Total Quota value available on FortiAnalyzer? (Choose two.)
- A. Used storage
- B. Total system storage
- C. Reserved space
- D. Retention policy
正解:B、C
解説:
The Total Quota is derived from the total system storage minus any reserved space allocated for system use, such as databases, system files, or reserved space for log retention policies. Used storage and retention policies do not directly impact the calculation of the quota available, though they can influence overall space utilization.
質問 # 54
On FortiAnalyzer, what is a wildcard administrator account?
- A. An account that allows guest access with read-only privileges
- B. An account that permits access to members of an LDAP group
- C. An account that requires two-factor authentication
- D. An account that validates against any user account on a FortiAuthenticator
正解:B
解説:
https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/747268/configuring-wildcard-admin-accounts
質問 # 55
Refer to the exhibit.
Which statement is correct regarding the event displayed?
- A. The risk source is isolated.
- B. The security event risk is considered open.
- C. The security risk was blocked or dropped.
- D. An incident was created from this event.
正解:B
解説:
Events in FortiAnalyzer will be in one of four statuses. The current status will determine if more actions need to be taken by the security team or not.
The possible statuses are:
Unhandled: The security event risk is not mitigated or contained, so it is considered open.
Contained: The risk source is isolated.
Mitigated: The security risk is mitigated by being blocked or dropped.
(Blank): Other scenarios.
FortiAnalyzer_7.0_Study_Guide-Online pag. 206
質問 # 56
Which two statements are true regarding high availability (HA) on FortiAnalyzer? (Choose two.)
- A. FortiAnalyzer HA supports synchronization of logs as well as some system and configuration settings.
- B. FortiAnalyzer HA implementation is supported by many public cloud infrastructures such as AWS, Microsoft Azure, and Google Cloud.
- C. All devices in a FortiAnalyzer HA cluster must run in the same operation mode: analyzer or collector.
- D. FortiAnalyzer HA can function without VRRP. and VRRP is required only if you have more than two FortiAnalyzer devices in a cluster.
正解:A、C
解説:
Reference:
FortiAnalyzer HA implementation works only in networks where Virtual Router Redundancy Protocol (VRRP) is permitted. Therefore it may not be supported by some public cloud infrastructures.
質問 # 57
FortiAnalyzer reports are dropping analytical data from 15 days ago, even though the data policy setting for analytics logs is 60 days.
What is the most likely problem?
- A. Quota enforcement is acting on analytical data before a report is complete
- B. Disk utilization for archive logs is set for 15 days
- C. Logs are rolling before the report is run
- D. CPU resources are too high
正解:C
質問 # 58
In the FortiAnalyzer FortiView, source and destination IP addresses from FortiGate devices are not resolving to a hostname.
How can you resolve the source and destination IP addresses, without introducing any additional performance impact to FortiAnalyzer?
- A. Resolve IP addresses on FortiGate
- B. Resolve IP addresses on a per-ADOM basis to reduce delay on FortiView while IPs resolve
- C. Configure # set resolve-ip enable in the system FortiView settings
- D. Configure local DNS servers on FortiAnalyzer
正解:A
解説:
https://packetplant.com/fortigate-and-fortianalyzer-resolve-source-and-destination-ip/
"As a best practice, it is recommended to resolve IPs on the FortiGate end. This is because you get both source and destination, and it offloads the work from FortiAnalyzer. On FortiAnalyzer, this IP resolution does destination IPs only"
質問 # 59
How does FortiAnalyzer retrieve specific log data from the database?
- A. SQL EXTRACT statement
- B. SQL FROM statement
- C. SQL SELECT statement
- D. SQL GET statement
正解:B
解説:
https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/137bb60e-ff37-11e8-8524-f8bc1258b856/fortianalyzer-fortigate-sql-technote-40-mr2.pdf
質問 # 60
Refer to the exhibit.
Which two statements are true regarding enabling auto-cache on FortiAnalyzer? (Choose two.)
- A. Enabling auto-cache reduces report generation time for reports that require a long time to assemble datasets.
- B. This feature is automatically enabled for scheduled reports.
- C. Report size will be optimized to conserve disk space on FortiAnalyzer.
- D. Reports will be cached in the memory.
正解:A、B
解説:
"Enable auto-cache in the report settings to boost the reporting performance and reduce report generation time. Scheduled reports have auto-cache enabled already." FortiAnalyzer_7.0_Study_Guide-Online page 306
質問 # 61
Which two settings must you configure on FortiAnalyzer to allow non-local administrators to authenticate on FortiAnalyzer with any user account in a single LDAP group? (Choose two.)
- A. One or more remote LDAP servers
- B. A local wildcard administrator account
- C. LDAP servers IP addresses added as trusted hosts
- D. An administrator group
正解:A、D
解説:
To allow non-local administrators to authenticate on FortiAnalyzer with any user account in a single LDAP group, you must configure one or more remote LDAP servers and an administrator group. First, you configure the LDAP server(s) by specifying the server name, IP, and other details such as the Common Name Identifier and Distinguished Name. Then, you add the LDAP server to a user group.
Finally, you create an administrator account that uses this user group for authentication, allowing any user from the specified LDAP group to authenticate.
Reference: FortiAnalyzer 7.2 Administrator Guide, "Configuring remote authentication for administrators using LDAP" section.
質問 # 62
Refer to the exhibit.
Which image corresponds to the packet capture shown in the exhibit?
- A.

- B.

- C.

- D.

正解:D
解説:
Chosen image shows the device Remote-FortiGate with the IP 10.200.3.1 and a connection status of "Connection Up," which is consistent with the packet capture details showing active communication between the client and server.
質問 # 63
An administrator has configured the following settings:
config system fortiview settings
set resolve-ip enable
end
What is the significance of executing this command?
- A. You must configure local DNS servers on FortiGate for this command to resolve IP addresses on Forti Analyzer.
- B. It resolves the destination IP address to a hostname in FortiView on FortiAnalyzer.
- C. It resolves the source and destination IP addresses to a hostname in FortiView on FortiAnalyzer.
- D. Use this command only if the source IP addresses are not resolved on FortiGate.
正解:D
質問 # 64
An administrator has configured the following settings:
config system global
set log-checksum md5-auth
end
What is the significance of executing this command?
- A. This command encrypts log transfer between FortiAnalyzer and other devices.
- B. This command records the log file MD5 hash value.
- C. This command records the log file MD5 hash value and authentication code.
- D. This command records passwords in log files and encrypts them.
正解:C
質問 # 65
Which two statements are true regarding ADOM modes? (Choose two.)
- A. In normal mode, the disk quota of the ADOM is fixed and cannot be modified, but in advance mode, the disk quota of the ADOM is flexible because new devices are added to the ADOM.
- B. Normal mode is the default ADOM mode.
- C. You can only change ADOM modes through CLI.
- D. In an advanced mode ADOM. you can assign FortiGate VDOMs from a single FortiGate device to multiple FortiAnalyzer ADOMs.
正解:B、D
質問 # 66
......
最新のFCP_FAZ_AD-7.4試験問題集でFortinetトレーニング試験には:https://www.goshiken.com/Fortinet/FCP_FAZ_AD-7.4-mondaishu.html
合格できるFortinet FCP_FAZ_AD-7.4のPDF問題集で最近更新された173問あります:https://drive.google.com/open?id=1b-zOhjutiv-jBwf8wf2aSjkvsgNfR0LS