Free FCP-FAZ-AN-7-4 sample questions
Real questions from the FCP - FortiAnalyzer 7.4 Analyst practice bank, with the correct answer and an explanation for each one. No junk, no filler.
Try them in the simulator Same questions, with study, timed and flashcard modes.
Showing 10 of 20 free sample questions.
A security analyst needs to create a playbook that automatically responds to a 'Malware Detected' event. The response requires retrieving the affected user's manager from an external HR system via a REST API and then sending a notification email to both the user and their manager. Which playbook component is essential for storing and reusing the manager's email address obtained from the API call for the subsequent notification task?
A junior analyst is tasked with creating a new incident in FortiAnalyzer based on a series of correlated, low-priority events that, when combined, indicate a potential slow-scan attack. When creating the incident manually, which two of the following fields are mandatory? (Choose two.)
A university's IT department uses FortiAnalyzer in Collector mode on a campus-wide VM cluster, which forwards all logs to an Analyzer-mode appliance in their central data center. An analyst in the data center is unable to see logs from a newly deployed FortiGate in the engineering building. The collector is receiving logs from other devices on the same subnet. What is the most likely reason for this issue?
True or False: When a playbook is exported from one FortiAnalyzer and imported into another, any connectors referenced in the playbook tasks are automatically created on the destination FortiAnalyzer if they do not already exist.
A SOC manager wants to create a weekly executive summary report that shows only the top 10 most active applications and the top 5 users by bandwidth across the entire organization. The default reports show too much detail. To achieve this, the analyst must create a custom chart. Which component must be created first before the custom chart can be configured to display this specific, aggregated data?
An analyst is building a playbook to automate the initial triage of a suspected phishing email. The playbook is triggered by a FortiMail event. A key step is to extract the sender's email address and the URL from the event log to perform reputation checks. Which syntax should be used within the playbook tasks to reference these dynamic values from the triggering event?
A financial institution has a strict 90-day log retention policy for all traffic logs for compliance reasons. An administrator has confirmed that the global log retention settings are configured correctly. However, a recent audit found that traffic logs for the 'Trading_Floor' ADOM are being purged after only 30 days. Logs for all other ADOMs are retained for the full 90 days. What is the most likely cause of this discrepancy?
An analyst is investigating an incident involving a compromised user account. To determine the blast radius, they need to find every IP address the user `j.doe` has logged in from over the past 7 days. Which of the following FortiAnalyzer log view queries would be the most efficient for this task?
What is the primary function of an 'Indicator' within the FortiAnalyzer SOC module?
10 more free samples are waiting
Create a free account to unlock the whole FCP-FAZ-AN-7-4 sample bank, or get full access to all 219 practice questions in the simulator.