FCP_FAZ_AN-7.6 PDF Dumps 2026 Exam Questions with Practice Test
Dumps for Free FCP_FAZ_AN-7.6 Practice Exam Questions
NEW QUESTION # 34
When managing incidents on FortiAnalyzer, which fact must an analyst be aware of?
- A. Indicators found on the Incidents page can be enriched only from the Indicators page.
- B. A playbook can be run from the Incidents page.
- C. Incidents must be acknowledged before they can be analyzed.
- D. The status of the incident is always linked to the status of the attached event.
Answer: B
Explanation:
FortiAnalyzer allows analysts to run playbooks directly from the Incidents page, enabling immediate automated response actions on the selected incident.
NEW QUESTION # 35
Refer to the exhibit. Which two observations can you make after reviewing this log entry?
(Choose two.)
- A. This log is in a raw log format.
- B. This is the original log that FortiAnalyzer received from FortiGate.
- C. This is a formatted view of the log.
- D. This is a normalized log.
Answer: A,B
Explanation:
The log line is displayed as a single, unparsed key-value string exactly as it was received from FortiGate, indicating it is the raw log format and represents the original FortiGate log before any FortiAnalyzer normalization or formatting is applied.
NEW QUESTION # 36
Which statement about sending notifications with incident update is true?
- A. If you use multiple fabric connectors, all connectors must have the same settings.
- B. Notifications can be sent only when an incident is updated or deleted.
- C. Notifications can be sent only by email.
- D. You can send notifications to multiple external platforms.
Answer: D
Explanation:
Exact Extract: Study Guide p.107: FortiAnalyzer can send incident notifications to external platforms using Fabric connectors; more than one connector can be added.
Technical Deep Dive: The correct answer is A. Incident update notifications are not restricted to email.
FortiAnalyzer can use configured Fabric connectors to notify external collaboration or response platforms, and each connector can be configured for the incident activities that should trigger a notification. Option B is too narrow because email is only one possible delivery model. Option C is wrong because multiple connectors do not have to share identical settings. Option D is wrong because notification triggers are configurable for different incident activities, not only update or delete events.
NEW QUESTION # 37
Why must you wait for several minutes before you run a playbook that you just created?
- A. FortiAnalyzer needs that time to back up the current playbooks.
- B. FortiAnalyzer needs that time to ensure there are no other playbooks running.
- C. FortiAnalyzer needs that time to debug the new playbook.
- D. FortiAnalyzer needs that time to parse the new playbook.
Answer: D
Explanation:
When a new playbook is created on FortiAnalyzer, the system requires some time to parse and validate the playbook before it can be executed. Parsing involves checking the playbook's structure, ensuring that all syntax and logic are correct, and preparing the playbook for execution within FortiAnalyzer's automation engine. This initial parsing step is necessary for FortiAnalyzer to load the playbook into its operational environment correctly.
NEW QUESTION # 38
You created a playbook on FortiAnalyzer that uses a FortiOS connector.
When you configure FortiGate, which type of trigger must you use so that the actions in an automation stitch are available in the FortiOS connector?
- A. Incoming webhook
- B. IP ban
- C. Fabric Connector event
- D. FortiAnalyzer Event Handler
Answer: A
Explanation:
FortiOS connector will be listed as soon as the first FortiGate is added to FortiAnalyzer.
However, in order to see the actions related to that FortiOS connector, you must enable an automation rule using the Incoming Webhook Call trigger on the FortiGate side.
NEW QUESTION # 39
Which statement about sending notifications with incident updates is true?
- A. Notifications can be sent only when an incident is created or deleted.
- B. You must configure an output profile to send notifications by email.
- C. Each incident can send notifications to multiple external platforms.
- D. All connectors used for sending notifications must share the same notification settings.
Answer: C
Explanation:
FortiAnalyzer allows incident notifications to be sent through multiple connectors and external platforms such as email, Slack, or other integrated systems. A single incident can trigger notifications to multiple configured destinations based on the defined automation or notification settings.
NEW QUESTION # 40
Which statement about automation connectors in FortiAnalyzer is true?
- A. The local connector becomes available after you connectors are displayed.
- B. The local connector becomes available after you configured any external connector.
- C. An ADOM with the Fabric type comes with multiple connectors configured.
- D. The actions available with FortiOS connectors are determined by automation rules configured on FortiGate.
Answer: D
Explanation:
For example, the FortiOS connector will be listed as soon as the first FortiGate device is added to FortiAnalyzer. However, in order to see the actions related to that FortiOS connector, you must enable an automation rule using the Incoming Webhook Call trigger on the FortiGate side.
NEW QUESTION # 41
Which statement about sending notifications with incident update is true?
- A. If you use multiple fabric connectors, all connectors must have the same settings.
- B. Notifications can be sent only when an incident is updated or deleted.
- C. Notifications can be sent only by email.
- D. You can send notifications to multiple external platforms.
Answer: D
Explanation:
In FortiOS and FortiAnalyzer, incident notifications can be sent to multiple external platforms, not limited to a single method such as email. Fortinet's security fabric and integration capabilities allow notifications to be sent through various fabric connectors and third-party integrations. This flexibility is designed to ensure that incident updates reach relevant personnel or systems using preferred communication channels, such as email, Syslog, SNMP, or integration with SIEM platforms.
Let's review each answer option for clarity:
* Option A: You can send notifications to multiple external platforms
* This is correct. Fortinet's notification system is capable of sending updates to multiple platforms, thanks to its support for fabric connectors and external integrations. This includes options such as email, Syslog, SNMP, and others based on configured connectors.
* Option B: Notifications can be sent only by email
* This is incorrect. Although email is a common method, FortiOS and FortiAnalyzer support multiple notification methods through various connectors, allowing notifications to be directed to different platforms as per the organization's setup.
* Option C: If you use multiple fabric connectors, all connectors must have the same settings
* This is incorrect. Each fabric connector can have its unique configuration, allowing different connectors to be tailored for specific notification and integration requirements.
* Option D: Notifications can be sent only when an incident is updated or deleted
* This is incorrect. Notifications can be sent upon the creation of incidents, as well as upon updates or deletion, depending on the configuration.
* According to FortiOS and FortiAnalyzer 7.4.1 documentation, notifications for incidents can be configured across various platforms by using multiple connectors, and they are not limited to email alone. This capability is part of the Fortinet Security Fabric, allowing for a broad range of integrations with external systems and platforms for effective incident response.
NEW QUESTION # 42
A playbook contains five tasks in total. An administrator runs the playbook and four out of five tasks finish successfully, but one task fails.
What will be the status of the playbook after it is run?
- A. Success
- B. Upstream_failed
- C. Attention required
- D. Failed
Answer: C
Explanation:
In FortiAnalyzer, when a playbook is run, each task's status impacts the overall playbook status.
Here's what happens based on task outcomes:
Status When All Tasks Succeed:
If all tasks finish successfully, the playbook status is marked as Success.
Status When Some Tasks Fail:
If one or more tasks in the playbook fail, but others succeed, the playbook status generally changes to Attention required. This status indicates that the playbook completed execution but requires review due to one or more tasks failing.
This is different from a complete Failed status, which is used if the playbook cannot proceed due to a critical error in an early task, often one that upstream tasks depend on.
NEW QUESTION # 43
What happens when the indicator of compromise (IOC) engine on FortiAnalyzer finds web logs that match blacklisted IP addresses?
- A. FortiAnalyzer flags the associated host for further analysis.
- B. A new infected entry is added for the corresponding endpoint under Compromised Hosts.
- C. The detection engine classifies those logs as Suspicious.
- D. The endpoint is marked as Compromised and, optionally, can be put in quarantine.
Answer: B
NEW QUESTION # 44
What is the purpose of playbook trigger variables?
- A. To use information from the trigger to filter the action in a task
- B. To provide the trigger information to make the playbook start running
- C. To display statistics about the playbook runtime
- D. To store the start the times of playbooks with On_Schedule triggers
Answer: A
NEW QUESTION # 45
Refer to the exhibit with partial output:
Your colleague exported a playbook and has sent it to you for review. You open the file in a text editor and observer the output as shown in the exhibit.
Which statement about the export is true?
- A. The export data type is zipped.
- B. The option to include the connector was not selected.
- C. Your colleague put a password on the export.
- D. The playbook is misconfigured.
Answer: A
Explanation:
Exact Extract: Study Guide p.217: zipped/base64 encoded JSON is one of the playbook export data types.
Technical Deep Dive: The correct answer is A. The exhibit shows encoded data rather than readable plain-text JSON, which indicates the playbook was exported in the zipped/base64 encoded format. That does not mean the playbook is misconfigured. It also does not prove connectors were excluded; connector inclusion is a separate export option. There is no indication of password protection. The key visual clue is that the export contains encoded data plus integrity information instead of a readable JSON playbook structure.
NEW QUESTION # 46
As part of your analysis, you discover that a Medium severity level incident is fully remediated.
You change the incident status to Closed:Remediated.
Which statement about your update is true?
- A. The incident dashboard will be updated.
- B. The incident severity will be lowered.
- C. The corresponding event will be marked as Mitigated.
- D. The incident can no longer be deleted.
Answer: A
NEW QUESTION # 47
Refer to the exhibit.
What can you conclude about the output?
- A. The output is not ADOM specific.
- B. The low indexing values require investigation.
- C. There are more event logs than traffic logs.
- D. The log rate higher than the message rate is not normal.
Answer: D
NEW QUESTION # 48
Which statement about exporting items in Report Definitions is true?
- A. Datasets can be exported.
- B. Chart exports contain associated datasets.
- C. Template exports contain associated charts and datasets.
- D. Templates can be exported.
Answer: C
NEW QUESTION # 49
Which SQL query is in the correct order to query to database in the FortiAnalyzer?
- A. SELECT devid FROM $log GROUP BY devid WHERE `user',,' users1'
- B. SELECT devid FROM $log WHERE `user'=' GROUP BY devid
- C. SELCT devid WHERE 'user'-` USER1' FROM $log GROUP By devid
- D. SELECT FROM $log WHERE devid `user',, USER1' GROUP BY devid
Answer: B
Explanation:
In FortiAnalyzer's SQL query syntax, the typical order for querying the database follows the standard SQL format, which is:
SELECT <column(s)> FROM <table> WHERE <condition(s)> GROUP BY <column(s)> Option D correctly follows this structure:
SELECT devid FROM $log: This specifies that the query is selecting the devid column from the
$log table.
WHERE 'user' = ': This part of the query is intended to filter results based on a condition involving the user column. Although there appears to be a minor typographical issue (possibly missing the user value after =), it structurally adheres to the correct SQL order. GROUP BY devid: This groups the results by devid, which is correctly positioned at the end of the query.
NEW QUESTION # 50
Which statement describes archive logs on FortiAnalyzer?
- A. Logs that are indexed and stored in the SQL database
- B. Logs compressed and saved in files with the .gz extension
- C. Logs that are parsed and normalized by FortiAnalyzer and available in the log view
- D. Logs received from other FortiAnalyzer devices
Answer: B
Explanation:
Archive logs on FortiAnalyzer are logs that have been stored in files and, once a log file reaches its size limit, it is "rolled" and compressed, becoming offline logs. These compressed archive logs are saved as files, typically with the .gz extension, and are not immediately viewable or reportable in FortiView, Log View, or Reports panes.
https://docs.fortinet.com/document/fortianalyzer/7.6.3/administration-guide/761825/analytics-and- archive-logs
NEW QUESTION # 51
Refer to the exhibit. Laptop1 is used by several administrators to manage FortiAnalyzer. You want to configure a generic text filter that matches all login attempts to the web interface generated by any user other than "admin", and coming from Laptop1.
Which filter will achieve the desired result?
- A. Operation-login & srcip== 10.1.1.100 and dstip==10.1.1.1.210 and user==admin
- B. Operation-login & performed_on==''GU (10.1.1.120)' and user!=admin
- C. Operation-login & dstip==10.1.1.210 and user!-admin
- D. Operation-login & performed_on==''GUI(10.1.1.100)' and user!=admin
Answer: D
Explanation:
On there the task was to create a filter for failed logins from any other location but the local computer:
"Add the text performed_on!~10.0.1.10.
This includes any attempts coming from devices with an IP address that is not the one configured on the Local-Client computer."
NEW QUESTION # 52
What is the purpose of using data selectors when configuring event handlers?
- A. They download new filters can be used in event handlers.
- B. They apply their filter criteria to the entire event handler so that you don't have to configure the same criteria in the individual rules.
- C. They filter the types of logs that FortiAnalyzer can accept from registered devices.
- D. They are common filters that can be applied simultaneously to all event handlers.
Answer: B
Explanation:
When configuring event handlers on FortiAnalyzer, data selectors act as global filter criteria.
These filters are applied at the event handler level, allowing all rules within that handler to inherit the same conditions. This avoids the need to repeatedly configure identical filters for each individual rule.
NEW QUESTION # 53
Which statement correctly describes one difference between templates and reports?
- A. Reports can be moved between ADOMs but templates cannot.
- B. Reports support macros but templates do not.
- C. Templates do not include advanced report settings, but reports do.
- D. Templates can be cloned, but reports cannot be cloned.
Answer: C
Explanation:
Templates define the layout and content structure of a report but do not include advanced report settings such as scheduling, output format, or delivery options. These advanced configuration settings are available only when creating and managing actual reports derived from templates.
NEW QUESTION # 54
Refer to Exhibit:
Client-1 is trying to access the internet for web browsing.
All FortiGate devices in the topology are part of a Security Fabric with logging to FortiAnalyzer configured.
All firewall policies have logging enabled. All web filter profiles are configured to log only violations.
Which statement about the logging behavior for this specific traffic flow is true?
- A. Only FGT-B will create traffic logs.
- B. Only FGT-A will create web filter logs if it detects a violation.
- C. FGT B will create traffic logs and will create web filter logs if it detects a violation.
- D. FGT-B will see the MAC address of FGT-A as the destination and notifies FGT-A to log this flow.
Answer: B
Explanation:
The study guide explains that in a Security Fabric, traffic logging is not duplicated across FortiGates for the same session: "Traffic logging for a session ... is always carried out by the first FortiGate that handled it" and if a FortiGate receives traffic from a peer FortiGate MAC, "it does not generate a new traffic log for that session." For UTM (web filtering) logs, the study guide states: "When configured, upstream devices complete UTM logging." In the illustrated example, it further clarifies the role split: "All traffic from Client-1 is first received by FGT-B, which creates traffic logs for the initial session... [then] forwarded to FGT-A... [and] FGT-A
... applies web filtering ... and generates the relevant UTM logs as necessary." Because web filter profiles are configured to log only violations, web filter (UTM) logs will be generated only when a violation is detected-and per the study guide behavior, that UTM logging is done by the upstream FortiGate (FGT-A). Therefore, only FGT-A will create web filter logs if it detects a violation (Option D).
NEW QUESTION # 55
What are two effects of enabling auto-cache in a FortiAnalyzer report? (Choose two.)
- A. The hcache data is updated automatically when new logs are received.
- B. The size of newly generated reports is optimized to conserve disk space.
- C. The report generation time is reduced.
- D. FortiAnalyzer local cache is used to store generated reports.
Answer: A,C
Explanation:
To boost the report performance and reduce report generation time, you can enable auto-cache in the settings of the report. In this case, the hcache is automatically updated when new logs come in and new log tables are generated.
NEW QUESTION # 56
After generating a report, you notice the information you where expecting to see is not included in it.
However, you confirm that the logs are there.
- A. Check the time frame covered by the report.
- B. Test the dataset
- C. Disable auto-cache.
- D. Increase the report utilization quota.
Answer: A,B
Explanation:
When a generated report does not contain the expected information even though the logs are confirmed to be present, it typically indicates an issue with the report's configuration. There are a few common reasons this might happen:
* Option A - Check the Time Frame Covered by the Report:
* Reports are generated based on a specific time frame. If the report's time frame does not cover the period when the relevant logs were collected, those logs won't appear in the report output.
Verifying and adjusting the time frame is essential to ensure the report includes all relevant data.
* Conclusion: Correct.
* Option B - Disable Auto-Cache:
* Auto-cache is designed to improve report generation speed by using cached data. Disabling auto- cache would typically only be relevant if the report is pulling outdated data from cache, but it doesn't directly affect whether specific logs are included in a report.
* Conclusion: Incorrect.
* Option C - Increase the Report Utilization Quota:
* The report utilization quota is related to the resource limits for generating reports. It does not directly influence whether certain data appears in a report. Increasing this quota would help only if there are resource issues preventing the report from completing, not if specific logs are missing from the report.
* Conclusion: Incorrect.
* Option D - Test the Dataset:
* Datasets determine which logs and data fields are pulled into the report. If a dataset is configured incorrectly or does not include the required log fields, it could lead to missing information.
Testing the dataset allows you to verify that it's correctly configured and pulling the expected data.
* Conclusion: Correct.
Conclusion:
* Correct Answer: A. Check the time frame covered by the report and D. Test the dataset.
* These steps directly address the issues that could lead to missing information in a report when logs are available but not displayed.
References:
FortiAnalyzer 7.4.1 documentation on report generation settings, time frames, and dataset configuration for accurate report results.
NEW QUESTION # 57
......
Fortinet FCP_FAZ_AN-7.6 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
Check your preparation for Fortinet FCP_FAZ_AN-7.6 On-Demand Exam: https://freecert.test4sure.com/FCP_FAZ_AN-7.6-exam-materials.html