For proper log correlation between the logging devices and FortiAnalyzer, FortiAnalyzer and all registered devices should:
A. Use DNS
B. Use host name resolution
C. Use an NTP server
D. Use real-time forwarding
What must you configure on FortiAnalyzer to upload a Fortianalyzer report to a supported external server? (Choose two.)
A. Report scheduling
B. Output profile
C. SFTP, FTP, or SCP server
D. Mail server
View the exhibit.
What does the data point at 14:35 tell you?
A. The sqlplugind daemon is ahead in indexing by one log
B. FortiAnalyzer is indexing logs faster than logs are being received
C. FortiAnalyzer is dropping logs
D. FortiAnalyzer has temporarily stopped receiving logs so older logs can be indexed
What is the purpose of employing RAID with FortiAnalyzer?
A. To provide data separation between ADOMs
B. To separate analytical and archive data
C. To back up your logs
D. To introduce redundancy to your log data
On FortiAnalyzer, what is a wildcard administrator account?
A. An account that permits access to members of a LDAP group
B. An account that allows guest access with read-only privileges
C. An account that requires two-factor authentication
D. An account that validates against any user account on a FortiAuthenticator
FortiAnalyzer uses the Optimized Fabric Transfer Protocol (OFTP) over SSL for what purpose?
A. To prevent log modification during backup
B. To send an identical set of logs to a second logging server
C. To encrypt log communication between devices
D. To upload logs to a SFTP server
In order for FortiAnalyzer to collect logs from a FortiGate device, what configuration is required? (Choose two.)
A. ADOMs must be enabled
B. Log encryption must be enabled
C. FortiGate must be registered with FortiAnalyzer
D. Remote logging must be enabled on FortiGate
What can the CLI command # diagnose test application oftpd 3 help you to determine?
A. What logs, if any, are reaching FortiAnalyzer
B. What ADOMs are enabled and configured
C. What devices and IP addresses are connecting to FortiAnalyzer
D. What devices are registered and unregistered
If you upgrade your FortiAnalyzer firmware, what report elements can be affected?
A. Report settings
B. Report scheduling
C. Output profiles
D. Custom datasets
Logs are being deleted from one of your ADOMs earlier than the configured setting for archiving in your data policy. What is the most likely problem?
A. Logs in that ADOM are being forwarded in real-time to another FortiAnalyzer device
B. CPU resources are too high
C. The ADOM disk quota is set too low based on log rates
D. The total disk space is insufficient and you need to add other disk