Fortinet NSE 5 Practice Exam Questions and Answers – Part 1/2

Practice for the NSE 5 – FortiAnalyzer 7.6 Analyst exam with 14 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: You find that as part of your role as an analyst, you frequently search Log View using the same parameters. Instead of d. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the NSE 5 – FortiAnalyzer 7.6 Analyst practice test →

What you will practice

  • You find that as part of your role as an analyst, you frequently search Log View using the same parameters. I…
  • Which statement describes archive logs on FortiAnalyzer?
  • Which statement about the FortiSOAR management extension is correct?
  • Why must you wait for several minutes before you run a playbook that you just created?
  • What are two effects of enabling auto-cache in a FortiAnalyzer report? (Choose two.)
  • You need to move reports between two ADOMs. Which two statements are true? (Choose two.)

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. You find that as part of your role as an analyst, you frequently search Log View using the same parameters. Instead of defining your search filters repeatedly, what can you do to save time?

Answer: B. B. Configure a custom view.

Creating a custom view allows you to save specific search filters and configurations for quick access. This prevents analysts from having to recreate complex queries manually. Dashboards and data selectors are for visual summaries, not saving search parameters.

Q2. Which statement describes archive logs on FortiAnalyzer?

Answer: C. C. Logs compressed and saved in files with the .gz extension

Archive logs are older records compressed and saved locally with the dot gz file extension. They are moved out of the active SQL database to save disk space, meaning they cannot be searched immediately in FortiView without restoration.

Q3. Which statement about the FortiSOAR management extension is correct?

Answer: B. B. It runs as a docker container on FortiAnalyzer.

The FortiSOAR management extension operates seamlessly as a docker container hosted directly on FortiAnalyzer. This integration provides lightweight orchestration without requiring a separate virtual machine. It functions independently of FortiManager and usually offers a limited trial.

Q4. Why must you wait for several minutes before you run a playbook that you just created?

Answer: A. A. FortiAnalyzer needs that time to parse the new playbook.

FortiAnalyzer needs time to parse and validate a newly created playbook to ensure its syntax and logic are correct before execution. Debugging is a manual administrator process, not an automated step that happens upon playbook creation.

Q5. What are two effects of enabling auto-cache in a FortiAnalyzer report? (Choose two.)

Answer: A,B. A. The generation time for reports is decreased. || B. When new logs are received, the hard-cache data is updated automatically.

Enabling auto-cache decreases report generation time by storing pre-generated data and automatically updates that hard-cache data when new logs are received. Auto-cache focuses on generation speed rather than conserving disk space or simply storing final reports.

Q6. You need to move reports between two ADOMs. Which two statements are true? (Choose two.)

Answer: B,C. B. All charts and datasets associated with the report will be imported together. || C. The ADOMs must be compatible types.

The correct answers are B and C because report dependencies move automatically and ADOM types must match. Remember that converting to a template is unnecessary, and FortiAnalyzer will not automatically rename reports to resolve naming conflicts.

Q7. What is the purpose of running the command diagnose sql status sqlreportd?

Answer: C. C. To display the SQL query connections and hcache status

The correct answer is C because the command displays active SQL query connections alongside the hcache status. Exam takers should memorize this specific diagnostic command for troubleshooting report generation and caching issues.

Q8. Which of the following are valid components of a FortiAnalyzer playbook?

Answer: B,C. B. Actions || C. Triggers

The correct answers are B and C because FortiAnalyzer playbooks are constructed using actions and triggers. Workflow templates and fabric connectors are valuable features, but they are not primary structural components of a playbook.

Q9. The connection status of a new device on FortiAnalyzer is listed as Unauthorized. What does that status mean?

Answer: A. A. It is a device whose registration has not yet been accepted in FortiAnalyzer.

The correct answer is A because the unauthorized status means the device attempted to register but awaits administrator approval. Assignment to an ADOM only happens after you explicitly authorize the device connection.

Q10. You discover that a few reports are taking a long time to generate. Which two steps can you take to troubleshoot? (Choose two.)

Answer: B,D. B. Enable auto-cache and run the reports again || D. Review report diagnostics

Enabling auto-cache allows FortiAnalyzer to reuse processed data, significantly speeding up report generation. Reviewing report diagnostics is the primary native troubleshooting step to identify bottlenecks. Increasing quotas or deleting cache entries does not resolve underlying performance delays.

Q11. Which log will generate an event with the status Contained?

Answer: A. A. An AV log with action=quarantine.

An antivirus log with the action set to quarantine generates an event with a contained status. The system successfully isolated the malicious file, preventing it from executing or spreading. Actions like pass or drop do not actively isolate the threat.

Q12. Which statement about exporting items in Report Definitions is true?

Answer: C. C. Chart exports contain associated datasets.

When exporting a chart from FortiAnalyzer, the system automatically includes its associated datasets. This ensures the chart has the necessary data structure to render correctly upon import. Templates and datasets lack this specific dependency link during export operations.

Q13. You are tasked with finding logs corresponding to a suspected attack on your network. You need to use an interface where all identified threats within a timeframe are listed and organized. You also need to be able to quickly export the inf…

Answer: D. C. FortiView

FortiView provides a graphical, interactive summary of network activity that lists and organizes threats by severity and time. Log View is incorrect because it focuses on raw log data rather than a summarized view, making threat investigation less efficient.

Q14. Which log will generate an event with the status Unhandled?

Answer: B. B. An IPS log with action=pass.

An IPS log with action equals pass generates an Unhandled status because the system detected a potential threat but did not actively mitigate or block the traffic. Logs showing dropped, blocked, or quarantined actions indicate the threat was actively handled.

More NSE 5 – FortiAnalyzer 7.6 Analyst drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top