Practice for the NSE 5 – FortiAnalyzer 7.6 Analyst exam with 16 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: Which two statements are true regarding the outbreak detection service? (Choose two.). Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.
Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the NSE 5 – FortiAnalyzer 7.6 Analyst practice test →
What you will practice
- Which two statements are true regarding the outbreak detection service? (Choose two.)
- What must you consider when using log fetching? (Choose two.)
- What output profiles can you configure for report event notifications? (Choose two.)
- What are two advantages of setting up a fabric ADOM? (Choose two.)
- What can you do on FortiAnalyzer to restrict administrative access from specific locations?
- Which two of the following must you configure on FortiAnalyzer to email a FortiAnalyzer report externally? (C…
Answers and explanations
Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.
Q1. Which two statements are true regarding the outbreak detection service? (Choose two.)
Answer: C,D. C. An additional license is required. || D. It automatically downloads new event handlers and reports.
The outbreak detection service requires an active FortiGuard license and automatically downloads newly created event handlers and reports. Alerts are not restricted to the root ADOM and can be viewed globally or within specific ADOMs rather than arriving via direct email.
Q2. What must you consider when using log fetching? (Choose two.)
Answer: A,B. A. The fetch client can retrieve logs from devices that are not added to its local Device Manager. || B. You can use filters to include only logs from a single device.
The fetch client can pull logs for devices not in its local Device Manager, and filters allow you to narrow the retrieval to a single device. Retrieved logs maintain their original type during transfer, meaning archived logs stay archived on the receiving client.
Q3. What output profiles can you configure for report event notifications? (Choose two.)
Answer: C,D. C. Upload to a server || D. Email
Email and upload to a server are correct because these are valid output profiles for notifications. Remember that forwarding logs to another analyzer is a log forwarding feature, not a report notification.
Q4. What are two advantages of setting up a fabric ADOM? (Choose two.)
Answer: A,C. A. It can be used for fast data processing and log correlation || C. It can include all Fortinet devices that are part of the same Security Fabric
A fabric ADOM centralizes logs from multiple Fortinet Security Fabric devices, not just FortiGates, enabling faster log processing and cross-device correlation. Avoid option B because the ADOM manages logs and analytics, it does not establish or facilitate direct communication between fabric devices.
Q5. What can you do on FortiAnalyzer to restrict administrative access from specific locations?
Answer: A. A. Configure trusted hosts for that administrator.
Configuring trusted hosts for an administrator restricts login attempts to approved IP subnets, securing access by location. Remember that two-factor authentication validates user identity, but it fails to restrict access based on the source location.
Q6. Which two of the following must you configure on FortiAnalyzer to email a FortiAnalyzer report externally? (Choose two.)
Answer: A,C. A. Output profile || C. Mail server
To email reports externally, an output profile dictates the delivery method, while a mail server provides the necessary SMTP relay. Remember that report scheduling only handles timing, whereas the output profile and mail server handle the actual email delivery mechanics.
Q7. What is the purpose of a dataset query in FortiAnalyzer?
Answer: B. B. It retrieves log data from the database
Dataset queries extract specific log data from the SQL database, forming the foundation for chart generation. Do not confuse this with log ingestion; FortiAnalyzer handles data insertion automatically, whereas datasets strictly retrieve information for analysis and reporting.
Q8. Which two settings must you configure on FortiAnalyzer to allow non-local administrators to authenticate to FortiAnalyzer with any user account in a single LDAP group? (Choose two.)
Answer: A,B. A. A local wildcard administrator account || B. A remote LDAP server
You must define the remote LDAP server to handle authentication and create a local wildcard administrator account linked to it. Trusted host profiles restrict IP access but do not define the LDAP group mapping required for authentication.
Q9. What is the primary difference between raw format logs and formatted format logs?
Answer: B. B. Raw logs display logs as they appear within the log file,
Raw logs are correct because they display the unprocessed data exactly as it appears in the file. Formatted logs are designed to be much more human readable, so raw logs lack that structured presentation.
Q10. Which two constraints can impact the amount of reserved disk space required by FortiAnalyzer? (Choose two.)
Answer: B,D. B. Disk size || D. RAID level
FortiAnalyzer calculates reserved disk space as a percentage based on the total disk size, and RAID levels reduce the total usable capacity. Quotas apply to logical data allocation and do not dictate the underlying hardware space the system reserves.
Q11. Which two statements about log forwarding are true? (Choose two.)
Answer: C,D. C. The client retains a local copy of the logs after forwarding. || D. You can use aggregation mode only with another FortiAnalyzer.
In log forwarding, the client retains a local copy of the logs, and aggregation mode is specifically designed to work between two FortiAnalyzer units. Aggregation reduces bandwidth by grouping logs, whereas standard forwarding sends logs in real time.
More NSE 5 – FortiAnalyzer 7.6 Analyst drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.