Fortinet NSE 5 Practice Exam Questions and Answers – Part 11/12

Practice for the NSE 5 – FortiAnalyzer 7.6 Analyst exam with 16 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: Which type of playbook in FortiAnalyzer is used to automate the triage process for security alerts?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the NSE 5 – FortiAnalyzer 7.6 Analyst practice test →

What you will practice

  • Which type of playbook in FortiAnalyzer is used to automate the triage process for security alerts?
  • Which report type would you generate in FortiAnalyzer to show firewall policy usage over time?
  • How does FortiAnalyzer improve log storage efficiency without losing critical data?
  • What feature does FortiAnalyzer offer to help organizations comply with regulatory reporting requirements?
  • How can FortiAnalyzer help in tracking user activity?
  • What is the purpose of an event handler in FortiAnalyzer?

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. Which type of playbook in FortiAnalyzer is used to automate the triage process for security alerts?

Answer: C. C. Triage playbook

A triage playbook is explicitly designed to automate the initial sorting, prioritization, and assignment of security alerts. For the exam, differentiate this from incident playbooks, which are used later to coordinate the actual response and remediation phases after triage is completed.

Q2. Which report type would you generate in FortiAnalyzer to show firewall policy usage over time?

Answer: D. D. Policy Hit Count report

The Policy Hit Count report tracks how many times each firewall policy has been triggered. This is crucial for identifying unused or heavily loaded policies. Traffic volume focuses on bandwidth, while user activity tracks behavior.

Q3. How does FortiAnalyzer improve log storage efficiency without losing critical data?

Answer: C. C. By applying log compression

The correct answer works because applying log compression reduces the physical disk space required to store logs without altering or deleting the actual data. For the exam, remember that pruning directly deletes older logs based on retention policies to free up space, whereas compression preserves the data.

Q4. What feature does FortiAnalyzer offer to help organizations comply with regulatory reporting requirements?

Answer: A. A. Compliance report templates

Compliance report templates provide pre-defined formats and datasets specifically designed to meet industry standards like PCI DSS or HIPAA. While forwarding logs or viewing dashboards provides raw visibility, only structured compliance reports fulfill formal regulatory auditing requirements on FortiAnalyzer.

Q5. How can FortiAnalyzer help in tracking user activity?

Answer: C. C. By generating user activity reports based on web and application usage

Generating user activity reports based on web and application usage is correct because it directly translates raw traffic and UTMP logs into readable behavioral insights. While analyzing raw traffic logs provides the underlying data, it does not summarize the activity into human-readable compliance formats.

Q6. What is the purpose of an event handler in FortiAnalyzer?

Answer: A. A. To monitor and respond to specific log events

Event handlers monitor incoming logs and trigger automated responses when specific criteria are met. This is a key exam concept for proactive threat management and incident creation, not routine disk management.

Q7. Which FortiAnalyzer feature allows for the automated detection of potential security incidents?

Answer: C. C. Event correlation

Event correlation automatically detects potential security incidents by analyzing and finding relationships between various log events. Incident management handles events after detection, whereas correlation actively identifies them.

Q8. How does FortiAnalyzer assist SOC teams in managing incidents?

Answer: C. C. By providing dashboards to track, escalate, and resolve incidents

FortiAnalyzer provides dashboards that let SOC teams track, escalate, and resolve incidents through a structured workflow. It is an analytics platform, so it does not actively disable network devices or run penetration tests.

Q9. What is the function of FortiAnalyzer's playbooks?

Answer: A. A. To automate repetitive SOC tasks

Playbooks are automated workflows designed to handle repetitive SOC tasks and speed up incident response. They are built for operational efficiency, rather than managing device configurations or acting as a backup repository.

Q10. Which of the following components is essential in creating a playbook on FortiAnalyzer?

Answer: C. C. Action blocks

Action blocks are the fundamental building blocks used to construct automated playbooks, dictating what the workflow executes. Device management and firmware schedulers are administrative tools unrelated to playbook logic.

Q11. What is the primary use of log statistics in FortiAnalyzer?

Answer: B. B. To provide a summary of log types and quantities over time

Log statistics provide a high-level summary of log types and quantities generated over a specific time. This helps analysts identify network trends. They do not directly measure security posture or configure retention policies.

Q12. What is the default protocol used by FortiAnalyzer to receive logs from FortiGate?

Answer: C. C. Syslog

FortiGate devices primarily use the standard Syslog protocol over UDP or TCP to send logs to FortiAnalyzer. Remember that while Syslog is the protocol, you must ensure port 514 is open for communication.

Q13. What is the purpose of creating custom report templates in FortiAnalyzer?

Answer: C. C. To customize reports for specific organizational needs

Custom report templates let you tailor content and format to meet specific organizational or compliance requirements. Standard templates might be too generic, so customizing ensures stakeholders receive relevant security data.

Q14. What is the purpose of an incident in FortiAnalyzer?

Answer: C. C. To document and manage security events for further investigation

Incidents are used to document, track, and manage security events that require further investigation. They package related event logs together, providing context for incident response rather than just recording system performance.

Q15. What is the function of a filter in a FortiAnalyzer log search?

Answer: C. C. To narrow down search results based on specific criteria

Filters refine log searches by applying specific criteria to narrow down results. This allows analysts to quickly isolate relevant security events from massive datasets. Without filters, finding specific threats is practically impossible.

Q16. When managing reports in FortiAnalyzer, what can be customized?

Answer: C. C. Report layouts, content, and templates

Customizing report layouts, content, and templates is correct because FortiAnalyzer provides dedicated report design tools. For the exam, remember that device firmware and system retention policies are administrative configurations, not design elements.

More NSE 5 – FortiAnalyzer 7.6 Analyst drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top