Practice for the NSE 5 – FortiAnalyzer 7.6 Analyst exam with 14 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: What is the purpose of playbook trigger variables?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.
Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the NSE 5 – FortiAnalyzer 7.6 Analyst practice test →
What you will practice
- What is the purpose of playbook trigger variables?
- As part of your analysis, you discover that a Medium severity level incident is fully remediated. You change…
- What happens when the indicator of compromise (IOC) engine on FortiAnalyzer finds web logs that match blackli…
- An administrator on your team has configured multiple reports to run periodically. Management has an addition…
- When managing incidents on FortiAnalyzer, what must an analyst be aware of?
- Which statement about SQL SELECT queries is true?
Answers and explanations
Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.
Q1. What is the purpose of playbook trigger variables?
Answer: B. B. To use information from the trigger to filter the action in a task
Trigger variables extract contextual information from the triggering event so you can use it to filter actions within subsequent tasks. They do not initiate the playbook run itself; they pass data to customize the response after the playbook starts.
Q2. As part of your analysis, you discover that a Medium severity level incident is fully remediated. You change the incident status to Closed: Remediated. Which statement about your update is true?
Answer: B. A. The incident dashboard will be updated.
Changing an incident status to Closed Remediated updates the incident dashboard to accurately reflect the current resolution state in reports and visualizations. Severity is a static attribute based on the event details and is not lowered by status updates.
Q3. What happens when the indicator of compromise (IOC) engine on FortiAnalyzer finds web logs that match blacklisted IP addresses?
Answer: D. D. A new infected entry is added for the corresponding endpoint under Compromised Hosts.
The IOC engine creates a new infected entry for the endpoint under the Compromised Hosts section to associate the threat with the device. FortiAnalyzer does not directly quarantine endpoints, as that action is managed by FortiGate or FortiClient.
Q4. An administrator on your team has configured multiple reports to run periodically. Management has an additional request that all newly generated reports be sent to a company email inbox for accessibility. The mail server has already been c…
Answer: D. D. Enable an output profile on the reports.
You must enable and assign an output profile on the reports to define the email recipients and file formats for generated reports. The report calendar handles scheduling but does not directly manage email distribution on its own.
Q5. When managing incidents on FortiAnalyzer, what must an analyst be aware of?
Answer: A. A. You can manually attach generated reports to incidents.
The correct answer is A because analysts can manually attach generated reports to incidents. Incident statuses are managed independently of attached events, and acknowledgment is not a prerequisite for analyzing the details.
Q6. Which statement about SQL SELECT queries is true?
Answer: D. D. They are not used in macros.
The correct answer is D because standard select queries are not used in FortiAnalyzer macros. Remember that SQL select statements strictly retrieve data and cannot purge logs or display database schemas on the exam.
Q7. Refer to the exhibit. What is the analyst trying to create?
Answer: B. B. The analyst is trying to create an output variable to be used in the playbook.
The correct answer is B because the analyst is creating an output variable. When you see a placeholder identifier being mapped within an action like attaching data, it indicates dynamic output being passed through the playbook.
Q8. Which FortiAnalyzer feature is primarily used for managing and investigating incidents?
Answer: C. C. Security Operations Center (SOC)
The correct answer is C because the Security Operations Center feature provides the centralized console for managing events and investigating incidents. While logging and reporting are crucial, they serve as supporting tools rather than the primary investigative interface.
Q9. Which two elements are contained in a system backup created on FortiAnalyzer? (Choose two.)
Answer: C,D. C. Report information || D. System information
A system backup on FortiAnalyzer includes system configuration information and report information, but it does not include the actual log database. Remember that device logs and database snapshots must be backed up using separate database backup procedures.
Q10. Which two actions should an administrator take to view Compromised Hosts on FortiAnalyzer? (Choose two.)
Answer: B,D. B. Enable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent to fortiAnalyzer. || D. Subscribe FortiAnalyzer to FortiGuard to keep its local threat database up to date.
Compromised Hosts detection relies on security logs like web filtering, so enabling these on FortiGate is essential. FortiAnalyzer also needs an active FortiGuard subscription to correlate these logs against the latest threat intelligence. Endpoint reachability is unnecessary.
Q11. Which two statements regarding the outbreak detection service are true? (Choose two.)
Answer: A,B. A. An additional license is required. || B. It automatically downloads new event handlers and reports.
Outbreak detection requires an additional FortiGuard license to activate its threat intelligence feeds. Once enabled, it automatically downloads updated event handlers and reports to track emerging threats. Alerts are viewed locally rather than being strictly limited to root ADOM.
Q12. Exhibit. How many events will be added to the incident created after running this playbook?
Answer: D. D. Ten events will be added.
The correct answer is ten events because the playbook filter matches exactly ten medium severity IPS events. For the exam, carefully count the events in the table that meet all configured criteria rather than relying on total numbers.
Q13. Exhibit: FAZ # diagnose fortilogd lograte last 5 seconds: 76.8, last 30 seconds: 132.1, last 60 seconds: 133.3 FAZ # diagnose fortilogd msgrate last 5 seconds: 1.4, last 30 seconds: 1.6, last 60 seconds: 1.6 What can you conclude about the…
Answer: E. A. The message rate being lower that the log rate is normal.
A lower message rate compared to the log rate is normal because FortiAnalyzer processes logs in batches and groups them into messages for efficient indexing. The output does not indicate indexing completion status or reveal the specific ratio of traffic logs to event logs.
Q14. Exhibit. What can you conclude about these search results? (Choose two.)
Answer: A,D. A. They can be downloaded to a file. || D. They were searched by using text mode.
The search results display raw log entries in plain text format with key value pairs, indicating the search was performed using text mode and can be downloaded. These logs are still available for analysis in FortiView despite the current text view.
More NSE 5 – FortiAnalyzer 7.6 Analyst drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.