Fortinet NSE 5 Practice Exam Questions and Answers – Part 4/4

Practice for the NSE 5 – FortiAnalyzer 7.6 Analyst exam with 17 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: Which two statements are true regarding FortiAnalyzer operating modes? (Choose two.). Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the NSE 5 – FortiAnalyzer 7.6 Analyst practice test →

What you will practice

  • Which two statements are true regarding FortiAnalyzer operating modes? (Choose two.)
  • Which statement is true about sending notifications with incident updates?
  • What is the main purpose of deploying RAID with FortiAnalyzer?
  • Refer to the exhibit. Which statement is correct regarding the event displayed?
  • A colleague has reported that log entries seen previously are now missing from FortiView. You confirmed that…
  • Which two statements are true regarding high availability (HA) on FortiAnalyzer? (Choose two.)

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. Which two statements are true regarding FortiAnalyzer operating modes? (Choose two.)

Answer: A,B. A. By deploying different FortiAnalyzer devices in both modes, you can improve their overall performance. || B. When in collector mode. FortiAnalyzer collects logs from multiple devices and forwards these logs in the original binary format.

Deploying collector mode offloads log receiving and forwarding tasks from the analyzer, which improves overall performance. The distractor about event management fails because collectors only forward logs in binary format and lack reporting or analysis features.

Q2. Which statement is true about sending notifications with incident updates?

Answer: A. A. You can send notifications to multiple external platforms.

FortiAnalyzer can send incident notifications to multiple external platforms simultaneously using fabric connectors. The strongest distractor fails because administrators can configure each individual fabric connector with completely different notification settings.

Q3. What is the main purpose of deploying RAID with FortiAnalyzer?

Answer: A. A. To provide redundancy of your log data

RAID provides redundancy and fault tolerance for log data storage. While backups create separate offline copies, RAID ensures continuous operation and data availability even if a physical drive fails.

Q4. Refer to the exhibit. Which statement is correct regarding the event displayed?

Answer: B. B. The security risk was blocked or dropped.

When an event status is mitigated, the security risk was actively blocked or dropped. Unhandled means the risk remains open, and contained indicates the source was isolated by network controls.

Q5. A colleague has reported that log entries seen previously are now missing from FortiView. You confirmed that FortiView is set to display logs from the appropriate time period, and set up with the appropriate filters. You also confirmed tha…

Answer: B,D. a. Check if the analytics logs retention data policy is too short. || c. Check if the total disk quota has been exceeded.

The analytics log retention policy dictates when processed logs are deleted, while the ADOM disk quota can trigger data purging independently of system-wide free space. Examining the archive logs will not help since FortiView queries strictly utilize the analytics database.

Q6. Which two statements are true regarding high availability (HA) on FortiAnalyzer? (Choose two.)

Answer: B,C. B. FortiAnalyzer HA supports synchronization of logs as well as some system and configuration settings. || C. All devices in a FortiAnalyzer HA cluster must run in the same operation mode: analyzer or collector.

FortiAnalyzer high availability synchronizes logs and configurations, and all nodes must operate in the same analyzer or collector mode. The strongest distractor fails because HA relies strictly on VRRP, meaning it is generally unsupported by public cloud providers.

Q7. Which two FortiAnalyzer features allow you to build a dataset and a chart automatically, based on a filtered search result? (Choose two.)

Answer: C,D. C. Export to Report Chart (FortiView) || D. Chart Builder

Chart Builder and Export to Report Chart generate datasets and charts automatically based on your filtered search results. The Dataset Library only provides static templates, so rely on the chart builder for automated visualizations.

Q8. What must be configured to be able to send notifications about incident updates?

Answer: B. B. Fabric connector

Configuring a fabric connector is required to send incident update notifications to external platforms. While an email server handles standard alerts, fabric connectors manage the routing and delivery of those automated incident notifications.

Q9. Which database language does FortiAnalyzer support for the purposes of logging and reporting?

Answer: B. A. SQL

FortiAnalyzer relies on Structured Query Language to manage its logging and reporting databases. For the exam, remember that SQL underpins the analytics and chart datasets, while LDAP and XML serve entirely different roles.

Q10. What allows one task to use the output of a previous task as its input?

Answer: D. C. Output variables

Output variables capture data from a completed task, allowing subsequent tasks to consume that information as input. This is a key playbook concept, whereas trigger variables only initiate the workflow itself.

Q11. Which connector type is enabled by default to be used in playbooks?

Answer: B. A. Local connector

The local connector is enabled by default for playbooks, allowing immediate execution of tasks on the FortiAnalyzer itself. Fabric connectors require explicit configuration before they can interact with downstream devices.

Q12. When is the execution of a playbook considered as failed?

Answer: E. D. When at least one of the tasks fails

A playbook execution is marked as failed if at least one of its tasks fails, ensuring prompt identification of workflow issues. A playbook does not require all tasks to fail to trigger a failure status.

Q13. When you move a FortiGate device from one ADOM to a new ADOM, what is the purpose of rebuilding the new ADOM database?

Answer: D. C. To run reports on the device's analytics logs in the new ADOM

Rebuilding the new ADOM database processes the device's analytics logs so you can generate reports successfully. Without rebuilding, the historical data remains inaccessible for reporting queries in the target ADOM.

Q14. What should you always do after erasing the FortiAnalyzer configuration on flash?

Answer: B. B. Run the execute format disk command

Running the execute format disk command prepares the disk for use after erasing the device configuration. Rebooting or resetting settings will skip the necessary disk preparation required for normal operation.

Q15. What is included in the disk quota for each ADOM on the FortiAnalyzer?

Answer: A. A. Archive logs and analytics logs

An ADOM disk quota specifically includes analytics logs and archive logs. The system manages raw logs and SQL database tables outside this specific quota limit, so watch for options mixing storage tiers.

Q16. Which two remote servers are supported for the upload of FortiAnalyzer local logs? (Choose two.)

Answer: D,E. C. FTP || D. SFTP

FortiAnalyzer supports uploading local logs to remote FTP and SFTP servers. TCP and UDP are underlying transport protocols rather than destination server types, making them incorrect choices for remote log uploads.

Q17. What is included in the allocated disk quota for each ADOM on FortiAnalyzer?

Answer: A. a. Archive logs and Analytics logs

The ADOM disk quota includes both analytics logs and archive logs, as these are the final data sets stored after the system processes incoming raw logs. FortiView and reports rely on this specific quota to function properly.

More NSE 5 – FortiAnalyzer 7.6 Analyst drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top