Practice for the NSE 5 – FortiAnalyzer 7.6 Analyst exam with 16 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: The RAID 10 level comprises what data format?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.
Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the NSE 5 – FortiAnalyzer 7.6 Analyst practice test →
What you will practice
- The RAID 10 level comprises what data format?
- Which statement about reports is true?
- Which statement accurately describes FortiAnalyzer operating in collector mode?
- What must you configure on FortiAnalyzer to upload a FortiAnalyzer report to a supported external server? (Ch…
- Which item must you configure on FortiAnalyzer to email generated reports automatically?
- Refer to the exhibit. What does the data point at 14:35 tell you?
Answers and explanations
Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.
Q1. The RAID 10 level comprises what data format?
Answer: B. B. Mirroring and striping
RAID 10 combines mirroring for redundancy and striping for performance. It requires a minimum of four disks and is well supported across FortiAnalyzer hardware models, making it distinct from parity based levels.
Q2. Which statement about reports is true?
Answer: B. b. They can be generated on demand or by schedule.
FortiAnalyzer reports can be generated manually on demand or automatically via a configured schedule. You do not need an output profile or a password to generate the report itself, though profiles dictate the final delivery format.
Q3. Which statement accurately describes FortiAnalyzer operating in collector mode?
Answer: D. d. This FortiAnalyzer device can collect logs from other devices, but will not provide analysis.
A FortiAnalyzer in collector mode receives logs from connected devices but does not analyze them locally. It forwards those logs upstream to an analyzer mode device for processing, which reduces the processing load on the collector.
Q4. What must you configure on FortiAnalyzer to upload a FortiAnalyzer report to a supported external server? (Choose two.)
Answer: A,C. A. SFTP, FTP, or SCP server || C. Output profile
You must configure an external server definition and an output profile to successfully upload reports. While report scheduling determines when generation occurs, the output profile explicitly dictates the delivery method and destination.
Q5. Which item must you configure on FortiAnalyzer to email generated reports automatically?
Answer: A. A. Output profile
An output profile acts as the central configuration point to define email delivery settings for generated reports. Report scheduling only triggers the report generation itself, while the output profile controls exactly how and where it is delivered.
Q6. Refer to the exhibit. What does the data point at 14:35 tell you?
Answer: B. B. FortiAnalyzer is indexing logs faster than logs are being received.
The correct answer works because the insert rate line tracking processing is higher than the receive rate. For the exam, carefully track which line is which; dropping logs would typically show a wide unprocessed gap.
Q7. In the FortiAnalyzer FortiView, source and destination IP addresses from FortiGate devices are not resolving to a hostname. How can you resolve the source and destination IP addresses, without introducing any additional performance impact…
Answer: D. D. Resolve IP addresses on FortiGate
The correct answer works because offloading DNS resolution to FortiGate prevents heavy lookup loads on the FortiAnalyzer database. Remember that local FortiAnalyzer resolution directly consumes analytical resources.
Q8. You need to upgrade your FortiAnalyzer firmware. What happens to the logs being sent to FortiAnalyzer from FortiGate during the time FortiAnalyzer is temporarily unavailable?
Answer: B. B. FortiGate uses the miglogd process to cache the logs
The correct answer works because the miglogd daemon caches logs locally on the FortiGate during outages. The FortiAnalyzer does not automatically fetch dropped logs unless explicitly configured.
Q9. If you upgrade the FortiAnalyzer firmware, which report element can be affected?
Answer: A. A. Custom datasets
Custom datasets often break during firmware upgrades due to changes in the underlying database schema. Standard report settings and schedules generally carry over cleanly, but your custom dataset syntax might require manual adjustments.
Q10. FortiAnalyzer reports are dropping analytical data from 15 days ago, even though the data policy setting for analytics logs is 60 days. What is the most likely problem?
Answer: A. A. Quota enforcement is acting on analytical data before a report is complete
Quota enforcement deletes older analytical data to free up disk space, overriding the configured data retention policy. If your disk fills up before the sixty day policy expires, the system automatically purges the oldest analytics.
Q11. Which two configurations must you set up on FortiAnalyzer to email a report externally? (Choose two.)
Answer: A,B. A. Mail server || B. Output profile
A mail server and an output profile are required because the profile dictates email delivery and the server handles transmission. Scheduling only automates generation time, not the actual delivery mechanism itself.
Q12. On the RAID management page, the disk status is listed as Initializing. What does the status Initializing indicate about what the FortiAnalyzer is currently doing?
Answer: C. C. FortiAnalyzer is writing to all of its hard drives to make the array fault tolerant
The correct answer works because initializing writes parity data across all drives to establish the array. Do not confuse this with rebuilding, which only reconstructs parity data onto a newly added replacement drive.
Q13. If a hard disk fails on a FortiAnalyzer that supports software RAID, what should you do to bring the FortiAnalyzer back to functioning normally, without losing data?
Answer: D. D. Shut down FortiAnalyzer and replace the disk
With software RAID, you must shut down the FortiAnalyzer before replacing the failed disk to prevent data corruption. Hot swapping is reserved for hardware RAID configurations, making that distractor incorrect for this specific scenario.
Q14. FortiAnalyzer centralizes which functions? (Choose three.)
Answer: B,C,E. B. Graphical reporting || C. Content archiving / data mining || E. Security log analysis / forensics
FortiAnalyzer centralizes graphical reporting, content archiving, and security log analysis to streamline network forensics. Remember that active vulnerability assessment and raw network analysis are typically handled by other dedicated Fortinet tools, not the analyzer.
Q15. After you have moved a registered logging device out of one ADOM and into a new ADOM, what is the purpose of running the following CLI command? execute sql-local rebuild-adom <new-ADOM-name>
Answer: E. D. To populate the new ADOM with analytical logs for the moved device, so you can run reports
The command works by repopulating the new domain database with historical logs so reports function correctly. Remember that simply moving the device in the GUI does not automatically migrate its older logs.
Q16. Templates do not contain ________.
Answer: A. A. Data
Report templates define the layout, macros, and datasets for generating a report, but they do not contain the actual data. The data is populated dynamically from the FortiAnalyzer database when the report runs.
More NSE 5 – FortiAnalyzer 7.6 Analyst drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.