Fortinet NSE 5 Practice Exam Questions and Answers – Part 7/8

Practice for the NSE 5 – FortiAnalyzer 7.6 Analyst exam with 16 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: What happens when a log file saved on FortiAnalyzer disks reaches the size specified in the device log settings?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the NSE 5 – FortiAnalyzer 7.6 Analyst practice test →

What you will practice

  • What happens when a log file saved on FortiAnalyzer disks reaches the size specified in the device log settin…
  • What is the purpose of employing RAID with FortiAnalyzer?
  • How do you restrict an administrator's access to a subset of your organization's ADOMs?
  • In order for FortiAnalyzer to collect logs from a FortiGate device, what configuration is required? (Choose t…
  • On FortiAnalyzer, what is a wildcard administrator account?
  • Which FortiAnalyzer feature allows you to retrieve the archived logs matching a specific timeframe from anoth…

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. What happens when a log file saved on FortiAnalyzer disks reaches the size specified in the device log settings?

Answer: B. B. The log file rolls over and is archived.

When a log file reaches its maximum configured size, FortiAnalyzer rolls over the active file and archives it. This prevents any single file from consuming excessive space and keeps the logging service running without interruption.

Q2. What is the purpose of employing RAID with FortiAnalyzer?

Answer: A. A. To introduce redundancy to your log data

Using RAID introduces redundancy to protect your log data against disk failures. While ADOMs handle logical data separation, RAID provides the physical fault tolerance required to maintain continuous log availability.

Q3. How do you restrict an administrator's access to a subset of your organization's ADOMs?

Answer: B. B. Assign the ADOMs to the administrator's account

Assigning specific ADOMs to an administrator account restricts their access to only those domains. Trusted hosts only limit management access by IP address, and assigning a super user profile grants unrestricted access across the system.

Q4. In order for FortiAnalyzer to collect logs from a FortiGate device, what configuration is required? (Choose two.)

Answer: A,D. A. Remote logging must be enabled on FortiGate || D. FortiGate must be registered with FortiAnalyzer

Enabling remote logging on FortiGate and registering the device with FortiAnalyzer are both required to collect logs. While ADOMs and encryption offer organizational and security benefits, they are not strictly required for basic log ingestion.

Q5. On FortiAnalyzer, what is a wildcard administrator account?

Answer: A. A. An account that permits access to members of a LDAP group

A wildcard administrator account allows members of a specified remote authentication group, such as an LDAP group, to access FortiAnalyzer without creating individual accounts. For the exam, remember that wildcard administration relies on group-based authentication rather than generic guest access.

Q6. Which FortiAnalyzer feature allows you to retrieve the archived logs matching a specific timeframe from another FortiAnalyzer device?

Answer: C. C. Log fetching

Log fetching allows a FortiAnalyzer to pull archived logs matching a specific timeframe from another FortiAnalyzer. In contrast, log forwarding pushes real-time logs, and aggregation mode synchronizes the entire database rather than querying a specific window.

Q7. How does FortiAnalyzer retrieve specific log data from the database?

Answer: C. C. SQL SELECT statement

FortiAnalyzer uses the SQL SELECT statement to query and retrieve specific log data from its database. Candidates should note that standard SQL syntax applies here, meaning GET and EXTRACT are either invalid or irrelevant for general data retrieval.

Q8. Logs are being deleted from one of your ADOMs earlier than the configured setting for archiving in your data policy. What is the most likely problem?

Answer: C. C. The ADOM disk quota is set too low based on log rates

ADOM disk quotas dictate exactly how much space an individual ADOM can consume, causing premature log deletion if set too low. While global disk space is a primary hardware constraint, the specific ADOM quota is the localized setting that overrides retention policies.

Q9. FortiAnalyzer uses the Optimized Fabric Transfer Protocol (OFTP) over SSL for what purpose?

Answer: C. C. To encrypt log communication between devices

OFTP over SSL is used to encrypt log communication between Fortinet devices, ensuring data confidentiality and integrity during transit. Remember that OFTP handles secure transfer, whereas options like log modification prevention or forwarding duplicate streams are policy features.

Q10. What FortiGate process caches logs when FortiAnalyzer is not reachable?

Answer: B. B. miglogd

The miglogd process on FortiGate caches logs locally whenever FortiAnalyzer is unreachable, forwarding them automatically upon restored connectivity. Candidates should memorize core daemons, distinguishing miglogd for logging from oftpd which handles the actual transfer protocol.

Q11. What is the purpose of the 'set log-checksum md5' CLI command?

Answer: D. D. To add a log file checksum

This command configures FortiAnalyzer to attach an MD5 checksum to log files, verifying data integrity during storage or transit. A common exam trap is confusing this security feature with standard encryption protocols or general log forwarding mechanisms.

Q12. Which two statements are true regarding FortiAnalyzer log forwarding? (Choose two.)

Answer: A,C. A. Both modes, forwarding and aggregation, support encryption of logs between devices. || C. Aggregation mode stores logs and content files and uploads them to another FortiAnalyzer device at a scheduled time.

Both forwarding and aggregation modes support encryption, and aggregation mode specifically uploads logs and content files at scheduled times. Avoid confusing the two, as forwarding happens in real-time and supports syslog servers, unlike aggregation which is strictly between FortiAnalyzers.

Q13. Which statement is true regarding macros on FortiAnalyzer?

Answer: D. D. Macros are ADOM specific and each ADOM has unique macros relevant to that ADOM.

Macros are ADOM specific, meaning each administrative domain utilizes unique macros tailored to its specific log data and reporting requirements. Remember that these dynamic variables populate report fields and are not limited to generic templates or restricted solely to FortiGate ADOMs.

Q14. What is the purpose of output variables in FortiAnalyzer playbooks?

Answer: D. D. To use the output of the previous task as the input of the current task

Output variables pass the results of a previous task as input for the current task, enabling seamless data chaining within automated workflows. For the exam, associate these variables strictly with task-to-task data flow rather than connector metadata or execution statistics.

Q15. A playbook contains five tasks in total. An administrator executed the playbook and four out of five tasks finished successfully, but one task failed. What will be the status of the playbook after its execution?

Answer: A. A. Failed

If any single task within a playbook execution fails, the overall playbook status is marked as Failed in the monitor. Success requires all tasks to complete without errors, while upstream failed only applies to dependent tasks skipped due to a prior failure.

Q16. You created a playbook on FortiAnalyzer that uses a FortiOS connector. When configuring the FortiGate side, which type of trigger must be used so that the actions in an automation stitch are available in the FortiOS connector?

Answer: B. B. Incoming webhook

An incoming webhook trigger is required on the FortiGate so it can receive actionable requests from the FortiAnalyzer playbook. Local event handlers and log triggers will not expose the automation stitch actions to the external FortiOS connector.

More NSE 5 – FortiAnalyzer 7.6 Analyst drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top