FCP-FAZ-AD-7-4 Sample Questions & Answers
Managing log data and building reports carries the most weight, alongside initial setup with high availability and RAID, registering and troubleshooting devices, and administering domains, access, and disk-quota backups.
Launch the full FCP-FAZ-AD-7-4 simulator →Free FCP-FAZ-AD-7-4 Sample Questions with Answers
Real questions from the Fortinet Certified Professional - FortiAnalyzer 7.4 Administrator practice test — answers and explanations included. Showing 10 of 20 free samples.
- Question 1Beginner
Administration · Manage disk quota and backups
True or False: Once an ADOM's disk quota is set, it can only be increased and cannot be decreased without deleting and recreating the ADOM.
Show answer & explanation
Correct answer: B
An ADOM's disk quota can be both increased and decreased after it has been set. This can be done through the GUI or CLI, provided there is available disk space. However, you cannot decrease the quota to a value less than the current amount of data stored in that ADOM.
- Question 2Beginner
Administration · Manage disk quota and backups
An administrator is restoring a FortiAnalyzer configuration backup onto a new, identical hardware model. The backup file is encrypted. What information, in addition to the backup file itself, is absolutely required to successfully complete the restore operation?
Show answer & explanation
Correct answer: B
When a FortiAnalyzer configuration backup is encrypted, the password used for that encryption is mandatory for the restore process. Without the correct password, the FortiAnalyzer cannot decrypt the file and the restore operation will fail.
- Question 3Intermediate
System Configuration · Manage High Availability
A FortiAnalyzer HA cluster is configured in active-passive mode. During a maintenance window, the primary unit is rebooted. A failover occurs as expected. After the original primary unit comes back online, it immediately takes over the primary role again, causing a second network interruption. What setting needs to be adjusted to prevent the original primary from automatically reclaiming its role after a reboot?
Show answer & explanation
Correct answer: C
HA preemption is the feature that allows a device with a higher priority (the original primary) to automatically take over the primary role when it becomes available. By disabling preemption, the original primary unit will remain in a passive state after it reboots, allowing the current primary (the original secondary) to continue its role without interruption. This prevents the unwanted second failover.
- Question 4Intermediate
Logs and Reports Management · Manage log data
An administrator observes that FortiAnalyzer is frequently rebuilding its SQL database, causing high CPU utilization and slow report generation. Which of the following actions is the most likely cause of this behavior?
Show answer & explanation
Correct answer: B
FortiAnalyzer maintains a specific SQL database schema for each FortiOS major version within an ADOM. If logs from a device with a different major FortiOS version (e.g., FortiOS 7.2 logs being sent to an ADOM configured for 7.4) are received, FortiAnalyzer will trigger a database rebuild to accommodate the different log format. This is a resource-intensive process and a common cause of performance issues.
- Question 5Beginner
Logs and Reports Management · Manage log data
What is the primary purpose of using log forwarding on FortiAnalyzer?
Show answer & explanation
Correct answer: B
Log forwarding allows FortiAnalyzer to act as a central aggregator and then forward received logs to other systems. This is commonly used to integrate with a central corporate SIEM (like Splunk or QRadar) or to create a tiered logging architecture with multiple FortiAnalyzers (e.g., regional collectors forwarding to a central analyzer).
- Question 6IntermediateSelect 3
Administration · Configure administrative access
An administrator is creating an admin profile to grant a junior analyst read-only access to view logs and reports within a specific ADOM. Which three permissions should be configured in the administrator profile to adhere to the principle of least privilege? (Select THREE)
Show answer & explanation
Correct answers: A, B, D
- Question 7Beginner
System Configuration · Describe FortiAnalyzer concepts
A FortiAnalyzer is deployed in Collector mode. What is its primary function in this configuration?
Show answer & explanation
Correct answer: B
In a distributed architecture, a FortiAnalyzer in Collector mode is optimized for log reception and forwarding. Its main job is to collect logs from multiple devices (often in a remote location), perform initial indexing, and then forward the logs to a central FortiAnalyzer in Analyzer mode for detailed analysis and reporting. This reduces the processing load on the Analyzer and optimizes WAN bandwidth.
- Question 8Advanced
Device Management · Manage devices
An organization is migrating its FortiGate devices to a new FortiAnalyzer. The administrator needs to move a FortiGate from the old FortiAnalyzer to the new one while preserving the ability to view its historical logs on the old appliance. What is the best approach to achieve this?
Show answer & explanation
Correct answer: B
Deleting a device from FortiAnalyzer also deletes its associated historical logs. To preserve the logs on the old appliance while stopping it from receiving new logs, the correct procedure is to edit the device and set its status to 'Inactive' or 'Decommissioned'. This retains the device entry and its log data for historical reporting but removes it from the active device list. The FortiGate can then be configured to send logs to the new FortiAnalyzer.
- Question 9Intermediate
Logs and Reports Management · Manage log data
The command
set log-checksum ______is used to configure the hashing algorithm for ensuring log file integrity. Which value should be entered in the blank to specify the strongest available algorithm?Show answer & explanation
Correct answer: C
FortiAnalyzer supports multiple hashing algorithms for log file checksums. Among the available options (md5, sha1, sha256, sha512), SHA-512 is the strongest. However, SHA-256 is a commonly available and strong option. For the purpose of this question, if both were options, sha512 would be stronger, but sha256 is the strongest among the typical choices provided in exams and a significant upgrade over md5 and sha1.
- Question 10Intermediate
Logs and Reports Management · Manage reports
A report is configured to be generated and emailed daily. Administrators report that the data in the report seems to be consistently 24 hours old. For example, Monday's report shows data from Saturday, not Sunday. What is the most likely cause of this issue?
Show answer & explanation
Correct answer: B
The 'Time Period' setting in a report is critical. 'Last 1 Day' (or Last 24 Hours) is a rolling window up to the moment the report is generated. 'Yesterday' refers to the fixed calendar day before the report is generated (from 00:00 to 23:59). If a report is generated early on Monday morning, 'Yesterday' refers to all of Sunday. The described behavior (Monday's report showing Saturday data) suggests the time period is set to something like 'Previous Day' in a context where the report generation cycle is misaligned with data aggregation, but the most common configuration error leading to stale data is using a fixed calendar period like 'Yesterday' when a rolling period is desired.
Ready for the real thing?
The full FCP-FAZ-AD-7-4 simulator has every exam-style question, timed mode, and instant scoring.