FCP-FAZ-AN-7-4 Sample Questions & Answers
Log parsing and analysis ties with working SOC event handlers alongside incidents and indicators for the heaviest weighting, built on core FortiAnalyzer concepts, report management and troubleshooting, and creating automation playbooks.
Launch the full FCP-FAZ-AN-7-4 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Reports · Manage reports
A SOC manager wants to create a weekly executive summary report that shows only the top 10 most active applications and the top 5 users by bandwidth across the entire organization. The default reports show too much detail. To achieve this, the analyst must create a custom chart. Which component must be created first before the custom chart can be configured to display this specific, aggregated data?
Show answer & explanation
Correct answer: D
Datasets are the foundation of custom charts in FortiAnalyzer reports. A dataset defines the SQL-like query that fetches, filters, and aggregates the raw log data. To show the 'top 10 applications' or 'top 5 users', a dataset must be created first to perform this specific grouping and limiting of the data. The custom chart is then built upon this pre-processed dataset.
- Question 2Advanced
Playbooks · Use variables in tasks
An analyst is building a playbook to automate the initial triage of a suspected phishing email. The playbook is triggered by a FortiMail event. A key step is to extract the sender's email address and the URL from the event log to perform reputation checks. Which syntax should be used within the playbook tasks to reference these dynamic values from the triggering event?
Show answer & explanation
Correct answer: C
FortiAnalyzer playbooks use a Jinja2 templating syntax to reference variables. Values from the triggering event are accessed through the
FGT_eventobject. The correct syntax is{{ FGT_event.fieldname }}, wherefieldnamecorresponds to the normalized log field from the event, such assenderorurl. - Question 3Intermediate
Features and concepts · Describe how logging works in a Security Fabric
A financial institution has a strict 90-day log retention policy for all traffic logs for compliance reasons. An administrator has confirmed that the global log retention settings are configured correctly. However, a recent audit found that traffic logs for the 'Trading_Floor' ADOM are being purged after only 30 days. Logs for all other ADOMs are retained for the full 90 days. What is the most likely cause of this discrepancy?
Show answer & explanation
Correct answer: B
FortiAnalyzer allows for both global and per-ADOM log retention policies. A policy configured at the ADOM level will always take precedence over the global settings for that specific ADOM. This allows for granular control based on different compliance or operational needs for different sets of devices.
- Question 4Intermediate
Logging · Analyze logs
An analyst is investigating an incident involving a compromised user account. To determine the blast radius, they need to find every IP address the user
j.doehas logged in from over the past 7 days. Which of the following FortiAnalyzer log view queries would be the most efficient for this task?Show answer & explanation
Correct answer: D
The correct syntax for an exact match filter in the FortiAnalyzer log view is
fieldname = 'value'. Using single quotes ensures an exact match for the string 'j.doe'. Using double quotes or no quotes can lead to different interpretations of the search term, and 'contains' would perform a substring match, which is less precise and efficient for this specific requirement. - Question 5Beginner
SOC events and incident management · Explain SOC features on FortiAnalyzer
What is the primary function of an 'Indicator' within the FortiAnalyzer SOC module?
Show answer & explanation
Correct answer: B
An Indicator, often called an Indicator of Compromise (IoC), represents a piece of data that signifies a potential threat. This could be a malicious IP, a known bad URL, a file hash of malware, etc. FortiAnalyzer uses these indicators to scan incoming logs and historical data to find matches, which can then be used to generate events or incidents.
- Question 6AdvancedSelect 2
Playbooks · Create and manage playbooks
An organization wants to monitor playbook execution failures. The lead analyst has designed a 'meta-playbook' that should be triggered whenever any other playbook fails. Which two components are required to implement this solution? (Choose two.)
Show answer & explanation
Correct answers: B, C
- Question 7Beginner
Reports · Manage reports
A new SOC analyst is learning how to customize reports. They have been asked to add the company logo and change the color scheme of all generated reports to match corporate branding. Where in the FortiAnalyzer GUI would they configure these settings to apply them globally to all reports?
Show answer & explanation
Correct answer: C
The Output Profile section within the report configuration area is where global branding settings, such as the company logo, report cover page, and color schemes, are defined. Modifying the output profile applies these changes to all reports that use it, ensuring consistent branding.
- Question 8Intermediate
Features and concepts · Describe FortiAnalyzer concepts
An organization has deployed FortiAnalyzer with ADOMs enabled. A junior administrator is granted read-only access to the 'Sales_ADOM'. True or False: This administrator will be able to view the global system performance dashboard under System Settings.
Show answer & explanation
Correct answer: B
Access to global settings, including the system performance dashboard, requires administrative privileges that are not scoped to a specific ADOM. An administrator whose access is restricted to a particular ADOM will not have the necessary permissions to view system-wide settings and performance data.
- Question 9Intermediate
SOC events and incident management · Manage events and event handlers
A SOC team is designing an automated incident response process. They have created an event handler that triggers on high-severity 'Application Vulnerability' events. The desired action is to use a Fabric Connector to add the source IP address of the attack to a block list on the edge FortiGate. Which component orchestrates this action by linking the event handler's trigger to the Fabric Connector's action?
Show answer & explanation
Correct answer: D
An automation stitch is the component within the Fortinet Security Fabric that connects triggers (like a FortiAnalyzer event) to actions (like blocking an IP via a FortiGate connector). While a playbook could also perform this action, the most direct link between a FortiAnalyzer event handler and a Fabric Connector action is an automation stitch. The event handler is configured to 'call' the stitch when it triggers.
- Question 10Advanced
Playbooks · Create and manage playbooks
An analyst has built a complex playbook with multiple conditional branches and API calls to external services. During testing, the playbook fails at an intermediate step, but the execution log does not provide enough detail to diagnose the problem. What is the most effective way to get more detailed, step-by-step information about the playbook's execution, including the data being passed between tasks?
Show answer & explanation
Correct answer: C
FortiAnalyzer provides a debug mode for individual playbooks. When enabled, it generates highly detailed logs for each execution, showing the input and output of every task, the values of all variables at each step, and the evaluation of conditional branches. This is the primary and most effective tool for troubleshooting complex playbook logic.
Ready for the real thing?
The full FCP-FAZ-AN-7-4 simulator has every exam-style question, timed mode, and instant scoring.