1. Which FortiAnalyzer operation mode supports
full features including FortiView, Incidents &
Events, and Reporting?
Correct Answer: B. Analyzer mode
A. Collector mode
Reference: Admin Guide, pp.31–33
Explanation: Analyzer mode is the default, full-featured
mode. Collector mode focuses on archiving and forwarding
logs and disables analytics features.
B. Analyzer mode
C. Monitor mode
D. Passthrough mode
E. Logger-only mode
2. Which panes are NOT available in Collector
mode? (Choose two) (Choose two)
A. FortiView
Correct Answers: A. FortiView, C. Incidents & Events
Explanation: Collector mode disables analytics-centric panes
such as FortiView and Incidents & Events. Device Manager,
Log View (raw archives), and System Settings remain.
Reference: Admin Guide, p.32
B. Log View
C. Incidents & Events
D. Reports
E. Device Manager
F. System Settings
3. Which statement best describes Analytics
(historical) logs in FortiAnalyzer?
Correct Answer: B. Indexed in the SQL database and
online for queries.
A. Uncompressed real-time log files in Archive.
Explanation: Analytics (historical) logs are indexed in the
SQL database, enabling queries and reporting.
Reference: Admin Guide, p.34–36
B. Indexed in the SQL database and online for
queries.
C. Only stored on remote syslog servers.
D. Never compressed or rolled.
4. Before FortiAnalyzer can accept logs from a
device, what must be true?
A. The device must be registered/authorized in
FortiAnalyzer.
B. The device must be placed in a Security
Fabric group first.
C. FortiAnalyzer must be in Collector mode.
D. The device must be in the same subnet as
FortiAnalyzer.
Correct Answer: A. The device must be
registered/authorized in FortiAnalyzer.
Explanation: Devices must be added and authorized before
FAZ accepts their logs.
Reference: Admin Guide, pp.65–68
5. What is the main purpose of Administrative
Domains (ADOMs) in FortiAnalyzer?
Correct Answer: B. Segment admin access to subsets
of devices/VDOMs
A. Accelerate log insertion
Explanation: ADOMs constrain admin access to subsets of
devices or VDOMs.
Reference: Admin Guide, pp.33, 309–318
B. Segment admin access to subsets of
devices/VDOMs
C. Encrypt traffic between devices and
FortiAnalyzer
D. Enable packet capture
6. ADOMs must be enabled to support
logging/reporting for which product families?
(Choose three) (Choose three)
Correct Answers: A. FortiCarrier, B. FortiClient EMS,
C. FortiMail
A. FortiCarrier
Reference: Admin Guide, p.33
Explanation: ADOMs are required for FortiCarrier, FortiClient
EMS, FortiMail, FortiWeb, FortiCache, and FortiSandbox.
B. FortiClient EMS
C. FortiMail
D. FortiSwitch
E. FortiWeb
F. FortiSandbox
7. FortiView dashboards are available in which
operation mode?
Correct Answer: A. Analyzer mode only
Explanation: FortiView is disabled in Collector mode.
Reference: Admin Guide, p.32
A. Analyzer mode only
B. Collector mode only
C. Both Analyzer and Collector
D. Neither
8. Which action is available in Event Monitor for
handling events?
Correct Answer: A. Acknowledge events
A. Acknowledge events
Reference: Admin Guide, pp.176–182
B. Convert events to firewall policies
C. Edit device firmware versions
D. Modify FortiGuard signatures
Explanation: Analysts can acknowledge and assign events
in Event Monitor.
9. Which capabilities are provided by event
handlers in FortiAnalyzer? (Choose two)
(Choose two)
Correct Answers: A. Define conditions to raise events,
C. Trigger notifications (email, SNMP, etc.)
A. Define conditions to raise events
Reference: Admin Guide, pp.182–227
Explanation: Event handlers analyze logs and can trigger
notification profiles.
B. Configure device SNMP communities
C. Trigger notifications (email, SNMP, etc.)
D. Modify FortiOS routing tables
E. Perform firmware upgrades
10. Which two components are central to Threat
Hunting in FortiAnalyzer? (Choose two) (Choose
two)
Correct Answers: A. Log count chart, B. SIEM log
analytics table
A. Log count chart
Reference: Admin Guide, pp.233–235
B. SIEM log analytics table
C. Firmware staging area
D. VPN monitor
E. RAID monitor
Explanation: Threat Hunting leverages the log count chart
and SIEM analytics table.