FCP_FAZ_AN-7.6 Sample Questions & Answers
Event handlers, incidents, and FortiAI-driven threat hunting under SOC operations get the heaviest weighting, alongside Security Fabric log collection, FortiView-based log search, and configuring, using, and troubleshooting reports.
Launch the full FCP_FAZ_AN-7.6 simulator →Showing 6 of 12 free samples.
- Question 1Advanced
SOC Operation and Automation · Events and Event Handlers
Case Study:
Scenario
An enterprise uses FortiAnalyzer to manage logs for 50 branches. Each branch has a FortiGate. The SOC team wants to detect a specific attack pattern: 'Multiple failed login attempts followed by a successful login from the same IP within 5 minutes'.Requirements
- Detect the sequence of events.
- Group these events into a single actionable item.
- Minimize noise from random failed logins.
Configuration
- Event Handler A: Detects 'Login Failed' (Count > 5).
- Event Handler B: Detects 'Login Success'.
Which configuration approach best satisfies the requirements?
Show answer & explanation
Correct answer: A
FortiAnalyzer Event Handlers support correlation rules. To detect a specific sequence (brute force success), you must create a correlation handler that looks for the specific sequence of sub-handlers (or log filters) occurring within a defined time window, grouped by the same Source IP. This creates a single event/incident for the entire attack chain.
- Question 2IntermediateSelect 2
Features and Concepts · Log Data Flow, Normalization, and Parsing
Which TWO statements accurately describe the behavior of FortiAnalyzer when operating in 'Collector' mode? (Select TWO)
Show answer & explanation
Correct answers: B, C
In Collector mode, the SQL database daemon (sqlplugind) is disabled, meaning no analytics, reports, or FortiView dashboards are available locally.
Collector mode is designed to receive logs from devices, compress/store them, and forward them to an Analyzer for indexing and reporting. It disables most analytic features like FortiView and Reporting to save resources for high-volume ingestion.
- Question 3Intermediate
Reports · Report Troubleshooting
A custom report using a SQL dataset fails to generate data. The dataset query is:
select * from $log where user = 'marketing'When testing the query in the dataset tester, it returns results. However, when the report runs as a scheduled task, it is empty. What is the most likely cause?
Show answer & explanation
Correct answer: C
Dataset testing usually queries a sample or a broad range. A scheduled report runs for a specific time frame (e.g., 'Last 24 Hours'). If the logs with 'user=marketing' exist outside that specific window, the report will be empty even if the query logic is correct.
- Question 4Intermediate
Reports · Report Configuration
Which SQL function should be used in a dataset query to replace NULL values in a column with a specific string, such as 'Unauthenticated'?
Show answer & explanation
Correct answer: B
The COALESCE(expression1, expression2, ...) function returns the first non-null value in the list. In FortiAnalyzer datasets,
COALESCE(user, 'Unauthenticated')is commonly used to ensure user fields are not empty in charts. - Question 5Beginner
Reports · Report Configuration
True or False: When a report is grouped by 'Device', the FortiAnalyzer generates a single PDF containing data from all devices, but with separate chapters for each device.
Show answer & explanation
Correct answer: B
False. When 'Group by Device' is selected in Report Settings, FortiAnalyzer generates a SEPARATE report file (e.g., separate PDF) for each device, not a single consolidated file with chapters.
- Question 6Intermediate
SOC Operation and Automation · FortiAI and Threat Hunting
An administrator wants to configure an 'Outbreak Alert' to notify the SOC team when a specific zero-day vulnerability is detected in the network. What prerequisite is required for FortiAnalyzer to receive the definition of this outbreak?
Show answer & explanation
Correct answer: A
Outbreak Alerts are a service provided by FortiGuard. FortiAnalyzer downloads these event definitions (similar to signatures) from FortiGuard. Once downloaded, FortiAnalyzer scans local logs to match these specific outbreak parameters.
Ready for the real thing?
The full FCP_FAZ_AN-7.6 simulator has every exam-style question, timed mode, and instant scoring.