NSE5-FAZ-7-2 Sample Questions

NSE5-FAZ-7-2 Sample Questions & Answers

Ground covered runs from what FortiAnalyzer is and how logs get analyzed, to handling SOC events and incidents, keeping reports running and fixing them when broken, and putting together playbooks from their components.

Launch the full NSE5-FAZ-7-2 simulator →

Showing 10 of 20 free samples.

  1. Question 1Beginner

    Features and concepts · Describe FortiAnalyzer concepts

    When creating a new ADOM in FortiAnalyzer 7.2, an administrator notices the 'ADOM Mode' option. What is the primary purpose of setting the ADOM Mode to 'Advanced'?

    Show answer & explanation

    Correct answer: B

    The 'Advanced' ADOM mode is specifically designed to support devices running different major firmware versions within a single ADOM. This is useful in environments with a mix of FortiOS versions, although it may limit the visibility of certain version-specific features. The 'Normal' mode restricts the ADOM to devices of the same major firmware version.

  2. Question 2Intermediate

    SOC · Explain SOC features on FortiAnalyzer

    An analyst is reviewing the 'Compromised Hosts' list in the FortiView dashboard. They notice a host with a high threat score and several Indicators of Compromise (IOCs) listed. What is the primary source of the IOC data used by FortiAnalyzer to identify these compromised hosts?

    Show answer & explanation

    Correct answer: B

    The 'Compromised Hosts' feature primarily relies on the FortiGuard Outbreak Detection Service (previously known as the IOC service). FortiAnalyzer downloads a package of IOCs from FortiGuard and scans incoming logs for matches. When a log entry matches a known indicator of compromise, the source IP is flagged and added to the Compromised Hosts list.

  3. Question 3IntermediateSelect 2

    Playbooks · Create and manage playbooks

    A new SOC analyst is tasked with creating a playbook that performs the following actions upon detecting a high-severity IPS event:

    1. Retrieve the source IP address from the event log.
    2. Query a third-party threat intelligence service (via API) to check the IP's reputation.
    3. If the reputation is 'malicious', add the IP to a specific address group on the edge FortiGate to block it.

    Which two playbook components are essential for this workflow? (Choose two.)

    Show answer & explanation

    Correct answers: A, C

    This workflow requires two key integrations: 1) An HTTP connector is needed to make an API call to the external threat intelligence service. 2) A FortiGate connector is required to interact with the FortiGate device and add the malicious IP to the specified address group for blocking.

  4. Question 4Intermediate

    Logging · Describe log fetching

    An administrator is configuring log fetching for a remote FortiGate. They want to ensure that if the connection between the FortiGate and FortiAnalyzer is interrupted, logs are buffered on the FortiGate and sent later when the connection is restored. Which FortiGate setting is required to enable this behavior?

    Show answer & explanation

    Correct answer: B

    On the FortiGate, under the config log fortianalyzer setting, the upload-option must be set to store-and-upload. This enables the reliable logging feature, where logs are stored locally on the FortiGate's disk if the FortiAnalyzer is unreachable. Once the connection is re-established, the buffered logs are uploaded.

  5. Question 5Advanced

    Playbooks · Create and manage playbooks

    A SOC analyst is debugging a playbook that is failing at a specific task. The task is supposed to extract a username from a log field and use it in a subsequent API call. The Playbook Monitor shows an error at the API call task. How can the analyst verify the value of the username variable as it was extracted in the preceding task?

    Show answer & explanation

    Correct answer: D

    The Playbook Monitor provides detailed execution logs for each playbook run. To debug variable values, an analyst can navigate to the specific failed run, find the task that was supposed to extract the username, and expand its details. The 'Output' section for that task will show the exact values that were produced and passed on as variables to subsequent tasks, allowing the analyst to confirm if the extraction was successful or if the value was malformed.

  6. Question 6Beginner

    SOC · Manage incidents

    A junior analyst has created an incident for a potential malware infection. The incident has been assigned to a senior analyst for investigation. The senior analyst reviews the incident, confirms it was a false positive, and adds a comment explaining their findings. What is the correct next step in the incident lifecycle for the senior analyst to perform?

    Show answer & explanation

    Correct answer: D

    Proper incident lifecycle management requires that all incidents are tracked to completion. After an investigation is complete, the correct procedure is to close the incident and set an appropriate resolution status, such as 'Resolved', 'False Positive', or 'Remediated'. This provides an audit trail and metrics for SOC performance. Deleting the incident would erase this valuable record.

  7. Question 7Advanced

    Reports · Troubleshoot reports

    A scheduled report on FortiAnalyzer fails to generate. When troubleshooting, the analyst finds the following error in the report's diagnostic logs: hcache data is not ready. What is the most likely cause of this error?

    Show answer & explanation

    Correct answer: C

    The hcache (historical cache) is used by FortiAnalyzer's auto-cache feature to pre-process data for faster report generation. The error hcache data is not ready indicates that the scheduled report attempted to run before the underlying auto-cache job for its datasets was finished. This can happen if the cache generation takes longer than the interval between report runs.

  8. Question 8Intermediate

    Logging · Gather log statistics

    What is the function of the log-insert-lag-time value displayed in the System Settings dashboard widgets?

    Show answer & explanation

    Correct answer: B

    The log-insert-lag-time is a key performance indicator for the FortiAnalyzer's logging daemon. It represents the time difference between a log's arrival at the FortiAnalyzer and its successful insertion into the analytics SQL database. A consistently high lag time indicates that the FortiAnalyzer is struggling to keep up with the log rate, potentially due to high I/O wait or CPU load.

  9. Question 9Intermediate

    SOC · Explain SOC features on FortiAnalyzer

    True or False: The 'Threat Hunting' feature in FortiSoC allows analysts to proactively search for threats using Indicators of Compromise (IOCs) but does not support searches based on MITRE ATT&CK techniques.

    Show answer & explanation

    Correct answer: B

    This statement is false. The Threat Hunting feature in FortiAnalyzer 7.2 provides pre-defined queries that analysts can run against their log data. These queries are categorized and mapped to both Indicators of Compromise (IOCs) and specific MITRE ATT&CK techniques, allowing analysts to hunt for threats based on known adversary tactics and behaviors.

  10. Question 10Advanced

    SOC · Manage incidents

    Case Study:

    A retail company, 'ShopSecure', uses FortiAnalyzer 7.2 to centrally log events from FortiGates at its headquarters and multiple store locations. The security team is small, and they are struggling to keep up with the volume of alerts. The CISO has mandated a new process: any event indicating a connection to a known Command and Control (C2) server must be immediately investigated and an incident must be created with a 'Critical' priority.

    The current 'Botnet C&C' event handler is enabled and generates events, but analysts must manually review these events, decide if they are actionable, and then manually create an incident. This delay is no longer acceptable. The CISO wants this entire process, from event generation to incident creation, to be fully automated.

    As the lead SOC analyst, you are tasked with implementing this automation. Which of the following solutions best meets the CISO's requirements using FortiAnalyzer's native capabilities?

    Show answer & explanation

    Correct answer: C

    FortiAnalyzer provides a native, direct way to automate incident creation from events without needing a playbook for this simple action. By editing the event handler itself, you can configure it to automatically create an incident whenever the event is triggered. This is the most direct and efficient method. While a playbook could achieve this, it adds unnecessary complexity for a simple 'event-to-incident' workflow that is built directly into the event handler's notification options.

Ready for the real thing?

The full NSE5-FAZ-7-2 simulator has every exam-style question, timed mode, and instant scoring.