What is the recommended method of expanding disk space on a FortiAnalyzer VM?
A. From the VM host manager, add an additional virtual disk and use the #execute lvm extend
B. From the VM host manager, expand the size of the existing virtual disk
C. From the VM host manager, add an additional disk and rebuild your RAID array
D. From the VM host manager, expand the size of the existing virtual disk and use the # execute format disk command to reformat the disk
How can you configure FortiAnalyzer to permit administrator logins from only specific locations?
A. Use trusted hosts
B. Use administrative profiles
C. Use secure protocols
D. Use static routes
View the exhibit.
What does the data point at 14:35 tell you?
A. The sqlplugind daemon is ahead in indexing by one log
B. FortiAnalyzer is indexing logs faster than logs are being received
C. FortiAnalyzer is dropping logs
D. FortiAnalyzer has temporarily stopped receiving logs so older logs can be indexed
You've moved a registered logging device out of one ADOM and into a new ADOM. What happens when you rebuild the new ADOM database?
A. FortiAnalyzer resets the disk quota of the new ADOM to default
B. FortiAnalyzer migrates analytics logs to the new ADOM
C. FortiAnalyzer removes analytics logs from the old ADOM
D. FortiAnalyzer migrates archive logs to the new ADOM
View the exhibit: What does the 1000 MB maximum for disk utilization refer to?
A. The disk quota for each device in the ADOM
B. The disk quota for the ADOM type
C. The disk quota for all devices in the ADOM
D. The disk quota for the FortiAnalyzer model
FortiAnalyzer uses the Optimized Fabric Transfer Protocol (OFTP) over SSL for what purpose?
A. To prevent log modification during backup
B. To send an identical set of logs to a second logging server
C. To encrypt log communication between devices
D. To upload logs to a SFTP server
In order for FortiAnalyzer to collect logs from a FortiGate device, what configuration is required? (Choose two.)
A. ADOMs must be enabled
B. Log encryption must be enabled
C. FortiGate must be registered with FortiAnalyzer
D. Remote logging must be enabled on FortiGate
Which FortiAnalyzer feature allows you to retrieve the archived logs matching a specific timeframe from another FortiAnalyzer device?
A. Log forwarding in aggregation mode
B. Log upload
C. Log fetching
D. Indicators of Compromise
What happens when a log file saved on FortiAnalyzer disks reaches the size specified in the device log settings?
A. The log file is stored as a raw log and is available for analytic support
B. The log file rolls over and is archived
C. The log file is purged from the database
D. The log file is overwritten
What is the purpose of the following CLI command?
A. To add the MD5's hash value and authentication code
B. To encrypt log communications
C. To add a unique tag to each log to provide that it came from this FortiAnalyzer
D. To add a log file checksum
If you upgrade your FortiAnalyzer firmware, what report elements can be affected?
A. Report settings
B. Report scheduling
C. Output profiles
D. Custom datasets
Logs are being deleted from one of your ADOMs earlier than the configured setting for archiving in your data policy. What is the most likely problem?
A. Logs in that ADOM are being forwarded in real-time to another FortiAnalyzer device
B. CPU resources are too high
C. The ADOM disk quota is set too low based on log rates
D. The total disk space is insufficient and you need to add other disk
How does FortiAnalyzer retrieve specific log data from the database?
A. SQL FROM statement
B. SQL GET statement
C. SQL SELECT statement
D. SQL EXTRACT statement
What FortiGate process caches logs when FortiAnalyzer is not reachable?
A. oftpd
B. miglogd
C. sqlplugind
D. logfiled
View the exhibit.
Why is the total quota less than the total system storage?
A. The oftpd process has not archived the logs yet
B. The logfiled process is just estimating the total quota
C. Some space is reserved for system use, such as storage of compression files, upload files, and temporary report files
D. 3.6% of the system storage is already being used