FCP_FAZ_AN-7.6試験問題集合格できるには更新された2026年08月テスト問題集 [Q41-Q64]

Share

FCP_FAZ_AN-7.6試験問題集合格できるには更新された2026年08月テスト問題集

FCP_FAZ_AN-7.6テスト問題練習は2026年最新のに更新された81問あります


Fortinet FCP_FAZ_AN-7.6 認定試験の出題範囲:

トピック出題範囲
トピック 1
  • ログ分析:この領域では、FortiViewダッシュボードとウィジェットを使用してログ、イベント、インシデントを調査および解釈し、データ視覚化を行い、レポート生成の問題を診断することに重点を置いています。
トピック 2
  • 機能と概念:この領域では、ログ収集のためのFortiAnalyzerとSecurity Fabricの統合、ログデータの流れ、正規化、解析の技術プロセス、およびセキュリティ監視と分析に利用できるSOC機能について説明します。
トピック 3
  • SOCの運用と自動化:この領域では、イベントとイベントハンドラーの設定、脅威追跡のためのインシデントとインジケーターの設定、オーケストレーションされた対応のためのプレイブックとファブリック自動化の設定、および自動化ワークフローの問題のトラブルシューティングについて説明します。
トピック 4
  • レポート:このドメインでは、セキュリティインテリジェンスを提示するためのレポート、チャート、データセットの使用方法について説明し、組織の要件を満たすためのレポート構成、およびレポート生成の問題のトラブルシューティングについても取り上げます。

 

質問 # 41
When managing incidents on FortiAnlyzer, what must an analyst be aware of?

  • A. You can manually attach generated reports to incidents.
  • B. Incidents must be acknowledged before they can be analyzed.
  • C. The status of the incident is always linked to the status of the attach event.
  • D. Severity incidents rated with the level High have an initial service-level agreement (SLA) response time of 1 hour.

正解:A

解説:
You can attach reports to incidents to add historical data in addition to real-time events.
These are the three ways that you can attach a report:
* Manually, from an existing report
* Manually, from an existing incident
* Automatically, through automation playbooks


質問 # 42
Which three tasks can be performed on FortiAnalyzer using FortiAI? (Choose three.)

  • A. Identify potential impacts and recommended remediation.
  • B. Perform threat hunting.
  • C. Configure site-to-site VPN using FortiAI
  • D. Configure SD-WAN overlay using FortiAI

正解:A、B

解説:
FortiAI on FortiAnalyzer assists analysts by identifying potential impacts of detected threats and providing recommended remediation guidance. It also supports threat hunting by enabling natural language queries to analyze logs and uncover suspicious activity. Configuration tasks such as SD-WAN or VPN setup are not performed through FortiAI.


質問 # 43
Which FortiAnalyzer feature allows you to use a proactive approach when managing your network security?

  • A. Threat hunting
  • B. Incidents dashboard
  • C. FortiView Monitor
  • D. Outbreak alert services

正解:A

解説:
FortiAnalyzer offers several features for monitoring, alerting, and incident management, each serving different purposes.
Option D - Threat Hunting:
Threat Hunting in FortiAnalyzer enables security analysts to actively search for hidden threats or malicious activities within the network by leveraging historical data, analytics, and intelligence.
This is a proactive approach as it allows analysts to seek out threats before they escalate into incidents.


質問 # 44
You created a playbook on FortiAnalyzer that uses a FortiOS connector.
When you configure FortiGate, which type of trigger must you use so that the actions in an automation stitch are available in the FortiOS connector?

  • A. Incoming webhook
  • B. IP ban
  • C. Fabric Connector event
  • D. FortiAnalyzer Event Handler

正解:A

解説:
FortiOS connector will be listed as soon as the first FortiGate is added to FortiAnalyzer.
However, in order to see the actions related to that FortiOS connector, you must enable an automation rule using the Incoming Webhook Call trigger on the FortiGate side.


質問 # 45
Exhibit. What is the analyst trying to create?

  • A. The analyst is trying to create a trigger variable to the used in the playbook.
  • B. The analyst is trying to create an output variable to be used in the playbook.
  • C. The analyst is trying to create a report in the playbook.
  • D. The analyst is trying to create a SOC report in the playbook.

正解:B

解説:
In the exhibit, the playbook configuration shows the analyst working with the "Attach Data" action within a playbook. Here's a breakdown of key aspects:
Incident ID: This field is linked to the "Playbook Starter," which indicates that the playbook will attach data to an existing incident.
Attachment: The analyst is configuring an attachment by selecting Run_REPORT with a placeholder ID for report_uuid. This suggests that the report's UUID will dynamically populate as part of the playbook execution.
Option B - Creating an Output Variable:
The field Attachment with a report_uuid placeholder suggests that the analyst is defining an output variable that will store the report data or ID, allowing it to be attached to the incident. This variable can then be referenced or passed within the playbook for further actions or reporting.


質問 # 46
Which statement regarding macros on FortiAnalyzer is true?

  • A. Macros are ADOM-specific and each ADOM type have unique macros relevant to that ADOM.
  • B. Macros are supported only on the FortiGate ADOMs.
  • C. Macros are useful in generating excel log files automatically based on the report settings.
  • D. Macros are predefined templates for reports and cannot be customized.

正解:C

解説:
Macros in FortiAnalyzer are used to streamline reporting tasks by automating data extraction and report generation. Here's a breakdown of each option to determine the correct answer:
* Option A - Macros are Predefined Templates for Reports and Cannot be Customized:
* This statement is incorrect. Macros in FortiAnalyzer are not simply fixed templates; they allow for customization to tailor data extraction and reporting based on specific needs and configurations.
* Conclusion: Incorrect.
* Option B - Macros are Useful in Generating Excel Log Files Automatically Based on the Report Settings:
* This statement is accurate. Macros in FortiAnalyzer can be configured to automate the generation of reports, including outputting log data to Excel format based on predefined report settings. This makes them especially useful for scheduled reporting and data analysis.
* Conclusion: Correct.
* Option C - Macros are ADOM-Specific and Each ADOM Type Has Unique Macros Relevant to that ADOM:
* Macros are not limited to specific ADOMs, nor are they ADOM-specific. Macros can be applied across various ADOMs based on report configurations but are not inherently tied to or unique for each ADOM type.
* Conclusion: Incorrect.
* Option D - Macros are Supported Only on the FortiGate ADOMs:
* This is not true. Macros in FortiAnalyzer are not restricted to FortiGate ADOMs; they can be utilized across different ADOMs that FortiAnalyzer manages.
* Conclusion: Incorrect.
Conclusion:
* Correct Answer: B. Macros are useful in generating excel log files automatically based on the report settings.
* This answer correctly describes the functionality of macros in FortiAnalyzer, emphasizing their role in automating report generation, especially for Excel log files.
References:
FortiAnalyzer 7.4.1 documentation on macros and report generation functionalities.


質問 # 47
What are the two methods you can use to send notifications when an event is generated by an event handler?
(Choose two answers)

  • A. Send an alert through the FortiGuard server.
  • B. Send SNMP trap.
  • C. Send an alert through Fabric connectors.
  • D. Send SMS notification

正解:B、C

解説:
Exact Extract: Study Guide p.78: event handlers can use notification profiles; p.107 describes external notifications through Fabric connectors.
Technical Deep Dive: The correct answers are A and C. When an event handler generates an event, FortiAnalyzer can use notification mechanisms such as SNMP traps through notification profiles.
FortiAnalyzer also supports sending alerts to external platforms using configured Fabric connectors.
FortiGuard is not an alert delivery server in this workflow; it supplies threat intelligence and outbreak content.
SMS notification is not one of the event-handler notification methods described in the guide sections relevant to this question.


質問 # 48
An administrator on your team has configured multiple reports to run periodically. Management has an additional request that all new generated reports be sent to a company email inbox for accessibility. The mail server has already been configured on FortiAnalyzer.
Which item must configure on FortiAnalyzer so that emails are sent when the reports are generated?

  • A. Add a mailto: < email address > option within the report layouts.
  • B. Enable the option to email all reports under the mail server.
  • C. Enable email notification under the report calendar.
  • D. Enable an output profile on the reports.

正解:D

解説:
Exact Extract: Study Guide p.181: output profiles specify report format and whether to email or upload generated reports.
Technical Deep Dive: The correct answer is D. The mail server being configured only gives FortiAnalyzer the ability to send email. To send generated reports automatically, the report must use an output profile that defines the delivery method and recipients or upload target. Option A is not a report-level distribution setting.
Option B confuses report layout content with report delivery. Option C is wrong because the report calendar shows scheduled report status; scheduling and distribution are configured in the report settings and output profile.


質問 # 49
Which two statements regarding FortiAnalyzer operating modes are true? (Choose two.)

  • A. A topology with FortiAnalyzeer devices running in both modes can improve their performance.
  • B. When running in collector mode, FortiAnalyzer can forward logs to a syslog server.
  • C. You can create and edit reports when FortiAnalyzer is running in collector mode.
  • D. FortiAnalyzer runs in collector mode by default unless it is configured for HA.

正解:A、D

解説:
FortiAnalyzer has two primary operating modes: Analyzer mode and Collector mode. Each mode serves specific purposes and has distinct capabilities.
Option B - Default Mode is Collector Mode Unless Configured for HA:
When a FortiAnalyzer is initially set up, it runs in Collector mode by default unless it is configured as part of a High Availability (HA) setup, which would set it to Analyzer mode. Collector mode prioritizes log collection and storage rather than analysis, offloading analysis to other devices in the network.
Option D - Performance Improvement with Both Modes in Topology:
Deploying FortiAnalyzer devices in both Collector and Analyzer modes in a network topology can enhance performance. Collector mode devices handle log collection, reducing the workload on Analyzer mode devices, which focus on log processing, analysis, and reporting. This separation of tasks can optimize resource usage and improve the overall efficiency of log management.


質問 # 50
Which two statements about local logs on FortiAnalyzer are true? (Choose two.)

  • A. You can view playbook logs for all ADOMs in the root ADOM.
  • B. Event logs are available only in the root ADOM.
  • C. They are not supported in FortiView.
  • D. Event logs show system-wide information, whereas application logs are ADOM specific.

正解:A、D

解説:
Playbook logs, which relate to automated incident response actions, can be viewed centrally in the root ADOM, allowing visibility across all ADOMs.
Event logs on FortiAnalyzer typically provide system-wide information applicable to the entire FortiAnalyzer unit, while application logs are specific to each ADOM, reflecting the logs related to devices and activities managed within that ADOM.
https://docs.fortinet.com/document/fortianalyzer/7.6.3/administration-guide/208717/enabling-and- disabling-the-adom-feature


質問 # 51
Which two actions should an administrator take to vide Compromised Hosts on FortiAnalyzer? (Choose two.)

  • A. Make sure all endpoints are reachable by FortiAnalyzer.
  • B. Enable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent to fortiAnalyzer.
  • C. Subscribe FortiAnalyzer to FortiGuard to keep its local threat database up to date.
  • D. Enable device detection on the FotiGate device that are sending logs to FortiAnalyzer.

正解:B、D

解説:
To view Compromised Hosts on FortiAnalyzer, certain configurations need to be in place on both FortiGate and FortiAnalyzer. Compromised Host data on FortiAnalyzer relies on log information from FortiGate to analyze threats and compromised activities effectively. Here's why the selected answers are correct:
* Option A: Enable device detection on the FortiGate devices that are sending logs to FortiAnalyzer
* Enabling device detection on FortiGate allows it to recognize and log devices within the network, sending critical information about hosts that could be compromised. This is essential because FortiAnalyzer relies on these logs to determine which hosts may be at risk based on suspicious activities observed by FortiGate. This setting enables FortiGate to provide device-level insights, which FortiAnalyzer uses to populate the Compromised Hosts view.
* Option B: Enable web filtering in firewall policies on FortiGate devices, and make sure these logs are sent to FortiAnalyzer
* Web filtering is crucial in identifying potentially compromised hosts since it logs any access to malicious sites or blocked categories. FortiAnalyzer uses these web filter logs to detect suspicious or malicious web activity, which can indicate compromised hosts. By ensuring that FortiGate sends these web filtering logs to FortiAnalyzer, the administrator enables FortiAnalyzer to analyze and identify hosts engaging in risky behavior.
Let's review the other options for clarity:
* Option C: Make sure all endpoints are reachable by FortiAnalyzer
* This is incorrect. FortiAnalyzer does not need direct access to all endpoints. Instead, it collects data indirectly from FortiGate logs. FortiGate devices are the ones that interact with endpoints and then forward relevant logs to FortiAnalyzer for analysis.
* Option D: Subscribe FortiAnalyzer to FortiGuard to keep its local threat database up to date
* Although subscribing to FortiGuard helps keep threat intelligence updated, it is not a requirement specifically to view compromised hosts. FortiAnalyzer primarily uses logs from FortiGate (such as web filtering and device detection) to detect compromised hosts.
* According to FortiOS and FortiAnalyzer documentation, device detection on FortiGate and enabling web filtering logs are both recommended steps for populating the Compromised Hosts view on FortiAnalyzer.
These logs provide insights into device behaviors and web activity, which are essential for identifying and tracking potentially compromised hosts.


質問 # 52
Which three tasks can be performed on FortiAnalyzer using FortiAI? (Choose three.)

  • A. Perform threat hunting.
  • B. Configure SD-WAN overlay using FortiAI.
  • C. Identify potential impacts and recommend remediation.
  • D. Configure site-to-site VPN using FortiAI.
  • E. Perform Incident investigation and response.

正解:A、C、E

解説:
Exact Extract: Study Guide p.120: FortiAI can support incident investigation, response, threat hunting, impact analysis, and remediation recommendations.
Technical Deep Dive: The correct answers are B, C, and E. FortiAI in FortiAnalyzer is designed to assist SOC workflows: interpreting security events, generating incident summaries, identifying possible impacts, recommending remediation, generating queries, and supporting threat hunting. Site-to-site VPN and SD- WAN overlay configuration are FortiGate/FortiManager network configuration tasks, not the FortiAnalyzer FortiAI use cases described in the Analyst guide. The guide keeps FortiAI scoped to FortiAnalyzer security operations and analytics workflows.


質問 # 53
Refer to the exhibit. What can you conclude about these search results? (Choose two.)

  • A. The logs have been parsed by FortiGate log parser.
  • B. They were searched using text mode.
  • C. They are sortable by columns and customizable.
  • D. They can be downloaded to a CSV file.

正解:B、D

解説:
The detailed, unstructured text format of the search results indicates the use of text mode.
Text mode search results in FortiAnalyzer can be exported or downloaded as a file for further analysis.


質問 # 54
Which statement regarding macros on FortiAnalyzer is true?

  • A. Macros are useful in generating excel log files automatically based on the report settings.
  • B. Macros are ADOM-specific and each ADOM type have unique macros relevant to that ADOM.
  • C. Macros are supported only on the FortiGate ADOMs.
  • D. Macros are predefined templates for reports and cannot be customized.

正解:B

解説:
Macros on FortiAnalyzer are predefined or custom query templates used in reports, and they are organized by ADOM (Administrative Domain). When using ADOMs, you must be in the correct ADOM to create or manage macros, indicating that macros are ADOM-specific and tailored to the device types or datasets relevant to that ADOM.
https://docs.fortinet.com/document/fortianalyzer/7.6.3/administration-guide/617380/creating- macros


質問 # 55
Which statement about sending notifications with incident update is true?

  • A. If you use multiple fabric connectors, all connectors must have the same settings.
  • B. Notifications can be sent only when an incident is updated or deleted.
  • C. Notifications can be sent only by email.
  • D. You can send notifications to multiple external platforms.

正解:D

解説:
In FortiOS and FortiAnalyzer, incident notifications can be sent to multiple external platforms, not limited to a single method such as email. Fortinet's security fabric and integration capabilities allow notifications to be sent through various fabric connectors and third-party integrations. This flexibility is designed to ensure that incident updates reach relevant personnel or systems using preferred communication channels, such as email, Syslog, SNMP, or integration with SIEM platforms.
Let's review each answer option for clarity:
* Option A: You can send notifications to multiple external platforms
* This is correct. Fortinet's notification system is capable of sending updates to multiple platforms, thanks to its support for fabric connectors and external integrations. This includes options such as email, Syslog, SNMP, and others based on configured connectors.
* Option B: Notifications can be sent only by email
* This is incorrect. Although email is a common method, FortiOS and FortiAnalyzer support multiple notification methods through various connectors, allowing notifications to be directed to different platforms as per the organization's setup.
* Option C: If you use multiple fabric connectors, all connectors must have the same settings
* This is incorrect. Each fabric connector can have its unique configuration, allowing different connectors to be tailored for specific notification and integration requirements.
* Option D: Notifications can be sent only when an incident is updated or deleted
* This is incorrect. Notifications can be sent upon the creation of incidents, as well as upon updates or deletion, depending on the configuration.
* According to FortiOS and FortiAnalyzer 7.4.1 documentation, notifications for incidents can be configured across various platforms by using multiple connectors, and they are not limited to email alone. This capability is part of the Fortinet Security Fabric, allowing for a broad range of integrations with external systems and platforms for effective incident response.


質問 # 56
Exhibit.

Which statement about the event displayed is correct?

  • A. An incident was created from this event.
  • B. The security event risk is considered open.
  • C. The security risk was blocked or dropped.
  • D. The risk source is isolated.

正解:B


質問 # 57
What is the purpose of running the command diagnose sql status sqlreportd?

  • A. To list the current SQL processes running
  • B. To view a list of scheduled reports
  • C. To display the SQL query connections and hcache status
  • D. To identify the database log insertion status

正解:C

解説:
The command diagnose sql status sqlreportd is used in FortiAnalyzer to obtain specific information about the SQL reporting process and caching status. Here's what this command accomplishes and an analysis of each option:
Command Functionality:
sqlreportd is the FortiAnalyzer daemon responsible for managing SQL-based reporting processes. The diagnose sql status sqlreportd command provides information on active SQL query connections and the hcache (historical cache) status, which helps in monitoring and troubleshooting SQL report generation.


質問 # 58
Refer to the exhibit. What can you conclude about the output?

  • A. The output is ADOM specific.
  • B. The message rate being higher than the log rate is not normal.
  • C. There are more traffic logs than event logs.
  • D. Both messages and logs are almost finished indexing.

正解:D

解説:
The commands shown are:
diagnose fortilogd lograte → shows the log receiving/indexing rate
diagnose fortilogd msgrate → shows the message processing rate
In the output, both rates are very low over the last 5, 30, and 60 seconds. This indicates that FortiAnalyzer is almost finished processing (indexing) incoming logs and messages, with no significant backlog.


質問 # 59
Which log will generate an event with the status Contained?

  • A. An AV log with action=quarantine.
  • B. An AppControl log with action=blocked.
  • C. A WebFilter log with action=dropped.
  • D. An IPS log with action=pass.

正解:A

解説:
Exact Extract: Study Guide p.82: Contained means the risk source is isolated; antivirus quarantine is the example.
Technical Deep Dive: The correct answer is A. An AV log with action=quarantine indicates the detected file or object has been isolated, so FortiAnalyzer classifies the event status as Contained. An IPS action=pass is Unhandled because the risk was not stopped. WebFilter dropped and AppControl blocked are enforcement outcomes, so they align with Mitigated rather than Contained. The distinction matters in SOC triage because Contained still deserves review, but the immediate source/object has already been isolated.


質問 # 60
Exhibit.

What can you conclude about these search results? (Choose two.)

  • A. They are not available for analysis in FortiView.
  • B. They were searched by using text mode.
  • C. They can be downloaded to a file.
  • D. They are sortable by columns and customizable.

正解:B、C

解説:
Exact Extract: Study Guide p.58: Log View search results can be downloaded, and raw/text filtering helps with exact field syntax.
Technical Deep Dive: The correct answers are A and D. FortiAnalyzer Log View allows administrators to download filtered logs as text or CSV, so the displayed search results can be exported to a file. The exhibit also indicates a text-mode search/filter rather than a purely GUI-built filter. Option B would be true for formatted log tables in general, but the question asks what can be concluded from the displayed search results.
Option C is not supported; whether FortiView can analyze related data depends on whether the logs are analytics logs, not merely on the search display.


質問 # 61
Which two statements about exporting and importing playbacks are true? (Choose two.)

  • A. You can import a playbook even if there is another one win the same name in the destination
  • B. You can export only one playbook at a time.
  • C. Playbooks can so imported 10 a different FortiAnayzer device, but only if the connectors already exist
  • D. A playbook that was disabled when it was exported mil be disabled when it is imported.

正解:C、D


質問 # 62
Exhibit. Assume these are all the events that exist on the FortiAnalyzer device. How many events will be added to the incident created after running this playbook?

  • A. Eleven events will be added.
  • B. No events will be added.
  • C. Seven events will be added
  • D. Four events will be added.

正解:D

解説:
In the exhibit, we see a playbook in FortiAnalyzer designed to retrieve events based on specific criteria, create an incident, and attach relevant data to that incident. The "Get Event" task configuration specifies filters to match any of the following conditions:
Severity = High
Event Type = Web Filter
Tag = Malware
Analysis of Events:
In the FortiAnalyzer Event Monitor list:
We need to identify events that meet any one of the specified conditions (since the filter is set to
"Match Any Condition").
Events Matching Criteria:
Severity = High:
There are two events with "High" severity, both with the "Event Type" IPS.
Event Type = Web Filter:
There are two events with the "Event Type" Web Filter. One has a "Medium" severity, and the other has a "Low" severity.
Tag = Malware:
There are two events tagged with "Malware," both with the "Event Type" Antivirus and "Medium" severity.
After filtering based on these criteria, there are four distinct events:
Two from the "Severity = High" filter.
One from the "Event Type = Web Filter" filter.
One from the "Tag = Malware" filter.


質問 # 63
Exhibit.

What is the analyst trying to create?

  • A. The analyst is trying to create a trigger variable to the used in the playbook.
  • B. The analyst is trying to create an output variable to be used in the playbook.
  • C. The analyst is trying to create a report in the playbook.
  • D. The analyst is trying to create a SOC report in the playbook.

正解:B

解説:
Exact Extract: Study Guide p.211: output variables use the output from a preceding task as input to the current task.
Technical Deep Dive: The correct answer is B. The exhibit shows the analyst referencing output from an earlier task, such as a generated report identifier, so a later task can attach that result to an incident. That is an output variable. A trigger variable would pull values from the event or incident that started the playbook. The analyst is not creating the report object itself, nor creating a SOC report definition; the report task has already produced data, and the current task is consuming that output dynamically.


質問 # 64
......

正真正銘のFCP_FAZ_AN-7.6問題集には100%合格率練習テスト問題集:https://www.passtest.jp/Fortinet/FCP_FAZ_AN-7.6-shiken.html

更新されたプレミアムFCP_FAZ_AN-7.6試験エンジンPDF:https://drive.google.com/open?id=1afFlsimSaNu1Bb72cCE2jOxC9024Y1Hw