FCP_FAZ_AN-7.6: Fortinet NSE 5 - FortiAnalyzer 7.6 Analyst Playbook Practice Questions
The free FCP_FAZ_AN-7.6: Fortinet NSE 5 - FortiAnalyzer 7.6 Analyst questions that deal with playbook, with answers and explanations. The full bank and the timed practice test cover every topic the exam asks about.
Question #2
A playbook contains five tasks in total. An administrator runs the playbook and four out of five tasks finish successfully, but one task fails. What will be the status of the playbook after it is run?
Correct answer: A
Explanation
In FortiAnalyzer, when a playbook is run, each task's status impacts the overall playbook status. Here's what happens based on task outcomes: * Status When All Tasks Succeed: * If all tasks finish successfully, the playbook status ismarked asSuccess. * Status When Some Tasks Fail: * If one or more tasks in the playbook fail, but others succeed, the playbook status generally changes toAttention required. This status indicates that the playbook completed execution but requires review due to one or more tasks failing. * This is different from a completeFailedstatus, which is used if the playbook cannot proceed due to a critical error in an early task, often one that upstream tasks depend on. * Option Analysis: * A. Attention required: This is correct as the playbook has completed, but with partial success and a task requiring review. * B. Upstream_failed: This status is used if a task cannot run because a prerequisite or "upstream" task failed. Since four out of five tasks completed, this is not the case here. * C. Failed: This status would imply that the playbook completely failed, which does not match the scenario where only one task out of five failed. * D. Success: This status would apply if all tasks had completed successfully, which is not the case here. Conclusion: * Correct Answer A. Attention required * The playbook status reflects that it completed, but an error occurred in one of the tasks, prompting the administrator to review the failed task. References: FortiAnalyzer 7.4.1documentation on playbook execution statuses and task error handling.
Question #8
Refer to the exhibit with partial output: Your colleague exported a playbook and has sent it to you for review. You open the file in a text editor and observer the output as shown in the exhibit. Which statement about the export is true?

Correct answer: A
Explanation
In the exhibit, the data structure shows a checksum field and a data field with a long, seemingly encoded string. This format is indicative of a file that has been compressed or encoded for storage and transfer. Export Data Type: The data field is likely a base64-encoded string, which is commonly used to represent binary data in text format. Base64 encoding is often applied to data that has been compressed (zipped) for easier handling and transfer. The checksum field, with an MD5 hash, provides a way to verify the integrity of the data after decompression. Option Analysis: * A. The export data type is zipped: Correct. The compressed and encoded format of the data suggests that the export is in a zipped format, allowing for efficient storage and transfer. * B. The playbook is misconfigured: There is no indication of misconfiguration in this exhibit. The presence of the checksum and data fields aligns with standard export practices. * C. The option to include the connector was not selected: There is no evidence in the output to conclude that connectors are missing. Connectors are typically listed separately and would not directly affect the checksum and encoded data structure. * D. Your colleague put a password on the export: There's no indication of password protection in the exhibit. Password protection would likely alter the data structure, and there would be some mention of encryption. Conclusion: Correct Answer:A. The export data type is zipped. This answer is consistent with the typical use of base64 encoding for compressed (zipped) data exports in FortiAnalyzer. [References:, FortiAnalyzer 7.4.1 documentation on exporting playbooks and data compression methods., ]
Question #9
Exhibit. Assume these are all the events that exist on the FortiAnalyzer device. How many events will be added to the incident created after running this playbook?


Correct answer: D
Explanation
In the exhibit, we see a playbook in FortiAnalyzer designed to retrieve events based on specific criteria, create an incident, and attach relevant data to that incident. The "Get Event" task configuration specifies filters to match any of the following conditions: Severity= High Event Type= Web Filter Tag= Malware Analysis of Events: In the FortiAnalyzer Event Monitor list: We need to identify events that meet any one of the specified conditions (since the filter is set to "Match Any Condition"). Events Matching Criteria: Severity = High: There are two events with "High" severity, both with the "Event Type" IPS. Event Type = Web Filter: There are two events with the "Event Type" Web Filter. One has a "Medium" severity, and the other has a "Low" severity. Tag = Malware: There are two events tagged with "Malware," both with the "Event Type" Antivirus and "Medium" severity. After filtering based on these criteria, there arefour distinct events: Two from the "Severity = High" filter. One from the "Event Type = Web Filter" filter. One from the "Tag = Malware" filter. Conclusion: Correct Answer:D. Four events will be added. This answer matches the conditions set in the playbook filter configuration and the events listed in the Event Monitor. [References:, FortiAnalyzer 7.4.1 documentation on event filtering, playbook configuration, and incident management criteria., ]
Continue with FCP_FAZ_AN-7.6: Fortinet NSE 5 - FortiAnalyzer 7.6 Analyst
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in FCP_FAZ_AN-7.6: Fortinet NSE 5 - FortiAnalyzer 7.6 Analyst, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
All FCP_FAZ_AN-7.6: Fortinet NSE 5 - FortiAnalyzer 7.6 Analyst practice questions →
