Free FCP_FAZ_AD-7.4 Exam Braindumps (page: 11)

Page 10 of 44

Which daemon is responsible for enforcing raw log file size?

  1. logfiled
  2. oftpd
  3. sqlplugind
  4. miglogd

Answer(s): A



An administrator has configured the following settings:

config system global set log-checksum md5-auth end

What is the significance of executing this command?

  1. This command records the log file MD5 hash value.
  2. This command records passwords in log files and encrypts them.
  3. This command encrypts log transfer between FortiAnalyzer and other devices.
  4. This command records the log file MD5 hash value and authentication code.

Answer(s): D


Reference:

https://docs.fortinet.com/document/fortianalyzer/6.4.6/administration- guide/410387/appendix-b-log-integrity-and-secure-log-transfer



Which two of the following must you configure on FortiAnalyzer to email a FortiAnalyzer report externally?

(Choose two.)

  1. Mail server
  2. Output profile
  3. SFTP server
  4. Report scheduling

Answer(s): A,B


Reference:

https://docs.fortinet.com/document/fortianalyzer/6.0.2/administration- guide/598322/creating-output-profiles



For which two purposes would you use the command set log checksum? (Choose two.)

  1. To help protect against man-in-the-middle attacks during log upload from FortiAnalyzer to an SFTP server
  2. To prevent log modification or tampering
  3. To encrypt log communications
  4. To send an identical set of logs to a second logging server

Answer(s): A,B

Explanation:

To prevent logs from being tampered with while in storage, you can add a log checksum using the config system global command. You can configure FortiAnalyzer to record a log file hash value, timestamp, and authentication code when the log is rolled and archived and when the log is uploaded (if that feature is enabled). This can also help against man-in-the-middle only for the transmission from FortiAnalyzer to an

SSH File Transfer Protocol (SFTP) server during log upload.

FortiAnalyzer_7.0_Study_Guide-Online page 149






Post your Comments and Discuss Fortinet FCP_FAZ_AD-7.4 exam with other Community members:

FCP_FAZ_AD-7.4 Discussions & Posts