Free NSE5_FAZ-7.2 Exam Braindumps (page: 17)

Page 16 of 35

Which statements are true regarding securing communications between FortiAnalyzer and FortiGate with IPsec? (Choose two.)

  1. Must configure the FortiAnalyzer end of the tunnel only--the FortiGate end is auto-negotiated.
  2. Must establish an IPsec tunnel ID and pre-shared key.
  3. IPsec cannot be enabled if SSL is enabled as well.
  4. IPsec is only enabled through the CLI on FortiAnalyzer.

Answer(s): B,D

Explanation:

Option B is correct because you must establish an IPsec tunnel ID and pre-shared key to secure the communication between FortiAnalyzer and FortiGate with IPsec12. The tunnel ID is a unique identifier for each tunnel and the pre-shared key is a secret passphrase that authenticates the peers.

Option D is correct because IPsec is only enabled through the CLI on FortiAnalyzer1. You cannot configure IPsec settings through the GUI on FortiAnalyzer.



Which two statements about log forwarding are true? (Choose two.)

  1. Forwarded logs cannot be filtered to match specific criteria.
  2. Logs are forwarded in real-time only.
  3. The client retains a local copy of the logs after forwarding.
  4. You can use aggregation mode only with another FortiAnalyzer.

Answer(s): C,D

Explanation:

https://docs.fortinet.com/document/fortianalyzer/6.2.5/administration-guide/420493/modes https://docs.fortinet.com/document/fortianalyzer/6.2.5/administration-guide/621804/log- forwarding



Which two methods can you use to send event notifications when an event occurs that matches a configured event handler? (Choose two.)

  1. SMS
  2. Email
  3. SNMP
  4. IM

Answer(s): B,C


Reference:

https://help.fortinet.com/fa/faz50hlp/60/6-0-2/Content/FortiAnalyzer_Admin_Guide/1800_Events/0200_Event_handlers/0600_Create_event_handlers.htm


https://help.fortinet.com/fa/faz50hlp/60/6-0- 2/Content/FortiAnalyzer_Admin_Guide/1800_Events/0200_Event_handlers/0600_Create_event_ha ndlers.htm



Consider the CLI command:



What is the purpose of the command?

  1. To add a unique tag to each log to prove that it came from this FortiAnalyzer
  2. To add the MD5 hash value and authentication code
  3. To add a log file checksum
  4. To encrypt log communications

Answer(s): C

Explanation:

https://docs.fortinet.com/document/fortianalyzer/6.2.5/cli-reference/849211/global






Post your Comments and Discuss Fortinet NSE5_FAZ-7.2 exam with other Community members:

NSE5_FAZ-7.2 Discussions & Posts