Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam NSE5_FAZ-7.2 topic 1 question 5 discussion

Actual exam question from Fortinet's NSE5_FAZ-7.2
Question #: 5
Topic #: 1
[All NSE5_FAZ-7.2 Questions]

What must you consider when using log fetching? (Choose two.)

  • A. The fetch client can retrieve logs from devices that are not added to its local Device Manager.
  • B. You can use filters to include only logs from a single device.
  • C. The fetching profile must include a user with the Super_User profile.
  • D. The archive logs retrieved from the server become archive logs in the client.
Show Suggested Answer Hide Answer
Suggested Answer: AB 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
fc58c80
2 weeks, 5 days ago
Possible answer as to why D is not correct: When you fetch archived logs from the server, its done for the purpose of analyzing and/or running reports on them. I believe the client stores these archived logs separately from its own normal archived logs, and manages them independently.
upvoted 1 times
...
alejandro1985
4 weeks, 1 day ago
Selected Answer: BD
B and D are correct. Ref: FortiAnalyzer_7.4_Analyst_Study_Guide-Online.pdf pag 84
upvoted 1 times
Alexh07
4 weeks ago
Please, could you indicate the precise justification for option D in FortiAnalyzer_7.4_Analyst_Study_Guide-Online.pdf page 84?
upvoted 1 times
...
...
Alexh07
1 month ago
Selected Answer: BC
A. (F) In FortiAnalyzer Analyst 7.2 Study Guide, p. 78 indicates that it must be the Device Manager but not necessarily a Local Device Manager. B. (V) In FortiAnalyzer Analyst 7.2 Study Guide, p. 78 indicates that you can choose filters that include logs from specific devices (it can be a single device) C. (V) In FortiAnalyzer Analyst 7.2 Study Guide, p. 77 indicates in the image of point number one that "must have Super_User or Standard_User profile" D. (F) In FortiAnalyzer Analyst 7.2 Study Guide, p. 77 indicates the following statement "The FortiAnalyzer device that fetches logs operates as the fetch client, and the other Fortinalyzer device that send logs operates as the fetch server". They focus on the devices, they never mention such terms for archive logs.
upvoted 1 times
fc58c80
2 weeks, 1 day ago
for option D, page 77 states: "This allows FortiAnalyzer to fetch the archived logs of specified devices from another FortiAnalyzer...". It does mention fetching archived logs, but not necessarily that they are archived when they get to the client. I assume I can make a case for A and B as well: A: page 78 on the slide says "You must add the devices to Device Manager before you can see the logs in the client. You can do the log fetching BEFORE adding the devices, but y ou won't be able to see the logs". For A to be wrong because it says local DM and not DM seems like they are trying to trick you, and I havent really noticed that on other questions. C. Page 78 on the slide: During the request, you can choose filters to include:..."
upvoted 1 times
fc58c80
2 weeks, 1 day ago
I meant to put B and not C. We need an edit button
upvoted 1 times
...
...
alejandro1985
4 weeks, 1 day ago
Hi!, Answer D states that the user has to be included in the Super_User profile, it does not present it as an option. In the study guide it is presented as an option since it can also be Standard_User. Reference: The fetch server administrator user name and password must be for an administrator with either a Standard_User or Super_User profile https://docs.fortinet.com/document/fortianalyzer/7.4.2/administration-guide/785943/fetching-profiles
upvoted 1 times
alejandro1985
4 weeks, 1 day ago
Sorry, I was referring to answer C, it is not correct.
upvoted 1 times
...
...
...
rian00z_
1 month ago
Selected Answer: AB
After revisiting this question, I suppose that it is broken. A copule of days I've explained about answers B and D such as correct, but answer A is also true: The fetch client can retrieve logs from devices that are not added to its local Device Manager, I did it on lab. If we Pass through the understanding about *maybe* answer D is incorrect, if we consider "...become archive logs in the client" that original logs will be moved from fetch server to client, and that's don't occurr.
upvoted 1 times
fc58c80
2 weeks, 3 days ago
In the lab, I assume you fetched the logs from another FortiAnalyzer? I think if A. stated that it can fetch from FA devices that are not on the Device Manger, then that would be correct. The question just says devices, but FA can't fetch from non-FA devices as far as I'm aware. I could be wrong though
upvoted 1 times
...
...
alejandro1985
1 month, 1 week ago
B and D D: The fetch server administrator user name and password must be for an administrator with either a Standard_User or Super_User profile. https://docs.fortinet.com/document/fortianalyzer/7.4.2/administration-guide/785943/fetching-profiles
upvoted 1 times
...
rian00z_
1 month, 2 weeks ago
Selected Answer: BD
B and D are correct About answer B, check it on FortiAnalyzer Analyst 7.2 Study Guide, p. 77 and https://docs.fortinet.com/document/fortianalyzer/7.4.2/administration-guide/651442/log-fetching About answer D, I've just tried the functionally on lab and on production, and I had just archived logs on FortiAnalyzer client. To see analytics logs, it's necessary wait the rebuild ADOM.
upvoted 2 times
...
bestboy120
1 month, 4 weeks ago
Selected Answer: BC
https://docs.fortinet.com/document/fortianalyzer/7.4.2/administration-guide/651442/log-fetching The fetching FortiAnalyzer can query the server FortiAnalyzer and retrieve the log data for a specified device and time period, based on specified filters. https://docs.fortinet.com/document/fortianalyzer/7.4.2/administration-guide/559986/fetch-requests The data policy for the local ADOM on the client must also support fetching logs from the specified time period. It must keep both archive and analytics logs long enough so they will not be deleted in accordance with the policy. For example: Today is July 1, the ADOM's data policy is configured to keep analytics logs for 30 days (June 1 - 30), and you need to fetch logs from the first week of May. The data policy of the ADOM must be adjusted to keep analytics and archive logs for at least 62 days to cover the entire time span. Otherwise, the fetched logs will be automatically deleted after they are fetched.
upvoted 1 times
bestboy120
1 month, 4 weeks ago
sorry: The fetch server administrator user name and password must be for an administrator with either a Standard_User or Super_User profile.
upvoted 2 times
...
...
myrmidon3
2 months, 3 weeks ago
Selected Answer: BC
FAZ Analyst 7.2 Study Guide Page: 77-78
upvoted 1 times
...
myrmidon3
2 months, 3 weeks ago
B & C FAZ Analyst 7.2 Study Guide Page: 77-78
upvoted 1 times
...
rac_sp
4 months, 3 weeks ago
Selected Answer: AB
A & B correct
upvoted 1 times
...
Thomas_2020
4 months, 3 weeks ago
Selected Answer: BC
B & C, Page 168 , FAZ_7.0
upvoted 1 times
...
Thomas_2020
5 months ago
B & C, Page 168 , FAZ_7.0
upvoted 1 times
...
r_jordan
5 months ago
Selected Answer: BD
- retrieve archive logs from another FAZ and run queries or reports on those archived logs - you can do the log fetching but you won't be able to see the logs if you do not add the FAZ to the Device Manager (pages 77-78) So I think B and D are more accurate answers.
upvoted 3 times
...
DaniSerb
6 months, 1 week ago
Selected Answer: AB
A: Using FortiAnalyzer, you can enable log fetching. This allows FortiAnalyzer to fetch the archived logs of specified devices from another FortiAnalyzer B: During the request, you can choose filters to include: - Logs from a specific device - Logs of specific types and values - Logs from a specific time frame Reference: FortiAnalyzer Analyst Study Guide for FortiAnalyzer 7.2
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...