exam questions

Exam NSE5_FAZ-6.0 All Questions

View all questions & answers for the NSE5_FAZ-6.0 exam

Exam NSE5_FAZ-6.0 topic 1 question 25 discussion

Actual exam question from Fortinet's NSE5_FAZ-6.0
Question #: 25
Topic #: 1
[All NSE5_FAZ-6.0 Questions]

View the exhibit.

What does the data point at 14:35 tell you?

  • A. FortiAnalyzer is dropping logs.
  • B. FortiAnalyzer is indexing logs faster than logs are being received.
  • C. FortiAnalyzer has temporarily stopped receiving logs so older logs' can be indexed.
  • D. The sqlplugind daemon is ahead in indexing by one log.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ZOKOF
Highly Voted 4 years, 8 months ago
B is the right answer
upvoted 5 times
...
meccorn
Most Recent 2 years, 10 months ago
Answer: D Explanation: Logs are received then they are indexed, no logging server in the world can index logs faster than they are received. When FAZ receives raw logs, they are inserted (indexed) by the SQL database and the sqlplugind daemon, this graph shows that FAZ received 3 logs and sqlplugind indexed 4.
upvoted 1 times
meccorn
2 years, 10 months ago
https://docs.fortinet.com/document/fortianalyzer/6.2.5/administration-guide/47690/insert-rate-vs- I am correcting , answer is B please check the below link
upvoted 1 times
...
...
Andres21216
4 years, 3 months ago
Hello, I took the exam in version 6.0, I failed it in the logging section and I got a similar question, but the time of the analysis was 14:55 not 14:35. I still have the doubt, I have the doubt between answer B and D. I cannot find any reference in the study guide to corroborate the answer. Please, if anyone has any reference to know what happens at 14:55 I would appreciate it infinitely
upvoted 2 times
dawa
4 years, 1 month ago
@14:55 FortiAnalyzer is dropping logs.
upvoted 3 times
...
Dee244
4 years, 1 month ago
I got the same exam couple of days ago, my answer was D and I passed the exam. You will find a similar part in the study guide 6.2 and the answer is there.
upvoted 2 times
...
...
Gary1020
4 years, 8 months ago
The correct answer will be B Raw logs are received and then that log is indexed. So indexing can never be ahead of logs received. But it can be that at a certain point in time logs are being indexed faster than they are received. If you look at the study guide you will notice that there is something called Insert Lag Time. And in this example it’s between 30-50 seconds. The point is the indexing of the logs can’t be ahead if it gets processed a few seconds later.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago