exam questions

Exam NSE5_FAZ-7.0 All Questions

View all questions & answers for the NSE5_FAZ-7.0 exam

Exam NSE5_FAZ-7.0 topic 1 question 12 discussion

Actual exam question from Fortinet's NSE5_FAZ-7.0
Question #: 12
Topic #: 1
[All NSE5_FAZ-7.0 Questions]

Which two statements are true regarding log fetching on FortiAnalyzer? (Choose two.)

  • A. Log fetching allows the administrator to fetch analytics logs from another FortiAnalyzer for redundancy.
  • B. A FortiAnalyzer device can perform either the fetch server or client role, and it can perform two roles at the same time with the same FortiAnalyzer devices at the other end.
  • C. Log fetching can be done only on two FortiAnalyzer devices that are running the same firmware version.
  • D. Log fetching allows the administrator to run queries and reports against historical data by retrieving archived logs from one FortiAnalyzer device and sending them to another FortiAnalyzer device.
Show Suggested Answer Hide Answer
Suggested Answer: CD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
morzart2025
Highly Voted 1 year, 8 months ago
C and D Using FortiAnalyzer, you can enable log fetching. This allows FortiAnalyzer to fetch the archived logs of specified devices from another FortiAnalyzer, which you can then run queries or reports on for forensic analysis. The FortiAnalyzer device that fetches logs operates as the fetch client, and the other FortiAnalyzer device that sends logs operates as the fetch server. Log fetching can happen only between two FortiAnalyzer devices, and both of them must be running the same firmware version. A FortiAnalyzer device can perform either the fetch server or client role, and it can perform two roles at the same time with different FortiAnalyzer devices at the other end. FortiAnalyzer_7.0_Study_Guide-Online pag. 168
upvoted 8 times
...
PiotrSwi
Most Recent 5 months, 2 weeks ago
C,D - Correct. FortiAnalyzer 7.0. Study Guide page 168.
upvoted 1 times
...
MaxTalin
6 months, 1 week ago
Coorect C and D Log fetching is used to retrieve archived logs from one FortiAnalyzer device to another. This allows administrators to run queries and reports against historic data, which can be useful for forensic analysis. Log fetching can only be done on two FortiAnalyzer devices running the same firmware
upvoted 2 times
...
SH_
11 months, 2 weeks ago
Selected Answer: CD
CD are correct. See https://docs.fortinet.com/document/fortianalyzer/7.4.0/administration-guide/651442/log-fetching
upvoted 2 times
...
Michael348
1 year, 1 month ago
Selected Answer: CD
B - says the Perform 2 roles with same FortiAnalyzer device. should perform 2 roles with different FortiAnalyzer device at the other end. So should be C and D
upvoted 2 times
...
Robku
1 year, 3 months ago
C and D FAZ must run the same firmware version And a FortiAnalyzer device can perform either the fetch server or client role, and it can perform two roles at the same time with different FortiAnalyzer devices at the other end. Key word is different in this case.
upvoted 2 times
...
Nappel
1 year, 3 months ago
Selected Answer: BC
FortiAnalyzer_7.0_Study_Guide-Online page: 168 | Log Fetching can happen only between two FortiAnalyzer devices, and both of them must be running the same Firmware. This makes Answer C correct FortiAnalyzer_7.0_Study_Guide-Online page: 168 | A FortiAnalyzer device can perform either the fetch server or client role, and it can perform two roles at the same time with different FortiAnalyzers devices at the other end. This makes answer B correct.
upvoted 1 times
mohamedismail
4 months, 1 week ago
same FortiAnalyzer devices - which is B is wrong
upvoted 1 times
...
...
AngelCruz21
1 year, 4 months ago
Selected Answer: CD
C and D
upvoted 1 times
...
iZippo
1 year, 5 months ago
The correct statements regarding log fetching on FortiAnalyzer are: B. A FortiAnalyzer device can perform either the fetch server or client role, and it can perform two roles at the same time with the same FortiAnalyzer devices at the other end. D. Log fetching allows the administrator to run queries and reports against historical data by retrieving archived logs from one FortiAnalyzer device and sending them to another FortiAnalyzer device. Explanation: A is not a true statement because log fetching allows the administrator to fetch logs from other Fortinet devices, not from another FortiAnalyzer. C is not a true statement because log fetching can be done between FortiAnalyzer devices running different firmware versions. Therefore, B and D are the two statements that are true regarding log fetching on FortiAnalyzer.
upvoted 1 times
...
Fikachew
1 year, 5 months ago
Selected Answer: BC
B and C. The answer D states that the FAZ fetches logs and sends the to a third FAZ to use. In the study guide at page 168 it states that it fetches logs from another FAZ and is being used by the current FAZ. Also documents says that this can only be done between two FAZ devices, NOT forwarded to a third.
upvoted 2 times
...
Christiandus
1 year, 5 months ago
Selected Answer: CD
C and D Using FortiAnalyzer, you can enable log fetching. This allows FortiAnalyzer to fetch the archived logs of specified devices from another FortiAnalyzer, which you can then run queries or reports on for forensic analysis. The FortiAnalyzer device that fetches logs operates as the fetch client, and the other FortiAnalyzer device that sends logs operates as the fetch server. Log fetching can happen only between two FortiAnalyzer devices, and both of them must be running the same firmware version. A FortiAnalyzer device can perform either the fetch server or client role, and it can perform two roles at the same time with different FortiAnalyzer devices at the other end. FortiAnalyzer_7.0_Study_Guide-Online pag. 168
upvoted 3 times
...
certmeupnow
1 year, 5 months ago
C and D. Classic devil in the details gotcha. B says *same* FortiAnalyzer devices, which is wrong... has to be *different* FAZ devices.
upvoted 1 times
...
KP001
1 year, 6 months ago
C and D FortiAnalyzer_7.0_Study_Guide-Online page 168; Log fetching can happen only between two FortiAnalyzer devices, and both of them must be running the same firmware version. A FortiAnalyzer device can perform either the fetch server or client role, and it can perform two roles at the same time with different FortiAnalyzer devices at the other end. (Key words different devices, makes answer B incorrect)
upvoted 1 times
...
nerostart
1 year, 6 months ago
Selected Answer: BC
FortiAnalyzer_7.0_Study_Guide-Online.pdf page 168: Log fetching can happen only between two FortiAnalyzer devices, and both of them must be running the same firmware version. A FortiAnalyzer device can perform either the fetch server or client role, and it can perform two roles at the same time with different FortiAnalyzer devices at the other end.
upvoted 2 times
Christiandus
1 year, 5 months ago
B. A FortiAnalyzer device can perform either the fetch server or client role, and it can perform two roles at the same time with the same FortiAnalyzer devices at the other end. Keyword is same. Your source clearly states the opposite.
upvoted 1 times
...
...
lucient
1 year, 6 months ago
Selected Answer: CD
C and D) FortiAnalyzer_7.0_Study_Guide-Online.pdf page 168: Using FortiAnalyzer, you can enable log fetching. This allows FortiAnalyzer to fetch the archived logs of specified devices from another FortiAnalyzer, which you can then run queries or reports on for forensic analysis. Log fetching can happen only between two FortiAnalyzer devices, and both of them must be running the same firmware version.
upvoted 1 times
...
Khs01
1 year, 8 months ago
Selected Answer: CD
C and D are the correct answers
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago