About the Exam

This exam covers FortiAnalyzer analytics for Fortinet Security Fabric environments. It tests applied knowledge of log analysis, incident analysis, reporting, Security Fabric integration, and troubleshooting scenarios. It is intended for network and security analysts who use FortiAnalyzer to automate detection and response workflows.

Exam Topics

  • Security Operations100%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated July 18, 2026 at 7:26 PM

Topic filter
Retired questions
Question sort

QuestionQ1

Security Operations

A playbook includes five tasks in total. An administrator executes the playbook: four of the five tasks complete successfully, but one task fails.

What is the playbook status after it has run?

  • A Running
  • B Failed
  • C Upstream_failed
  • D Success
Explanation

A completed FortiAnalyzer playbook job is marked Failed if one or more of its tasks fail to complete successfully, even when other tasks complete successfully. Upstream_failed is a task status indicating failure to connect with an upstream device.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Security Operations

Which statement regarding the FortiSIEM management extension is correct?

  • A Allows you to manage the entire life cycle of a threat or breach.
  • B Its use of the available disk space is capped at 50%.
  • C It requires a licensed FortiSIEM supervisor.
  • D It can be installed as a dedicated VM.
Explanation

The FortiSIEM management extension application is a FortiAnalyzer-hosted collector that must register with and is centrally managed by a FortiSIEM Supervisor. It is not deployed as a separate dedicated virtual machine.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Security Operations

Which two statements are accurate about the outbreak detection service?

Choose two
  • A New alerts are received by email.
  • B Outbreak alerts are available on the root ADOM only.
  • C An additional license is required.
  • D It automatically downloads new event handlers and reports.
Explanation

FortiAnalyzer Outbreak Detection Service is a licensed feature. When its license is valid, FortiAnalyzer automatically downloads Fortinet-created outbreak event handlers and reports from FortiGuard. Outbreak alerts are available from any ADOM, and notifications for new alerts appear in the interface banner rather than being delivered by email.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Security Operations

Which FortiAnalyzer feature lets you take a proactive approach to managing network security?

  • A Outbreak alert services
  • B FortiView Monitor
  • C Threat hunting
  • D Incidents dashboard
Explanation

Threat hunting enables analysts to proactively investigate SIEM log data, filter and drill down into relevant activity, and identify potential threats before they become confirmed incidents. FortiAnalyzer provides Threat Hunting as a SOC analytics dashboard backed by its SIEM database.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Security Operations

Refer to the exhibit shown below.

Question Image

Based on the partial output displayed, which devices can be members of a FortiAnalyzer Fabric?

  • A FortiAnalyzer1 and FortiAnalyzer3
  • B FortiAnalyzer1 and FortiAnalyzer2
  • C All devices listed can be members
  • D FortiAnalyzer2 and FortiAnalyzer3
Explanation

FortiAnalyzer Fabric permits multiple FortiAnalyzers operating in Analyzer mode to be configured as members, and all members must use the same timezone as the supervisor. Each listed device is in Analyzer mode and uses the same Pacific Time (GMT-8:00) timezone; differing disk capacity and concurrent-report limits do not disqualify a device from membership.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

That's the end of the preview

It's free

100% of the questions are free for all users.
No strings attached.

Topics covered
Security Operations
Know a question that should be here? Contribute to this exam
Back home