10 free sample questions from a bank of 63, with the correct answers and explanations. No signup required — start practising right now.
1Which statement about automation connectors on FortiAnalyzer is true?
An ADOM with the Fabric type comes with multiple connectors configured.
The local connector comes online once you have a playbook task referencing it.
The actions available with FortiOS connectors are determined by automation rules configured on FortiGate.
The playbook module must be enabled before external connectors are displayed.
Answer: C
The short version
C — FortiOS connector actions come from FortiGate automation rules. The connector exposes what the FortiGate side defines.
Key concepts in this question
The FortiOS connector lets FAZ playbooks trigger FortiGate automation-stitch actions.
Available actions mirror the automation rules configured on FortiGate, not FAZ-side settings.
Why C is correct
A FortiOS connector is a window into FortiGate's automation rules: only actions defined there appear as runnable actions on the connector. No FortiGate rule, no action.
Why the others are wrong
A. Fabric-type ADOMs do not ship preconfigured connectors.
B. The local connector's online state does not depend on playbook references.
D. External connectors display independently of the playbook module toggle.
2Which three modules does FortiAnalyzer automatically download content from with a valid SOC Automation service license? (Choose three.)
Report templates
Dashboards
Event handlers
Active Connectors
Playbooks
Incident templates
Answer: A, C, E
The short version
A, C, E — a SOC Automation license feeds report templates, event handlers, and playbooks. Content packs, not live modules.
Key concepts in this question
The SOC Automation service delivers downloadable content: handlers that detect, playbooks that respond, report templates that present.
Dashboards, connectors, and incident templates are configured locally, not downloaded.
Why A, C and E are correct
Report templates (A), event handlers (C), and playbooks (E) are the three content types the SOC Automation service publishes for auto-download — detection, response, and reporting in one bundle.
Why the others are wrong
B. Dashboards are built locally from widgets, not downloaded.
D. Active connectors are configured integrations, not content downloads.
F. Incident templates are local definitions, not service content.
3Refer to the exhibit. Which two observations can you make after reviewing this log entry? (Choose two.)
This is a formatted view of the log.
This is a normalized log.
This log is in a raw log format.
This is the original log that FortiAnalyzer received from FortiGate.
Answer: C, D
The short version
C and D — the exhibit is the raw key=value stream FortiGate sent. Unparsed, unformatted, original.
Key concepts in this question
Raw logs are the as-received key=value lines (adom_oid, itime, logid, … with logMeta=undefined).
Normalized/formatted views parse those lines into field tables or GUI layouts.
Why C and D are correct
The exhibit shows the unparsed stream exactly as received — raw format (C), which by definition is the original log from FortiGate (D). No parsing or GUI formatting has been applied.
Why the others are wrong
A. A formatted view would show the GUI layout, not the raw stream.
B. Normalized means parsed into indexed fields — this line is explicitly unparsed.
FortiGate exam tip
key=value stream with logMeta=undefined = raw + original. Tables = normalized.
4Refer to the exhibit. What is the purpose of using the Chart Builder feature on FortiAnalyzer7?
To build a chart automatically based on the top 100 log entries
To add charts to generate reports directly in the current ADOM
To add a new chart under FortiView to be used in new reports
To build a dataset and chart based on the filtered search results
Answer: D
The short version
D — Chart Builder turns your current filtered search into a dataset plus chart. Search first, chart second.
Key concepts in this question
Chart Builder consumes the active Log View filter and builds a reusable dataset/chart from those results.
It does not invent top-N charts or attach to ADOMs/FortiView directly.
Why D is correct
The feature's purpose is search-driven charting: filter the logs, then build the dataset and chart from exactly that result set for reports.
Why the others are wrong
A. No automatic top-100 charting is involved.
B. Charts are not generated into the current ADOM by this tool.
C. FortiView placement is a separate concern.
FortiGate exam tip
Chart Builder = filtered search results become a chart. Search comes first.
5Refer to the exhibit. The playbook shown in the exhibit requires fine-tuning. A task needs to be configured to run a report on the updated asset list that the FortiAnalyzer receives from the FortiClient EMS. Which SOC role is responsible for making this change?
Threat hunter
SOC engineer
Security analyst
Incident responder
Answer: B
The short version
B — playbook/report edits are engineering work: the SOC engineer owns them. Tuning tasks is not hunting, analysis, or response.
Key concepts in this question
SOC engineer: builds and tunes playbooks, connectors, reports.
8Which two parameters does FortiAnalyzer use to identify an indicator of compromise (IOC)? (Choose two.)
Application category
IP address
URL
Policy ID
Answer: B, C
The short version
B and C — an IOC is identified by IP address and URL. The two network locators.
Key concepts in this question
FortiAnalyzer IOC matching keys on IP and URL observables from logs.
Application category and policy ID are context, not identifiers.
Why B and C are correct
IP addresses and URLs are the two parameters the IOC engine uses to declare a match — the documented identifier pair.
Why the others are wrong
A. Application category describes traffic, it does not identify IOCs.
D. Policy IDs locate the rule, not the compromise.
FortiGate exam tip
IOC identity = IP + URL. Everything else is context.
9Which statement describes archive logs on FortiAnalyzer?
Logs that are parsed and normalized by FortiAnalyzer and available in the log view
Logs received from other FortiAnalyzer devices
Logs compressed and saved in files with the .gz extension
Logs that are indexed and stored in the SQL database
Answer: C
The short version
C — archive logs are compressed .gz files. Cold storage, not live views.
Key concepts in this question
Archive logs: gzipped files for retention, outside the indexed database.
Live/parsed/indexed logs are the analytic (SQL/ClickHouse) set.
Why C is correct
Compressed .gz file storage is the definition of the archive tier — retrievable but not queryable until restored.
Why the others are wrong
A. Parsed/normalized in log view describes analytic logs.
B. Inter-Analyzer transfers are a different feature (aggregator tiers).
D. Indexed SQL storage describes analytic logs.
FortiGate exam tip
.gz = archive. Indexed = analytic. Never mix the tiers.
10An analyst needs to move reports between two ADOMs. Which two statements are true? (Choose two.)
All charts and datasets associated with the report will be imported together.
The date and time will be appended to the original report name to avoid conflicts.
The ADOMs must be compatible types.
The reports must be converted into templates first.
Answer: A, C
The short version
A and C — charts/datasets travel with the report, but only between compatible ADOMs. Portability with prerequisites.
Key concepts in this question
Report export/import bundles associated charts and datasets automatically.
Cross-ADOM moves require compatible ADOM types (e.g. Fabric vs FortiGate).
Why A and C are correct
The bundle behavior (A) plus the compatibility gate (C) are the two documented move semantics — everything arrives together, but only where the ADOM type allows.
Why the others are wrong
B. No timestamp renaming happens on import.
D. No template conversion is required to move a report.
FortiGate exam tip
Report moves = bundle travels, ADOM types must match.