Main Flashcards
(136 cards)
Event status ‘mitigated’
Security risk was dropped or blocked
Handle HD failure on FAZ with hardware RAID
Hot swap disk
Handle HD failure on FAZ with software RAID
Shutdown device and replace hard drive
Statement describes management extensions on faz
May require a min number of CPU cores to run
2 most common way to control and restrict admin access on faz
- Trusted hosts 2. Admin profiles
Daemon responsible for enforcing raw log file size
Logfiled
Process responsible for disk quota enforcement
Logfiled
Process that enforces SQL database size
Sqlplugind
Process that enforces archive file size
Oftpd
How frequently Logfiled checks processes
Every 2 minutes
What is the purpose of a predefined template on the FortiAnalyzer?
It specifies the report layout which contains predefined texts, charts, and macros
Which clause is considered mandatory in SELECT statements used by the FortiAnalyzer to generate reports?
FROM
In Log View, you can use the Chart Builder feature to build a dataset and chart based on the filtered search results.
Similarly, which feature can you use for FortiView?
Export to Report Chart
2 ways to enable ADOMS
- GUI System Setting > Dashboard > Enable Administrative Domains
- CLI
config sys global
set adom-status enable/disable
end
FAZ modes
- Analyzer (default)
- Collector (no event management or reporting
what Collector mode does
Forwards logs in original binary format
Collector mode advantages
- Increase performance
- Focuses on receiving logs
- Helps with logs over unreliable links
- Allocate most disk space for archive logs
What GUI elements not available in collector mode
- FortiView
- Fabric View
- FortiSOC
- Reports
SQL DB in collector mode
Disabled by default. Can be enabled from CLI
Admin pass recovery procedure
- Factory reset VM/appliance
- Execute migrate from CLI
- Use default admin account and pass
Reset to factory defaults CLI options
Exe reset all-settings
Exe reset all-except-ip
Exe format disk - deletes all settings, images, DBs, log data from disk
What includes system config backup
Includes
1. Sys information
2. Device list
3. Report info
System config backup
Does NOT include
Does NOT include
1.actual logs
2. Generated reports
Exe backup logs
Backup logs and reports