Exam nse5_faz-70 All QuestionsBrowse all questions from this exam
Question 29

Refer to the exhibit.

The image displays the configuration of a FortiAnalyzer the administrator wants to join to an existing HA cluster.

What can you conclude from the configuration displayed?

    Correct Answer: A

    The FortiAnalyzer is set to join an existing HA cluster with a preferred primary role, but as it is joining an existing cluster, it will not assume the primary role unless the current primary fails. Therefore, through the provided configuration, it is concluded that this FortiAnalyzer will join the cluster initially as a secondary member. However, as it has the highest priority set (120), it is configured to become the primary if there is a failover scenario. The other options do not match the configuration details accurately: it is not explicitly stated that port1 is set to receive logs, the failover trigger settings indicate a 30-second timeframe due to heartbeat interval and failover threshold settings, and log data sync is not enabled in the configuration.

Discussion
D10SJokerOption: B

Answer is B

certmeupnowOption: B

B is correct... A is wrong, it's configured to be *preferred* primary but that does not mean it'll be operational primary to an existing cluster (i.e. it will not preempt).

pmorinOption: A

Answer is A B. Port 1 is the interface the FortiAnalyzer HA unit uses to provide redundancy, not receive logs C. Failover Threshold is the one that does that. The number of heartbeat intervals that one of the cluster units waits to receive HA heartbeat packets from other cluster units before assuming that the other cluster units have failed. The default failover threshold is 3. D. Log Data Sync is not checked A. Preferred Role is selected primary, Priority is set to the highest priority possible (120). Ref : https://docs.fortinet.com/document/fortianalyzer/6.4.10/administration-guide/275104/configuring-ha-options

whatz

A: is wrong. The unit joins an existing cluster and therefore no election will take place. The unit will join as secondary even it is configured as primary. Here the statement from the admin guide: "If the preferred role is Primary, then this unit becomes the primary unit if it is configured first in a new HA cluster. If there is an existing primary unit, then this unit becomes a secondary unit." (https://docs.fortinet.com/document/fortianalyzer/7.0.5/administration-guide/275104)

Ronnie89

Furthermore: Fortianalyzer study guide 7.0: page 61: In the Cluster Virtual IP section, you need to select the interface and type the IP address for which the FAZ device is to provide redundancy. This is the IP that other devices need to point to send their logs once the cluster is up.

Ronnie89Option: C

I don't think it's A. Cause the key word is that it will join "existing" cluster. That means there already is a primary and it won't trigger failover.

D10SJokerOption: B

I think is B. If the preferred role is Primary, then this unit becomes the primary unit if it is configured first in a new HA cluster. If there is an existing primary unit, then this unit becomes a secondary unit.

GeorgeheichOption: D

A. This FortiAnalyzer will join to the existing HA cluster as the primary. *NO, because a primary already exists, although the priority is high, the primary must fail for failover to occur.* B. This FortiAnalyzer is configured to receive logs in its port1. *NO, logs are not received based on a port, in addition this port and IP is for redundancy communication* C. This FortiAnalyzer will trigger a failover after losing communication with its peers for 10 seconds. *NO, because the value for failover should be 30 seconds since "heart beat interval" is multiplied by failover threshold* D. *After joining to the cluster, this FortiAnalyzer will keep an updated log database.* SI, Synchronizes logs and data securely among multiple FortiAnalyzer devices. System and configuration settings applicable to HA are also synchronized. ANSWER CORRECT A

Georgeheich

SORRY ANSWER CORRECT IS D

MaxTalinOption: B

I'm sorry, the correct answer is B not A B: In the Cluster Virtual IP section, you need to select the interface, and type the IP address for which the FortiAnalyzer device is to provide redundancy. Once the cluster is up, the devices sending their logs must point to this IP

MaxTalinOption: A

Correct A Preferred Role is selected primary, Priority is set to the highest priority possible (120).

MickderOption: D

The correct answer is D --> After joining to the cluster, this FortiAnalyzer will keep an updated log database. https://docs.fortinet.com/document/fortianalyzer/6.4.10/administration-guide/275104/configuring-ha-options Log Data Sync: This option is on by default. It provides real-time log synchronization among cluster members.

jayessarreOption: C

logical answer is C Study Guide P. 62 " By default, the only parameter checked to trigger an automatic failover is the network reachability among cluster members." Notice the subnet configured on FAZ and Peer Subnet is different, which means there will be reachability issue with cluster members, which may trigger failover

Fikachew

Not really, as stated on page 61: As shown on the previous slide, these IP addresses (referring to Peer IP) don’t have to be on the same subnet as the cluster virtual IP. And regarding to answer B, virtual IP: "This is the IP that other devices need to point to send their logs once the cluster is up."

jayessarre

yeah, but the log sync option seems disabled on the screen shot

khanwooOption: C

why ppl don't see Heart Beat Interval Answer is C.

CertificateStudyingGuy

The heartbeat is 10 seconds and the threshold is 3. It doesn’t failover for another 20 seconds. ‘The answer is B. Study Guide Pg. 61 In the Cluster Virtual IP section, you need to select the interface, and type the IP address for which the FortiAnlayzer devices to provide redundancy. This is the IP that other devices need to point to send their logs once the cluster is IP. Other devices send logs to the cluster IP, so the Cluster Virtual IP receives logs, as the question is asking.