Fortinet • NSE5_FAZ-7.4
Validates the skills of security analysts and SOC engineers in using FortiAnalyzer 7.4 for centralized logging, security analytics, threat detection, and automated response within the Fortinet Security Fabric. Covers system configuration, device management, log management, reporting, and FortiSOC operations.
Questions
597
Duration
60 minutes
Passing Score
60%
Difficulty
ProfessionalLast Updated
Apr 2026
The Fortinet NSE 5 – FortiAnalyzer 7.4 Analyst (NSE5_FAZ-7.4) certification validates the skills of security professionals in deploying and operating FortiAnalyzer 7.4 as a centralized log management and security analytics platform within the Fortinet Security Fabric. The exam covers core competencies including FortiAnalyzer architecture and feature concepts, log collection and analysis, SOC event and incident management, playbook-driven automation, and report generation. It is part of Fortinet's transition toward the FCP (Fortinet Certified Professional) – Security Operations certification track, with the parallel exam code FCP_FAZ_AN-7.4 also in use for the same version.
This certification demonstrates practical proficiency in using FortiAnalyzer to aggregate log data from FortiGate and other Security Fabric devices, correlate security events, manage threat indicators, build automated response playbooks, and produce actionable compliance and security reports. It is particularly relevant in organizations running Fortinet-centric SOC environments where FortiAnalyzer serves as the nerve center for visibility and incident response.
This exam is designed for network and security analysts, SOC engineers, and threat analysts who are responsible for day-to-day security monitoring and operations using FortiAnalyzer. It suits professionals in roles such as security operations center (SOC) analyst, network security engineer, and cybersecurity analyst who work within Fortinet Security Fabric environments.
Candidates typically have hands-on experience managing Fortinet products and are looking to formalize their expertise in centralized log management, event correlation, and SOC automation. It is well suited for those pursuing the FCP – Security Operations certification path or those who already hold the NSE 4 – FortiGate Security certification and want to specialize in analytics and SOC operations.
There are no mandatory formal prerequisites for this exam. However, Fortinet recommends a minimum of 6 months to 1 year of hands-on experience with both FortiGate and FortiAnalyzer before attempting the exam. Candidates should be comfortable with basic network security concepts, FortiGate administration, and familiarity with log management workflows.
Completion of the official Fortinet FortiAnalyzer Analyst course, which includes hands-on labs, is strongly recommended as direct preparation. Reviewing the FortiAnalyzer 7.4 Administration Guide and New Features Guide is also advised. Holding the NSE 4 – FortiGate Security and Infrastructure certifications provides useful foundational context, though it is not a requirement.
The NSE5_FAZ-7.4 exam consists of approximately 30–35 multiple-choice and multiple-select questions, with a time limit of 60–65 minutes. Questions are scenario-based and require applied knowledge; no partial credit is awarded — answers must be fully correct to receive credit. The exam is delivered in English and Japanese through Pearson VUE, available at authorized test centers or via OnVUE online proctoring.
The passing threshold is 60%. Results are reported as pass or fail, and a detailed score report is available through the candidate's Pearson VUE account. Candidates must wait 15 days between attempts. Upon passing, the Fortinet Training Institute transcript is updated within five business days, and a printable certificate becomes available. The certification remains valid for two years from the date of completion.
Earning the NSE 5 – FortiAnalyzer 7.4 Analyst certification positions professionals for specialized roles in security operations, including SOC Analyst, Security Engineer, Threat Intelligence Analyst, and Network Security Engineer. As organizations increasingly adopt Fortinet's Security Fabric, demand for certified analysts who can operate FortiAnalyzer for centralized visibility, incident detection, and automated response continues to grow. This certification also contributes toward the Fortinet Certified Professional (FCP) – Security Operations designation when combined with the NSE 4 credential.
Professionals holding NSE 4–5 level Fortinet certifications report average annual salaries in the range of $110,000–$135,000 in the United States, with certified individuals generally earning up to 40% more than non-certified peers in comparable roles. The FCP designation, achievable by combining this exam with NSE 4, is associated with an estimated 15% salary boost. Compared to vendor-neutral certifications such as CompTIA Security+ or CySA+, this exam offers deeper, platform-specific validation that is directly applicable in Fortinet-centric enterprise and MSSP environments.
1. A FortiAnalyzer administrator at Litware Inc. exports a custom event handler named 'Critical-Outbound-Botnet' that includes email and syslog notification profiles. The administrator imports this handler into a different ADOM on the same FortiAnalyzer to replicate the detection logic. After importing, what two behaviors should the administrator expect? (Select two!)
Select all that apply2. A security team at Adatum Corporation is analyzing a security incident. The FortiSOC incident was created last week and has been through several status transitions. The team lead wants to permanently delete the incident from the system because it turned out to be a false positive and they want to clean up the incident list. What will happen when the administrator attempts to delete the incident? (Select one!)
3. A FortiAnalyzer administrator at Fabrikam Inc. is setting up a FortiGate connector in FortiSOC for use in automated playbooks. After configuring the connector with the FortiGate IP, port, and API key, the administrator runs the Test Connectivity function, which succeeds. However, when a playbook executes a 'Ban IP' action against the FortiGate, the action fails. What is the most likely cause? (Select one!)
4. A security engineer at Litware Inc. is configuring a correlation event handler in FortiAnalyzer to detect a specific attack sequence. The handler should trigger only when a failed admin login event is followed by a successful admin login event from the same source IP within 5 minutes. Which subrule correlation mode should the engineer select? (Select one!)
5. A FortiAnalyzer administrator at Contoso Ltd. is configuring a playbook that needs to perform a VirusTotal reputation lookup on file hashes extracted from malware events. The organization uses a free VirusTotal API account. During testing, the playbook frequently fails at the VirusTotal task. What is the most likely cause and recommended solution? (Select one!)
All exams included • Cancel anytime