Guide · free to read
The NSE 5 (FortiAnalyzer 7.6 Analyst) exam blueprint, domain by domain.
Fortinet’s exam description page for the FortiAnalyzer 7.6 Analyst exam lists four domains and the tasks under each, the same way it does for every NSE exam. What it doesn’t give you is a weighting — no percentages, no bands, nothing to tell you where to spend your study hours. That’s what this piece adds, with the reasoning shown.
The basics
Exam code FCP_FAZ_AN-7.6. 30–35 questions, 65 minutes, English or
Japanese.
Fortinet does not publish a cut score — the widely repeated “70%” is an estimate, not a published number, and you should treat it that way.
Fortinet’s own page recommends 6 months to a year of hands-on FortiGate and FortiAnalyzer experience before you sit it, which is a fair description of how much of this exam assumes you’ve actually looked at real logs before.
Fortinet publishes no domain percentages for this exam. The exam description page lists the domains and their tasks and gives no weights at all. The split below is ours, derived from that task breakdown and from how much of the documentation each area occupies — useful for planning study time, and not something to attribute to Fortinet.
| Domain | Weight (this budget) |
|---|---|
| SOC operation and automation | 32% |
| Log Analysis | 24% |
| Features and concepts | 22% |
| Reports | 22% |
SOC operation and automation is the largest single domain by our own estimate, and it’s also the newest-feeling material on this exam if your FortiAnalyzer experience predates its SOAR-style automation features — events, incidents, indicators, and playbooks are a different skill from reading logs.
1. SOC operation and automation — the largest domain
Four task bullets, and they build on each other in order:
- Configure and manage events and event handlers. The mechanism the rest of this domain sits on top of — an event handler is what turns raw log traffic into something worth looking at.
- Configure incidents and indicators. What you do once an event handler has actually found something.
- Configure playbooks and fabric automation. The automated-response layer — what happens after an incident exists, without a human clicking through it manually.
- Troubleshoot playbook and fabric automation issues. Listed as its own task, separate from configuring playbooks in the first place — expect the exam to test failure diagnosis, not just setup.
Primary source: the FortiAnalyzer 7.6.0 Administration Guide, the event handler, incidents, and fabric automation chapters. The 7.6.0 New Features Guide is worth a pass too if your working knowledge of FortiAnalyzer predates this version — SOC automation is an area Fortinet keeps extending release over release.
2. Log Analysis — 24%
- Analyze logs, events, and incidents. The baseline skill the rest of the exam assumes.
- Analyze FortiView dashboards and widgets. FortiView is FortiAnalyzer’s built-in visualization layer — know what a widget is actually querying, not just how to read one.
- Diagnose and troubleshoot report generation issues. Listed under this domain rather than under Reports — read that as a signal that the exam treats a stuck or failed report as a log and data-pipeline problem first, not a reporting-feature problem.
Primary source: the Administration Guide, the FortiView and log-viewing chapters.
3. Features and concepts — 22%
This domain is the conceptual foundation for the other three, which is why it’s worth reading first even though it isn’t the largest:
- Explain Fabric integration and log collection. How FortiAnalyzer actually receives data from the Security Fabric in the first place.
- Explain log data flow, normalization, and parsing. What happens to a log message between arriving and becoming a normalized, queryable record — this is the mechanics question domain, and it’s foundational to nearly everything tested elsewhere.
- Explain SOC features on FortiAnalyzer. The conceptual counterpart to domain 1’s hands-on configuration tasks.
Primary sources: the Administration Guide and the Fabric Normalization Reference for how raw logs become normalized fields — this is a good page to actually sit and read once, not just skim.
4. Reports — 22%
- Explain the use of reports, charts, and datasets. The conceptual layer — what a dataset actually is, and how it relates to a chart or a report built on top of it.
- Configure reports. The hands-on task.
- Troubleshoot report generation. The failure-diagnosis counterpart, same pattern as domain 2’s troubleshooting task.
Primary sources: the Dataset Reference and the SQL Query Documentation — reporting on FortiAnalyzer is built on SQL datasets under the hood, and questions in this domain tend to assume you know that, not just that you can click through the report builder.
How to actually use this
- Pull the exam description page yourself and check this breakdown against it — that’s the whole point of citing a public source instead of asking you to trust a summary.
- Budget study time toward SOC operation and automation first — by our own estimate it’s the single largest domain, and if your FortiAnalyzer background is mostly log-viewing and reporting, the event handler / incident / playbook chain is probably the least familiar material here.
- Don’t skip Features and concepts because it looks like the “easy” conceptual domain. Log normalization and parsing mechanics show up as the reasoning behind questions in the other three domains, not just as their own standalone questions.
- Confirm any study material you’re using is actually written to FortiAnalyzer 7.6 — Fortinet’s own exam page names the product version as 7.6 without a point release, and SOC/automation features in particular have been extended across recent point releases.
Every practice question we publish carries the Fortinet page it was written from, the same way this guide does. How they are written is set out on the methodology page, and the catalogue says which exams are on sale today. There is also a free readiness assessment — it is drawn from the NSE 4 bank rather than this one, but it is the fastest way to see how a question and its explanation are put together.