NSE4 High Availability and Diagnostics Practice Question
A FortiGate admin wants to send logs to both a local disk and a remote FortiAnalyzer. Which log configuration must be set?
⚠ Common exam trap
NSE4 often tests whether candidates know that local and remote logging are configured independently, so they pick a non-existent 'mirror' option instead of enabling both destinations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable local logging and configure FortiAnalyzer as a remote server
To send logs to both local disk and a remote FortiAnalyzer, you must enable local logging (so logs are written to disk) and configure FortiAnalyzer as a remote logging server. FortiOS supports simultaneous local and remote logging when both are enabled; no special 'mirror' toggle is required for FortiAnalyzer in standard configurations. This combination satisfies the requirement of dual destinations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the 'diagnose debug application log' command
Why it's wrong here
The 'diagnose debug application log' command is a real-time troubleshooting diagnostic that streams log messages to the CLI console; it does not configure any persistent log destination. It is useful for viewing raw logs during a debugging session, but it cannot be used to simultaneously send logs to a local disk and a FortiAnalyzer because it does not write to or alter any log destination configuration. Log destinations must be defined in the FortiGate's configuration using global or per-VDOM log settings, not through debug commands.
- ✗
Select 'Mirror local logs to FortiAnalyzer'
Why it's wrong here
FortiOS does not offer a 'Mirror local logs to FortiAnalyzer' option. Local disk logging and FortiAnalyzer forwarding are two separate and independent log destinations; when both are enabled, FortiGate sends the same log stream directly to each destination in parallel, not by mirroring the local disk contents. There is no setting in the FortiGate or FortiAnalyzer GUI/CLI that copies logs from the local disk to FortiAnalyzer—the FortiAnalyzer receives logs over its own logging protocol once 'Send logs to FortiAnalyzer' is enabled.
- ✓
Enable local logging and configure FortiAnalyzer as a remote server
Why this is correct
The correct approach is to enable two independent log destinations in the FortiGate's log settings: first, set the local disk as a log destination (config log disk set status enable), and second, add and enable the FortiAnalyzer as a remote log server (config log fortianalyzer set status enable set server <fortianalyzer_IP>). Each destination is configured in its own block with its own severity/filter settings, and FortiGate will deliver logs to both simultaneously once both are enabled. This matches the requirement to send logs to both a local disk and a FortiAnalyzer without any dependency between the two.
- ✗
Set the log severity to 'Information' on both
Why it's wrong here
Setting the log severity to 'Information' on both destinations controls which log levels (Emergency through Information) are recorded and forwarded; it does not enable or configure multiple log destinations. Severity thresholds are applied independently per destination, so even if both are set to Information, each destination must still be separately enabled and configured. The administrator's task is to choose where logs go, not to tune severity—low severity simply ensures all message types are included, but if no destination is enabled, no logs are sent.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.