Courseiva

NSE4 High Availability and Diagnostics Practice Question

A FortiGate admin wants to send logs to both a local disk and a remote FortiAnalyzer. Which log configuration must be set?

⚠ Common exam trap

NSE4 often tests whether candidates know that local and remote logging are configured independently, so they pick a non-existent 'mirror' option instead of enabling both destinations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable local logging and configure FortiAnalyzer as a remote server

To send logs to both local disk and a remote FortiAnalyzer, you must enable local logging (so logs are written to disk) and configure FortiAnalyzer as a remote logging server. FortiOS supports simultaneous local and remote logging when both are enabled; no special 'mirror' toggle is required for FortiAnalyzer in standard configurations. This combination satisfies the requirement of dual destinations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the 'diagnose debug application log' command

    Why it's wrong here

    The 'diagnose debug application log' command is a real-time troubleshooting diagnostic that streams log messages to the CLI console; it does not configure any persistent log destination. It is useful for viewing raw logs during a debugging session, but it cannot be used to simultaneously send logs to a local disk and a FortiAnalyzer because it does not write to or alter any log destination configuration. Log destinations must be defined in the FortiGate's configuration using global or per-VDOM log settings, not through debug commands.

  • ✗

    Select 'Mirror local logs to FortiAnalyzer'

    Why it's wrong here

    FortiOS does not offer a 'Mirror local logs to FortiAnalyzer' option. Local disk logging and FortiAnalyzer forwarding are two separate and independent log destinations; when both are enabled, FortiGate sends the same log stream directly to each destination in parallel, not by mirroring the local disk contents. There is no setting in the FortiGate or FortiAnalyzer GUI/CLI that copies logs from the local disk to FortiAnalyzer—the FortiAnalyzer receives logs over its own logging protocol once 'Send logs to FortiAnalyzer' is enabled.

  • ✓

    Enable local logging and configure FortiAnalyzer as a remote server

    Why this is correct

    The correct approach is to enable two independent log destinations in the FortiGate's log settings: first, set the local disk as a log destination (config log disk set status enable), and second, add and enable the FortiAnalyzer as a remote log server (config log fortianalyzer set status enable set server <fortianalyzer_IP>). Each destination is configured in its own block with its own severity/filter settings, and FortiGate will deliver logs to both simultaneously once both are enabled. This matches the requirement to send logs to both a local disk and a FortiAnalyzer without any dependency between the two.

  • ✗

    Set the log severity to 'Information' on both

    Why it's wrong here

    Setting the log severity to 'Information' on both destinations controls which log levels (Emergency through Information) are recorded and forwarded; it does not enable or configure multiple log destinations. Severity thresholds are applied independently per destination, so even if both are set to Information, each destination must still be separately enabled and configured. The administrator's task is to choose where logs go, not to tune severity—low severity simply ensures all message types are included, but if no destination is enabled, no logs are sent.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.