Courseiva

NSE4 High Availability and Diagnostics Practice Question

A FortiGate administrator needs to forward logs to a FortiAnalyzer for centralized management. The FortiAnalyzer is reachable at 10.0.1.100. Which configuration step is required on the FortiGate to send logs to this FortiAnalyzer?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the FortiAnalyzer in System > FortiAnalyzer

To send logs to FortiAnalyzer, the administrator must configure the FortiAnalyzer server under System > FortiAnalyzer or via CLI using 'config log fortianalyzer setting set server 10.0.1.100'. The log forwarding policy is not used for FortiAnalyzer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a syslog server under Log Setting

    Why it's wrong here

    Syslog is a generic, unstructured logging protocol that lacks the advanced indexing, compression, and analytics capabilities of FortiAnalyzer's native protocol (FAS). While FortiAnalyzer can ingest syslog messages, the FortiGate's syslog configuration under Log Setting is intended for third-party syslog servers, not for establishing the authenticated, managed FortiAnalyzer connection. To forward logs to FortiAnalyzer, you must configure the FortiAnalyzer under System > FortiAnalyzer, which enables bi-directional communication, proper log format, and reporting; a syslog server entry will not register the FortiGate for FortiAnalyzer management or reporting.

  • ✗

    Add a firewall policy allowing traffic from FortiGate to FortiAnalyzer

    Why it's wrong here

    A firewall policy merely permits traffic between the FortiGate and FortiAnalyzer IP addresses over the required ports (e.g., TCP/514); it does not instruct the FortiGate to generate or forward any logs. Even if the policy allows connectivity, the FortiGate has no awareness of the FortiAnalyzer as a log collector unless you explicitly configure it via System > FortiAnalyzer or the 'config log fortianalyzer setting' CLI command. Additionally, FortiAnalyzer requires an authenticated registration (serial number or access token) before it will accept logs, so a security policy alone cannot enable log forwarding.

  • ✓

    Configure the FortiAnalyzer in System > FortiAnalyzer

    Why this is correct

    This is the correct method because it establishes the native, authenticated FortiAnalyzer connection. Under System > FortiAnalyzer, you specify the FortiAnalyzer IP address, set an access token or serial number, and enable logging; this configures the FortiGate to use FortiAnalyzer's proprietary logging protocol (FAS) with features like log buffering, encryption, and compression. The CLI equivalent, 'config log fortianalyzer setting', offers the same options and is often used in automated deployments. Once configured, the FortiGate begins forwarding all configured log types to FortiAnalyzer for centralized logging, analytics, and reporting.

  • ✗

    Enable logging to FortiCloud instead

    Why it's wrong here

    FortiCloud is a cloud-based service for FortiGate logging and management, but it is a distinct destination from FortiAnalyzer. The question specifically asks to forward logs to a FortiAnalyzer, so configuring FortiCloud logging would send logs to a different platform, not to the intended FortiAnalyzer. Additionally, FortiAnalyzer can be an on-premises appliance or a VM, with its own licensing and storage, whereas FortiCloud uses a different subscription model. Using FortiCloud would not satisfy the requirement, and the FortiGate would not be managed by or report to the FortiAnalyzer.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on NSE4

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A FortiGate administrator needs to send logs to an external FortiAnalyzer for centralized monitoring. Which log configuration step is required?

medium
  • A.Configure syslog server
  • ✓ B.Add the FortiAnalyzer as a logging device in System > FortiAnalyzer
  • C.Enable FortiCloud logging
  • D.Enable disk logging on the FortiGate

Why B: To send logs from a FortiGate to an external FortiAnalyzer for centralized monitoring, the administrator must add the FortiAnalyzer as a logging device under System > FortiAnalyzer. This step establishes the secure, authenticated connection (typically using FortiGate's proprietary protocol over TCP/514 or TCP/3000) and enables log forwarding to the FortiAnalyzer. Without this configuration, the FortiGate will not send logs to the FortiAnalyzer, even if other logging methods are enabled.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.