NSE4 High Availability and Diagnostics Practice Question
A FortiGate administrator needs to send logs to an external FortiAnalyzer for centralized monitoring. Which log configuration step is required?
⚠ Common exam trap
A common mix-up: candidates confuse the FortiAnalyzer configuration with a generic syslog server setup, assuming any external logging destination works the same way, but FortiAnalyzer requires a specific device registration and protocol that differs from standard syslog.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add the FortiAnalyzer as a logging device in System > FortiAnalyzer
To send logs from a FortiGate to an external FortiAnalyzer for centralized monitoring, the administrator must add the FortiAnalyzer as a logging device under System > FortiAnalyzer. This step establishes the secure, authenticated connection (typically using FortiGate's proprietary protocol over TCP/514 or TCP/3000) and enables log forwarding to the FortiAnalyzer. Without this configuration, the FortiGate will not send logs to the FortiAnalyzer, even if other logging methods are enabled.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure syslog server
Why it's wrong here
Configuring a syslog server is incorrect because syslog uses the standard IETF protocol (UDP/TCP port 514) with a plain text format, whereas FortiAnalyzer receives logs via a proprietary encrypted protocol that supports advanced indexing, correlation, and reporting. While FortiGate can send logs to any syslog server, a syslog server cannot replicate the automated event correlation, log aggregation, and FortiAnalyzer-specific queries available in a true FortiAnalyzer integration. The action to send logs to FortiAnalyzer is specifically performed under System > FortiAnalyzer, not by configuring a generic syslog destination.
- ✓
Add the FortiAnalyzer as a logging device in System > FortiAnalyzer
Why this is correct
Adding the FortiAnalyzer as a logging device in System > FortiAnalyzer is the correct method because FortiGate communicates with FortiAnalyzer using the FortiAnalyzer protocol—a proprietary, secure connection that registers the FortiGate, handles authentication, and forwards logs to the FortiAnalyzer's dedicated log database. In the FortiAnalyzer settings you specify the FortiAnalyzer IP address, the serial number for registration, and optionally enable SSL encryption; this creates a direct log-forwarding pipeline beyond simple syslog. This integration is the designed path for an external FortiAnalyzer to receive logs, enabling centralized management, advanced search, and reporting.
- ✗
Enable FortiCloud logging
Why it's wrong here
Enabling FortiCloud logging is incorrect because FortiCloud is a separate cloud-based service used for FortiGate cloud management and basic logging, not an external FortiAnalyzer. When you enable FortiCloud logging, logs are sent to Fortinet's cloud infrastructure, not to your own FortiAnalyzer appliance or VM. The FortiCloud service also has different retention limits and analytics capabilities, so it does not satisfy a requirement to forward logs to an on-premises or remote FortiAnalyzer.
- ✗
Enable disk logging on the FortiGate
Why it's wrong here
Enabling disk logging on the FortiGate is incorrect because disk logging stores log entries locally on the FortiGate's internal storage, which only allows local review and does not forward logs to any external device. The purpose of sending logs to an external FortiAnalyzer is to offload storage and enable centralized log management; disk logging keeps everything on the FortiGate and can cause local log rotation or overwriting based on disk space. This option provides no network transmission of logs, so it fails the requirement to send logs to an external destination.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.