Courseiva

NSE4 System and Network Administration Practice Question

A FortiGate administrator notices that the device's disk usage is critically high, causing logging failures. The administrator wants to free up space without losing important logs. Which action should be taken first?

⚠ Common exam trap

Many exam-takers confuse 'increasing retention period' (which makes the problem worse) with 'decreasing retention period' (which would free space but delete logs), or they may think disabling logging is a quick fix without realizing it stops all logging activity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure log compression

Log compression reduces the size of existing log files on the disk without deleting any data, directly addressing the critically high disk usage while preserving all important logs. This is the safest first step because it reclaims space immediately without risking data loss or altering logging behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Delete all existing log files

    Why it's wrong here

    Deleting all existing log files frees disk space immediately but is a destructive, one-time action that permanently erases forensic data, audit trails, and historical records needed for incident response, troubleshooting, or regulatory compliance. It treats the symptom without addressing the root cause, so the disk will again fill as new logs accumulate — making it an unsustainable 'band-aid' that sacrifices valuable evidence.

  • ✓

    Configure log compression

    Why this is correct

    Configuring log compression on a FortiGate (typically using gzip) reduces the on-disk footprint of stored logs without removing any data, preserving full log fidelity for later analysis. This non-destructive approach directly addresses disk-full pressure by shrinking existing and future log files, and it can be combined with retention policies to keep more history within the same space.

  • ✗

    Disable logging to the local disk

    Why it's wrong here

    Disabling logging to the local disk stops the device from writing new log entries, but it does not actively shrink the existing log files; it only halts further growth. This radically reduces security visibility — the device can no longer retain critical event information locally for troubleshooting or compliance — making it a disproportionate response that leaves the FortiGate blind to historical and ongoing threats.

  • ✗

    Increase the disk retention period

    Why it's wrong here

    Increasing the disk retention period would instruct the FortiGate to keep logs for a longer time before overwriting or purging them, which necessarily consumes more disk space over time, not less. This option is logically opposite to the administrator's goal of reducing disk usage and would accelerate the disk-full condition rather than alleviating it.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.