Courseiva

NSE4 System and Network Administration Practice Question

A FortiGate administrator wants to send logs to a FortiAnalyzer. The FortiAnalyzer IP is 192.168.1.100, and logging is configured under Log & Report. However, no logs are being received. Which command should the administrator use on the FortiGate to verify connectivity to the FortiAnalyzer?

⚠ Common exam trap

Many candidates assume a successful ping (Option B) proves log connectivity, but the NSE4 exam tests the distinction between network-layer reachability and application-layer log protocol status, making the diagnostic command the only correct verification method.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

diagnose log device status

The 'diagnose log device status' command specifically checks the connectivity status and last-acknowledged sequence number between the FortiGate and the configured FortiAnalyzer. This command verifies whether the FortiGate can reach the FortiAnalyzer at the logging protocol level (FGFM), which is essential for log transmission, unlike a basic ICMP ping that only tests network-layer reachability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    diagnose log device status

    Why this is correct

    diagnose log device status is the correct diagnostic command because it directly queries the FortiGate's logging subsystem to report the operational state of configured log devices, such as a FortiAnalyzer. This command displays fields like connection state (e.g., 'valid' or 'invalid'), the last log message timestamp, and any error counters, verifying whether the FortiAnalyzer is reachable and accepting logs. Unlike ping or configuration views, it reflects the live status of the log-forwarding pipeline, making it the definitive tool for confirming that logs are being transmitted successfully.

  • ✗

    execute ping 192.168.1.100

    Why it's wrong here

    execute ping 192.168.1.100 only tests ICMP reachability to the FortiAnalyzer's IP address, which does not exercise the logging service itself. Even if the host responds to ping, the FortiGate's log daemon (logd) may still be unable to connect because the FortiAnalyzer's log-receiving service (e.g., syslog on port 514 or FTP on 6343) is down, or because an intermediate firewall is blocking non-ICMP traffic. Thus, a successful ping cannot confirm that the logging service is operational, and a failed ping would not pinpoint whether the cause is network, configuration, or the FortiAnalyzer itself.

  • ✗

    show full-configuration log fortianalyzer

    Why it's wrong here

    show full-configuration log fortianalyzer outputs the configured settings for the FortiAnalyzer log device, such as the server IP address, port, and associated serial number. However, this is purely a static dump of the intended configuration; it does not query the live connection state or show whether logs are actually being received. The command cannot reveal connectivity problems, authentication failures, or service outages, so it is insufficient for verifying that logging is working in real time.

  • ✗

    get system ha status

    Why it's wrong here

    get system ha status is solely focused on high-availability cluster information, including HA role (primary/secondary), synchronization status, and peer unit connectivity. Log forwarding to a FortiAnalyzer operates independently of HA state; even a perfectly healthy HA cluster may have a misconfigured or unreachable FortiAnalyzer. This command provides no relevant data about log device connectivity or log transmission, making it entirely irrelevant to the administrator's troubleshooting goal.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.