NSE4 High Availability and Diagnostics Practice Question
A network admin receives an alert that the FortiGate disk logs are no longer being written. The admin checks the disk status and sees that the disk is full. However, the admin needs to preserve the logs for compliance purposes. Which action should the admin take to continue logging while preserving the existing logs?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure log upload to FortiAnalyzer and manually archive current logs, then clear the local disk
The correct action is to configure log upload to FortiAnalyzer and manually archive the current logs, then clear the local disk. This preserves the logs for compliance by offloading them to an external server, while freeing up disk space to allow new logging to continue. Other options are incorrect: increasing the disk quota does not solve the full issue, deleting logs loses compliance data, and compression alone may not free enough space immediately.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure log upload to FortiAnalyzer and manually archive current logs, then clear the local disk
Why this is correct
Offloading new logs to FortiAnalyzer frees local disk space while retaining compliance evidence, and archiving existing logs before clearing preserves them. This satisfies the stem's dual constraint: continue logging and keep the current logs, which simply deleting or disabling logging would violate.
- ✗
Increase the log disk quota to allow more logs
Why it's wrong here
Raising the quota does not create free space on an already-full disk, so logging remains stalled. It is tempting because quota settings govern log storage allocation, and it would be correct when the disk has capacity but the configured log allowance is the limiting factor.
- ✗
Delete all logs from the disk and restart logging
Why it's wrong here
Deleting all logs destroys the records compliance requires, directly contradicting the preservation requirement. It is tempting because it immediately frees disk space and restores logging, and it would be correct only where retention obligations do not apply and historical logs are expendable.
- ✗
Compress the existing log files and set a higher compression level for future logs
Why it's wrong here
Compression frees space only after logs are rotated and compressed, but the disk is already full, so FortiGate cannot write new entries meanwhile. Compression is for reducing storage consumption of archived logs, and would suit a healthy disk nearing capacity, not one already exhausted.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.