Courseiva

NSE4 System and Network Administration Practice Question

An admin needs to configure a FortiGate to send logs to a FortiAnalyzer. Which TWO steps must be performed? (Choose two.)

⚠ Common exam trap

Test-takers frequently think a firewall policy is required to allow outbound log traffic, but FortiGate management traffic (including logs to FortiAnalyzer) bypasses the firewall policy engine and is controlled solely by the management VDOM or system settings.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the FortiAnalyzer IP under config system log-fortianalyzer

The FortiGate must be configured with the FortiAnalyzer IP address under the `config system log-fortianalyzer` hierarchy to establish the logging destination. Option E is correct because after setting the IP, the `set status enable` command must be issued to activate log forwarding to that FortiAnalyzer; without this, no logs are sent even if the IP is configured.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set the log aggregation interval

    Why it's wrong here

    Setting the log aggregation interval is an optional tuning parameter that controls how log summaries are compiled, such as hourly or daily rollups. While it can be configured under the log-fortianalyzer settings to optimize reporting, it does not establish the FortiAnalyzer connection. Without first specifying the server IP and enabling the status, no logs are forwarded regardless of aggregation settings.

  • ✗

    Configure SNMP trap destinations

    Why it's wrong here

    SNMP trap destinations are used to send SNMP alerts/notifications for network events to an SNMP manager. This is a separate logging and alerting mechanism from FortiAnalyzer log forwarding. FortiAnalyzer receives syslog-style logs via proprietary protocols, not SNMP traps. Configuring SNMP destinations would not forward firewall logs to FortiAnalyzer and is irrelevant to the required log-forwarding configuration.

  • ✗

    Create a firewall policy to allow traffic to FortiAnalyzer

    Why it's wrong here

    In some deployments, FortiAnalyzer may be on a different network segment, requiring an inter-VDOM or intra-VDOM policy to permit the log forwarding traffic. However, this is a prerequisite for network connectivity rather than the actual log configuration. The direct configuration step is to define the FortiAnalyzer server under the system log-fortianalyzer hierarchy and enable it; the firewall policy only ensures the traffic can traverse, not that logging is enabled.

  • ✓

    Configure the FortiAnalyzer IP under config system log-fortianalyzer

    Why this is correct

    The command `config system log-fortianalyzer` enters the FortiAnalyzer configuration mode, where the `set server <ip>` command specifies the IPv4 address of the FortiAnalyzer device that will receive logs. This is the mandatory first step in the CLI to point the FortiGate at its log collector. Without this address, the FortiGate has no destination for its syslog-like log streams to FortiAnalyzer. Optionally, parameters like `set upload-option` and `set source-ip` can also be set here, but the server IP is essential.

  • ✓

    Enable logging to FortiAnalyzer using the 'set status enable' command under the same configuration

    Why this is correct

    Merely specifying the FortiAnalyzer IP does not activate log forwarding; the FortiGate disables the FortiAnalyzer log link by default. Running `set status enable` within `config system log-fortianalyzer` turns on the log upload, causing the FortiGate to establish a connection and transmit logs according to the configured upload/schedule settings. This is the necessary second step that makes the configured IP operational.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.